Pricing
Priced by applications, not users.
You pay for the applications you register — each set of services with its own audience and permissions — not per user, not per monthly active user, and not per tenant. Ten users or a hundred thousand cost the same. A second product line is what moves you up a plan.
For a single product with a few backend services behind it.
- Multiple microservices per app
- One tenant, sub-organizations at any depth, isolated by role reach
- Managed updates and monitoring
- All four SDKs and the full API
- Mobile apps authorization
- DPA / AVV included
- Email support, next business day
For a platform with several product lines, each its own set of services.
- Everything in Team, plus:
- Priority support with a response-time target
- Upgrade guidance for major versions
- DPA / AVV included
For HIPAA or financial data, where isolation and paperwork are part of the product.
- Everything in Scale, plus:
- Signed BAA, alongside the DPA / AVV
- Your own isolation level: a dedicated instance, or a database no other customer touches
- White-labeling and branding at any node of your org tree
- Independent tenants on one account, and subtrees hidden from their own parent
- Data residency and a contractual SLA
- Custom token claims and real-time, assignable alarms
- Native mobile app for security alerts, not just device authorization
- Onboarding and an architecture review, with a named contact
A DPA (AVV) is available and signed on every plan, before any customer data is processed. A BAA is available on Regulated; if you handle US PHI, that is the plan to ask about. Move between plans as you add or retire product lines — nothing to migrate, just a plan change. At the Regulated tier the price follows isolation: a dedicated instance, or a database for a single customer, costs more to run than a shared deployment, and that's the conversation to have.
Calculator
What it costs you as you grow.
Enter what you actually have. The user count changes the plan you need in exactly no way — that's the point of the exercise. If you already pay for identity somewhere, put that number in and the difference is shown against it.
Questions about the bill
What counts, and what doesn't.
What exactly is an "application set"?
One product and every service behind it that shares an audience and a permission vocabulary. A web front end, three backend services and a worker queue serving the same product are one set, not five.
Do users, tenants or logins ever affect the price?
No. Users, monthly active users, sub-organizations and tenants are not metered. Registering a second product line is what moves you from Team to Scale.
Is a DPA / AVV included on the cheaper plans?
Yes. A DPA (Auftragsverarbeitungsvertrag) is available and signed on every plan, Team included, before any customer data is processed.
We handle US PHI. Which plan do we need?
Regulated. That's the plan a BAA is signed on, and the one that carries dedicated isolation and data residency.
Which capabilities are Regulated-only?
White-labeling and per-node branding, independent tenants on one account, subtrees hidden from their own parent, and the native mobile alerts app. Team and Scale give you one tenant with sub-organizations at any depth, isolated by role reach. The full breakdown is in the plan matrix.
What happens when we move up or down a plan?
Nothing migrates. The plan sets how many application sets you may register and which capabilities are switched on; your organizations, roles and tokens are untouched.
Tell us how many products you're putting behind it.
That's the number that decides the plan. Bring the org structure your last system couldn't model and we'll tell you on the call whether this one does.