Licensing
Editions
| Community | Business | Enterprise | |
|---|---|---|---|
| Price | Free | $10 / seat / month or $108 / seat / year (save 10%), 25-seat minimum per subscription | From $25k / year |
| Who | Personal; orgs <100 people and <$10M revenue | Any organization | Any organization |
| Seats | 25 active users | Purchased pool, split across gateways | Unlimited |
| Nodes per gateway | 1 | 3 | Unlimited |
| Gateways / sites | 1 | Unlimited | Unlimited |
| Local accounts with TOTP two-factor, one OIDC provider | ✓ | ✓ | ✓ |
| Model aliases; in-app and webhook alerts | ✓ | ✓ | ✓ |
| Guardrails and secret detection (observe and report) | ✓ | ✓ | ✓ |
Offline install, offline license verification, JANUS_OFFLINE |
✓ | ✓ | ✓ |
| SCIM, LDAP, multiple identity providers | — | ✓ | ✓ |
| HA, guardrail enforcement (redact and block), scheduled reports, captures, audit export | — | ✓ | ✓ |
| Fallback models, email alerts | — | ✓ | ✓ |
| Perpetual keys, purchase by PO without the portal, white-label, SLA | — | — | ✓ |
A subscription's seats form a pool. Split it into one key per gateway or site in any sizes that add up to the pool: a 25-seat subscription can be a 15-seat key for production and a 10-seat key for a lab.
Air-gapped networks
Janus Edge runs fully offline in every edition. The offline Linux archives, the signed license file (verified against keys built into the binary) and JANUS_OFFLINE=true are the same for Community, Business and Enterprise. What differs is how the license stays current:
- Community needs no key at all.
- Business keys are subscription keys. Issue an offline key from the portal (no sync URL), and carry each renewed key into the network after every paid renewal. If a renewal is not installed, the key expires and enters its grace period.
- Enterprise adds perpetual keys that never expire: a perpetual key has a maintenance date, and every release published on or before it runs indefinitely. Enterprise can also be bought by PO or wire with keys delivered by hand, never through the online portal, and includes air-gap deployment help under the support SLA.
The key
A key is a signed text file: JANUS-LICENSE-1.<payload>.<signature>. The gateway verifies it with public keys built into the binary — no network needed. Install under Admin → System → License, or mount it at JANUS_LICENSE_FILE.
Payload fields: license_id, org, issued_to, edition, seats, nodes, site, features, issued, exp, grace_days, term, maintenance_until, offline, sync_url.
Seats
An active user is a person who signed in during the last 30 days. Buy a pool in the portal, then issue one key per gateway with a seat allocation and a site label. The sum of allocations can never exceed the pool. Revoke and re-issue to move seats.
Automatic sync (optional)
Automatic license sync is off by default and separate from software update checks. We recommend it for monthly and annual subscriptions. An online key, sync_url, token or active subscription does not enable it.
Explicitly enable Automatic sync in Admin → System → License and supply the portal sync credential, or set JANUS_LICENSE_SYNC=true and JANUS_LICENSE_SYNC_TOKEN. An explicitly supplied true/false environment setting controls enablement; when unset, the saved UI setting applies. JANUS_OFFLINE and offline licenses override sync. File-mounted licenses are not automatically rewritten: deliberately switch to a managed database-installed key if you want sync.
The portal's Sync token copy button copies only the raw token. Direct API clients use Authorization: Bearer <license_id>.<sync_token>; the gateway also accepts that complete credential only when its license ID matches the installed key (do not paste the Bearer header text).
A revoked sync response preserves existing signed rights and warns administrators. Sync continues when enabled, but an active flag alone cannot clear that warning. Automatic recovery requires a newly signed same-identity license issued after the stored revocation barrier and a newer, fresh, matching subscription generation. Old servers without revoked_at cannot authorize automatic recovery; obtain and manually install a verified replacement key.
Without sync, download and install the renewed license after each paid renewal. Paying an invoice alone does not update an offline gateway. Sync failures do not extend the signed license or grace period. Check the License card for exact dates and sync health.
Buying and billing
Buy Business seats online from the portal, billed monthly or annually by card or US bank account. Card payments issue your seat pool immediately. Bank payments get a 30-day provisional license while the payment settles. Organization owners and administrators manage billing: from the portal they can download invoices, update the payment method and cancel at the end of the current period. Seat count and billing cadence can't be changed mid-subscription; contact support to change them. Need a purchase order, net terms or an Enterprise agreement? Contact sales.
Expiry behavior
- Before expiry: an ordinary expiry warning may be suppressed only while automatic renewal and fresh, healthy sync are positively confirmed. Cancellation, failed payment, stale/failed sync and expired licenses remain visible.
- Stripe subscription paid-through → +7 days (grace): banner, configured work continues. Coverage comes from verified paid invoices, not the next scheduled billing date. Existing manual and Community keys retain their signed grace period (normally 30 days); they are not shortened by this policy.
- After grace: existing configuration continues to run — proxying, SSO/SCIM, guardrails, quotas, HA, reports. Creating new models, upstreams, keys, quotas, rules, teams, schedules or captures is blocked until a current key is installed. Edits and deletes still work. Existing users are never signed out.
- Over seat allowance: new users cannot complete first sign-in; existing users are unaffected.
Perpetual keys
Sold by agreement for restricted environments. term: perpetual with a maintenance_until date: any release published on or before that date runs forever; newer releases refuse the key before running migrations, so you can roll back cleanly. Maintenance renewals extend the date.