Logto OSS

Self-hosted plans

Logto stays free and open source. Self-hosted plans add official support and commercial features for teams that run Logto on their own infrastructure, so your identity data never leaves it.

Looking for the fully managed service? See Logto Cloud pricing.

OSS Community
Free
The full open source product, self-hosted by you, with community support.
Complete authentication and authorization
Unlimited users and applications
Community support on GitHub and Discord
Your infrastructure, your data
Start with OSS
Free forever, no license required. Read the self-hosting docs
Self-hosted Pro
Early access
$199/mo, billed annually
Commercial features and email support for growing teams that run Logto themselves.
Everything in OSS Community
Console collaborators and mandatory MFA policy
Bring your UI, hide Logto branding, IdP-initiated SSO
Unlimited SAML applications
Email support within 3 business days
Request early access
We are onboarding teams in batches and will reach out as we open the next one.
Self-hosted Enterprise
Custom
SLA-backed support, deployment and migration services, and contract-defined terms.
Everything in Self-hosted Pro
Severity-based SLA over a private Slack or Teams channel
LTS release channel and built-in email service
Architecture review, migration, and go-live support
MSA, DPA, and custom procurement terms
Contact sales

What each plan unlocks

Logto OSS already covers authentication end to end. Paid self-hosted plans add the capabilities that production teams keep asking for, unlocked by a commercial license on the release you already run.

OSS Community
Self-hosted Pro
Self-hosted Enterprise
Invite teammates into Logto Console with roles, instead of sharing one admin account
-
with role governance guidance
Require MFA for every Console member. Self-service MFA stays free in OSS; the tenant-wide enforcement policy is what the paid plans add
-
with security policy guidance
Upload your own sign-in experience assets and serve them from your own object storage
-
Remove the "Powered by Logto" sign from the sign-in experience
-
Send verification emails through the Logto-hosted mail service. Your own SMTP or email provider works on every plan
--
Let enterprise customers start sign-in from their own identity provider portal
-
Applications that authenticate against Logto over SAML
3Unlimited, fair useContract-defined
LTS release channel
A long-term support line to stay on, so you upgrade on your schedule rather than the release cadence
--
Contract-defined resource quotas
Custom limits for resources such as connectors, webhooks, rate limits, and supported deployments
-Standard fair-use limitsContract-defined

What you get when something breaks

Self-hosting means you operate the deployment. A paid plan means you are not alone when it misbehaves at 2am.

OSS Community
Self-hosted Pro
Self-hosted Enterprise
Support channel
Where you reach us
CommunityEmail supportPrivate Slack or Teams channel, plus email
Response target
How quickly a human replies
No guaranteeWithin 3 business days
Severity-based SLA
Set in your contract
Support hours
When the response targets apply
Community availabilityBusiness daysAround the clock for critical incidents
Named contacts
People on your side who can open a ticket
-23-5
Incident handling
How production incidents are worked
Community best effortEmail troubleshootingPriority handling
Root cause analysis
A written post-incident report
--
for major incidents
Version support
Which releases we support you on
Latest community releaseCurrent stable and previous minorCurrent stable and LTS or contract-defined versions
Upgrade guidance
Help planning and running upgrades on your infrastructure
Docs onlyEmail guidanceUpgrade planning and assisted upgrade window
Security advisory
What you get when a vulnerability is disclosed
Public noticesPublic notices and email guidancePriority guidance and mitigation planning
Custom contract
Paperwork your procurement team needs
-Standard termsMSA, DPA, procurement and custom terms
Severity levels, response targets, and support hours are defined in the subscription terms.

Enterprise services

Self-hosted Enterprise carries the same service baseline as Cloud Enterprise: a dedicated Solution Engineer, SLA-backed support, root cause analysis for major incidents, and the security and compliance package. On top of that, it covers the work Cloud would otherwise be doing for you.

Deployment

We review the deployment you run before it carries production traffic, and keep reviewing it as it grows.

  • Architecture review and recommended Docker or Kubernetes topology
  • Postgres high availability, backup, restore, and upgrade review
  • Redis and central cache performance and reliability review
  • Object storage architecture and security review
  • Production readiness review of environment variables
  • Logging, metrics, and alerting recommendations
  • Disaster recovery strategy review
  • Go-live review and launch support
  • Quarterly or semiannual deployment health check

Migration

Moving off Auth0, Cognito, Keycloak, or an in-house system is a project. We plan it with you rather than hand you a document.

  • Source system assessment and migration plan
  • Data mapping review
  • SSO and connector migration guidance
  • Test migration review
  • Go-live migration support
  • Rollback planning
  • Full migration implementation, as an optional paid service

Customer infrastructure monitoring, managed self-hosted operation, and penetration test remediation are available as optional add-ons.

Frequently asked questions

Does Logto OSS become limited if I do not buy a plan?

How do the paid features reach my deployment?

Where does my data live?

Is there a scale limit on Self-hosted Pro?

How is this different from Logto Cloud?

Request early access

We are onboarding self-hosted teams in batches. Tell us how you run Logto and we will reach out as we open the next one.

Logto OSS stays free and unrestricted while you wait.