Plans and feature availability
Most of NextPKI works the same on every plan. Five capabilities are part of a paid plan, and this page says which, so you can tell a missing entitlement from a bug.
Prices are not repeated here - they live on nextpki.com/pricing, and a stale number in the documentation is worse than no number.
What belongs to a paid plan
Section titled “What belongs to a paid plan”| Capability | Free | Pro and above |
|---|---|---|
Renewal automation - unattended, driven by auto_renew |
✓ | |
| Alert webhooks into Slack, Teams or a custom endpoint | ✓ | |
| Single sign-on via SAML | ✓ | |
| Organisations below the tenant root and per-org roles | ✓ | |
| CSV export of the inventory | ✓ |
What every plan keeps
Section titled “What every plan keeps”This list is the more important one, because it is what a plan change cannot take away from a running system:
- Discovery, inventory and Certificate Transparency monitoring, in full.
- Expiry alerts by e-mail to owners and admins. These are never gated, in any plan and in any payment state - including while an invoice is unpaid. A billing problem must not be the reason nobody hears that a certificate is expiring.
- Renewing a certificate by hand, including creating and approving renewals and configuring the CA connectors needed to do it. Only the unattended run is a paid capability.
- Signing in through an existing SSO connection. If a tenant moves to Free, people already signing in through SAML keep signing in; what is gated is creating or changing a connection.
- Managing members at your top-level organisation, and removing anything you configured earlier - webhooks, connections, organisations. Clean-up is never behind a paywall.
Where to change plan
Section titled “Where to change plan”Owners find the current plan, domain usage and the checkout under Settings → Plan and billing in the Console. Payment, invoices and cancellation happen in Stripe’s customer portal, reachable from that page - card details never touch NextPKI.
The page is owner-only. Other roles see what a capability costs but are pointed at the public price list, because changing what a tenant pays is not an operating decision.
Business and Enterprise are invoiced outside Stripe; ask us directly.
How a missing entitlement shows up
Section titled “How a missing entitlement shows up”In the Console the form is replaced by a card naming the capability and the plan
it belongs to. Direct requests to a gated Console endpoint answer 402 Payment Required, which is deliberately distinct from the 403 you get for a missing
role.
The public API returns no 402 today: its endpoints cover the manual path, which
is not gated. Automation is enforced where it runs, in the renewal scheduler, so a
certificate on a Free tenant with auto_renew set is simply not picked up.