Skip to content

Plans and feature availability

Most of NextPKI works the same on every plan. Five capabilities are part of a paid plan, and this page says which, so you can tell a missing entitlement from a bug.

Prices are not repeated here - they live on nextpki.com/pricing, and a stale number in the documentation is worse than no number.

Capability Free Pro and above
Renewal automation - unattended, driven by auto_renew ✓
Alert webhooks into Slack, Teams or a custom endpoint ✓
Single sign-on via SAML ✓
Organisations below the tenant root and per-org roles ✓
CSV export of the inventory ✓

This list is the more important one, because it is what a plan change cannot take away from a running system:

  • Discovery, inventory and Certificate Transparency monitoring, in full.
  • Expiry alerts by e-mail to owners and admins. These are never gated, in any plan and in any payment state - including while an invoice is unpaid. A billing problem must not be the reason nobody hears that a certificate is expiring.
  • Renewing a certificate by hand, including creating and approving renewals and configuring the CA connectors needed to do it. Only the unattended run is a paid capability.
  • Signing in through an existing SSO connection. If a tenant moves to Free, people already signing in through SAML keep signing in; what is gated is creating or changing a connection.
  • Managing members at your top-level organisation, and removing anything you configured earlier - webhooks, connections, organisations. Clean-up is never behind a paywall.

Owners find the current plan, domain usage and the checkout under Settings → Plan and billing in the Console. Payment, invoices and cancellation happen in Stripe’s customer portal, reachable from that page - card details never touch NextPKI.

The page is owner-only. Other roles see what a capability costs but are pointed at the public price list, because changing what a tenant pays is not an operating decision.

Business and Enterprise are invoiced outside Stripe; ask us directly.

In the Console the form is replaced by a card naming the capability and the plan it belongs to. Direct requests to a gated Console endpoint answer 402 Payment Required, which is deliberately distinct from the 403 you get for a missing role.

The public API returns no 402 today: its endpoints cover the manual path, which is not gated. Automation is enforced where it runs, in the renewal scheduler, so a certificate on a Free tenant with auto_renew set is simply not picked up.