Self-hosted plans
Logto stays free and open source. Self-hosted plans add official support and commercial features for teams that run Logto on their own infrastructure, so your identity data never leaves it.
Looking for the fully managed service? See Logto Cloud pricing.
What each plan unlocks
Logto OSS already covers authentication end to end. Paid self-hosted plans add the capabilities that production teams keep asking for, unlocked by a commercial license on the release you already run.
OSS Community | Self-hosted Pro | Self-hosted Enterprise |
Invite teammates into Logto Console with roles, instead of sharing one admin account | - | with role governance guidance | |
Require MFA for every Console member. Self-service MFA stays free in OSS; the tenant-wide enforcement policy is what the paid plans add | - | with security policy guidance |
Upload your own sign-in experience assets and serve them from your own object storage | - | ||
Remove the "Powered by Logto" sign from the sign-in experience | - | ||
Send verification emails through the Logto-hosted mail service. Your own SMTP or email provider works on every plan | - | - |
Let enterprise customers start sign-in from their own identity provider portal | - | ||
Applications that authenticate against Logto over SAML | 3 | Unlimited, fair use | Contract-defined |
LTS release channel A long-term support line to stay on, so you upgrade on your schedule rather than the release cadence | - | - | |
Contract-defined resource quotas Custom limits for resources such as connectors, webhooks, rate limits, and supported deployments | - | Standard fair-use limits | Contract-defined |
What you get when something breaks
Self-hosting means you operate the deployment. A paid plan means you are not alone when it misbehaves at 2am.
OSS Community | Self-hosted Pro | Self-hosted Enterprise |
Support channel Where you reach us | Community | Email support | Private Slack or Teams channel, plus email |
Response target How quickly a human replies | No guarantee | Within 3 business days | Severity-based SLA Set in your contract |
Support hours When the response targets apply | Community availability | Business days | Around the clock for critical incidents |
Named contacts People on your side who can open a ticket | - | 2 | 3-5 |
Incident handling How production incidents are worked | Community best effort | Email troubleshooting | Priority handling |
Root cause analysis A written post-incident report | - | - | for major incidents |
Version support Which releases we support you on | Latest community release | Current stable and previous minor | Current stable and LTS or contract-defined versions |
Upgrade guidance Help planning and running upgrades on your infrastructure | Docs only | Email guidance | Upgrade planning and assisted upgrade window |
Security advisory What you get when a vulnerability is disclosed | Public notices | Public notices and email guidance | Priority guidance and mitigation planning |
Custom contract Paperwork your procurement team needs | - | Standard terms | MSA, DPA, procurement and custom terms |
Enterprise services
Self-hosted Enterprise carries the same service baseline as Cloud Enterprise: a dedicated Solution Engineer, SLA-backed support, root cause analysis for major incidents, and the security and compliance package. On top of that, it covers the work Cloud would otherwise be doing for you.
Deployment
We review the deployment you run before it carries production traffic, and keep reviewing it as it grows.
- Architecture review and recommended Docker or Kubernetes topology
- Postgres high availability, backup, restore, and upgrade review
- Redis and central cache performance and reliability review
- Object storage architecture and security review
- Production readiness review of environment variables
- Logging, metrics, and alerting recommendations
- Disaster recovery strategy review
- Go-live review and launch support
- Quarterly or semiannual deployment health check
Migration
Moving off Auth0, Cognito, Keycloak, or an in-house system is a project. We plan it with you rather than hand you a document.
- Source system assessment and migration plan
- Data mapping review
- SSO and connector migration guidance
- Test migration review
- Go-live migration support
- Rollback planning
- Full migration implementation, as an optional paid service
Customer infrastructure monitoring, managed self-hosted operation, and penetration test remediation are available as optional add-ons.
Frequently asked questions
Does Logto OSS become limited if I do not buy a plan?
How do the paid features reach my deployment?
Where does my data live?
Is there a scale limit on Self-hosted Pro?
How is this different from Logto Cloud?
Request early access
We are onboarding self-hosted teams in batches. Tell us how you run Logto and we will reach out as we open the next one.
Logto OSS stays free and unrestricted while you wait.