# Billing & Plans

## How billing works

Signing up for **Starter or Pro** runs through Stripe Checkout. Once you're on a plan, you can **switch between Starter and Pro right from the Billing tab** - "Upgrade to Pro" / "Switch to Starter" - without leaving the app. The switch retargets your existing subscription in place (it never creates a second one), takes effect immediately, keeps any trial in progress, and confirms the projected cost first. Canceling, updating a payment method, and viewing invoice history still happen in a self-serve Stripe Customer Portal, available to the org owner (which also offers the same plan switch as a fallback). The Billing tab shows a **"What happens if you cancel?"** summary next to the portal link - 24 hours, then the 28-day grace period with access blocked, then permanent deletion - so the consequences are visible before the cancellation button, not only after. See [Data Portability & Offboarding](https://swarmfile.com/docs/admin/data-portability-and-offboarding) for the full detail.

**Free** is different: it's a no-card tier you choose at signup, not something you switch into or out of later. There's no Stripe subscription behind it at all - nothing to charge, cancel, or retarget. Upgrading from Free runs the same org through Checkout for the first time, the same as any Starter/Pro signup; there's no separate downgrade path back into Free afterward.

One thing neither the app nor the portal lets you edit **once you're subscribed**: seat *quantity*. (At sign-up you can pre-pick a starting seat count - that's the number the first invoice uses - but from then on it's live.) Seat count is derived from org membership, not a number you type - **you change your seat count by adding or removing people in the Team tab**, and your billed seats follow automatically, reconciled daily. Editing a seat count by hand would just get overwritten by the next reconcile sweep; the Billing tab links you to Team instead.

Starter and Pro carry the same 7-day free trial. Your card is collected upfront at signup, and the first charge happens on day 7. **During the trial, seats are capped at 2 and add-ons aren't available** - growing past 2 people, or adding extra storage/collaborator capacity, means ending the trial and paying first (you can do that any time, see below). Trials are also one-time per org: once a subscription has gone active, canceling and resubscribing doesn't grant a new trial period.

The trial is optional, and you can leave it early:

- **Skip it.** At sign-up, tick **Skip the 7-day trial and start paying today**, or pick more than 2 seats (a trial can't cover them, so that starts paid automatically). From the Billing tab, Starter and Pro each offer **Subscribe now, skip the trial** next to the trial button. Either way you get a paid subscription straight away, with no trial and no 2-seat cap.
- **End it early.** While trialing, the Billing tab's **End trial and subscribe now** charges your card on file for about the first month's seats right away (the confirmation shows the amount) and lifts the 2-seat cap immediately; add-on packs unlock at the same moment. If the card is declined, nothing changes: you stay on the trial, and you can update the card in the Customer Portal and try again. If you canceled during the trial, resume the subscription in the Customer Portal first; the Billing tab points you there instead of offering to end a trial that's already set to stop. The Team tab's seat-limit notice and the desktop app's trial notice both link there, and the Billing history records the change as **Trial ended early**.

## Plans

| Plan | Price | Storage | Seats | External collaborators | Headless API keys |
|---|---|---|---|---|---|
| Free (`community` in the API) | Free, no card | Grows with account age, up to 1 GiB total | 1 seat only | Free on public projects | 1 |
| Starter | $5/seat/mo | 100 GiB/seat | 1+ seats, no ceiling | 1 per seat (private projects); public projects free | 2 per seat (min 5) |
| Pro | $25/seat/mo | 500 GiB/seat | 1+ seats, no ceiling | 5 per seat (private projects); public projects free | 5 per seat (min 10) |

The seat figures above describe an active, paid subscription - the 7-day trial itself is capped at 2 seats regardless of plan (see above). The Free plan has no trial (there's nothing to trial) and no add-ons; its storage cap is a single all-in allowance that starts small on a brand-new org and rises to 1 GiB over its first few months, rather than the per-seat allowance Starter and Pro use.

The Free plan can only create **public** projects, and every project it creates is stored **unencrypted** at rest - private projects and managed encryption at rest both require Starter or above; the end-to-end tier requires Pro or above. The same is true of any **public** project on a paid plan: public projects must be unencrypted so they can be served anonymously. These are the two things the Free plan restricts by *kind*, not just by size: a Free-plan org that wants either has to upgrade first, it can't simply run out of room the way storage or collaborators can. Encryption tier is also fixed at project creation - upgrading doesn't retroactively encrypt a project created while on Free; only projects created after the upgrade get managed encryption. See [Security Architecture](https://swarmfile.com/docs/admin/security-architecture#unencrypted-tier) for the full detail.

Each plan also caps how many **live projects** an organization can have: 10 on Free, 100 on Starter, 250 on Pro (Enterprise is contract-negotiated). Deleting a project frees its slot; the cap bounds per-org resources and never bills anything.

Everything stored at rest counts toward your storage allowance on the same basis - project files, and the objects held for a project used as a [git-LFS](https://swarmfile.com/docs/guides/git-lfs) server (billed on distinct content, so deduplication applies). Storage starts with the first project: an org with no projects has no billed storage and no dedicated bucket yet. Bandwidth is unlimited and free on every plan, for both cloud and P2P transfer. Every plan's included bandwidth allowance is unlimited: egress is never billed and no plan caps it, and egress bytes are still counted per org and shown on the Usage tab. The one ceiling is the platform-wide anonymous-read abuse backstop (see [Telemetry & Data Collection](https://swarmfile.com/docs/reference/telemetry-and-data-collection)), which can refuse anonymous public reads at extreme volume. Unlike storage and collaborators, egress has no billed meter at all, so "unlimited" is a policy choice on top of real counters, not an absence of counting. Self-hosted seed/NAS nodes require Pro or above; see [Self-Hosted Seed Nodes](https://swarmfile.com/docs/admin/self-hosted-seed-nodes) for setup.

Need more than Pro's limits - unbounded external collaborators and headless API keys, a custom seat arrangement, or different billing terms? Enterprise plans are available; contact us.

### Overage rates

Storage that exceeds your plan's included allowance is billed at $4/100 GiB on Pro and $5/100 GiB on Starter. External collaborators beyond your plan's included allowance are billed at $1/month per collaborator, up to the 3x hard ceiling described below - **private-project grants only**. Collaborators on public projects are free and consume nothing: neither the included allowance, the overage meter, nor the ceiling. The Free plan bills no overage on anything - there's nothing to charge a card that doesn't exist - so its storage allowance is a hard wall, not a soft one (see Enforcement below). Headless API keys never bill overage - they're a hard cap, not a metered dimension: Starter includes 2 per seat (minimum 5) and Pro 5 per seat (minimum 10), and committed key packs add 10 keys for $20/month on either plan (see Enforcement below).

Prefer committed capacity to overage? **Storage packs** pre-buy it at a discount: **$4/100 GiB on Starter and $3/100 GiB on Pro** per month - a dollar below the matching overage rate. A pack adds 100 GiB to your included allowance for as long as it's on the subscription, and because the allowance is raised first, pack capacity is never also billed as overage (and never counts against the spend cap below). Manage them in the **Add-ons** section of the Billing tab; a plan caps pack counts per kind - 100 per kind on Starter; on Pro, 10,000 storage packs or 1,000 collaborator/key packs - because each committed pack also lifts the 3x hard ceiling. Collaborator packs work the same way: $0.80/month per extra external collaborator, versus $1 in overage. Changes are also rate-limited (about ten per organization per day), and an increase must clear its prorated charge immediately rather than waiting for the next invoice.

Hosted CI compute is a third metered dimension, separate from the allowances above: [Hosted CI](https://swarmfile.com/docs/guides/hosted-ci) jobs bill per second of container time at our underlying provider's at-cost rate × 1.1, with a 60-second minimum per job and no included allowance on any plan - every cent counts against the spend cap from the first second. It is deliberately not plan-gated: every plan can enable it per project. A Free-plan org has no card by default, so it attaches one for compute only (a zero-price subscription, not a plan upgrade) before its first job, and then runs under a platform compute ceiling scaled by account trust.

## Enforcement

Quota enforcement is always on. There's no setting to disable it and no feature flag gating it off - it's a structural part of the product, not an opt-in.

Plan storage counts the size of your files. Each project also has a separate, unbilled limit on its file information and history (names, versions, and so on), which only very large projects approach - see [Project storage limit](https://swarmfile.com/docs/admin/operations#project-storage-limit).

Storage, seats, and external collaborators are enforced differently, on purpose:

- **Seats** have no ceiling and no minimum on either plan once you're subscribed, beyond the universal 1-seat floor every org has (you always have at least an owner). Add or remove people in the Team tab any time; billed seats simply follow. The one exception is the 7-day trial itself, which is capped at 2 seats until you commit to a plan (see [Plans](#plans) above). The Team tab reflects whichever cap applies - it replaces the invite form with the plan's limit and an upgrade link at the Free plan's single seat, and a **Subscribe now** link (to end the trial) at the trial's two, so the refusal is visible before anyone types an address.
- **Storage and private-project external collaborators** both bill metered overage before hard-blocking, rather than blocking right at the included amount: storage hard-blocks at 3x the included allowance, and private-project external collaborators hard-block at 3x the included per-seat allowance. (Public-project collaborators sit outside this meter entirely - free, no slot, no ceiling.)
- **Headless API keys** are a hard cap, not a soft one: minting is refused with a `402` (`code: keys_cap`) the moment the org is at its allowance - Starter 2 per seat with a floor of 5, Pro 5 per seat with a floor of 10, Free 1 - and key packs (+10 keys for $20/month) raise the cap. Keys are org-owned machine credentials for headless fleets (render nodes, CI, containerized agents, seed/NAS nodes); user workstations and their mounted agents need none, and personal access tokens (a person's own automation) are free. Revoking a key frees a slot immediately, and a downgrade never revokes keys you already have - it only blocks minting new ones past the new allowance. A key is walled off to exactly one project, and deleting a project revokes its keys with it. Owners see the standard soft-cap warning banner in Billing once the org reaches 80% of its key allowance, before minting ever refuses.
- **The Free plan's storage** is the one exception to the above: its included allowance and its hard block are the same number. There's no overage zone to sell, so there's nothing to leave room for - the cap you see is the cap that's enforced.

The reasoning: the pricing page sells metered overage as a real capability for both dimensions, so hard-blocking the moment you cross the included allowance would refuse to sell what's advertised. The backstop exists to catch runaway or abusive usage, not to cap normal overage billing. The Free plan isn't selling anything, so this reasoning doesn't apply to it.

### Spend cap

Starter and Pro also carry a **spend cap**: a monthly dollar ceiling on metered charges (storage above your allowance, extra external collaborators, and hosted-CI compute - metered from the first second, with no included allowance). Seats and add-on packs aren't counted against it, and downloads are always free. By default the cap equals your plan's seat charge - your seat count times the per-seat price - and an owner or admin can change it under **Billing → Spend cap**, either permanently or for 24 hours, 7 days or 30 days before it reverts to the default. Leaving the field blank, or choosing **Reset to plan default**, clears your own figure. Resetting to a default that sits below metered charges already accrued this month pauses new uploads immediately, exactly like lowering the cap by hand - the form says so before you click. There's no upper limit on the figure: above the most storage and collaborator growth alone could bill (the 3x hard ceiling), metered compute can still push usage past the cap, and the Billing form says so as you enter it.

The cap is a hard ceiling on the overage line itself, not just a pause button: overage bills up to it and never past it. Because metering follows your *standing* usage for the period, the ceiling applies to the whole month - lowering it below overage you've already accrued drops that month's charged overage to the new figure and pauses further growth immediately, while raising it lets accrual continue. It never changes what's included: plan seats and committed packs still raise your allowance before any overage is counted.

When metered charges reach the cap, uploads that would add billable storage (and invites that would add a billed collaborator) pause, and new hosted-CI jobs are refused with a blocked `spend_cap_reached` run - running jobs finish. Reading, streaming, deleting, renaming and everything else keep working, and nothing is lost: the desktop app holds paused saves and uploads them once the cap is raised or storage is freed. A refusal is a `402` with `code: spend_cap_reached` carrying `capCents`, `usedCents`, `remainingCents` and the figure the request would have reached; the desktop app shows "Spend cap reached" and keeps retrying, so a raise resumes the backlog on its own. The Free plan and Enterprise have no spend cap on the storage/collaborator line - a Free-plan org's hosted CI runs under the platform's Community compute ceiling (after a card attach), and Enterprise compute is contract-priced.

A payment **dispute** (a chargeback on the subscription) is a different, deliberately sticky lockout rather than a cap: while it is open, the org's file reads and writes are refused with a `402` (`code: grace_period_inaccessible`) until the dispute is resolved with support. Nothing is deleted, and saves that were paused upload as soon as it is cleared.

**Per-key budgets.** A project-scoped API key can also carry its own ceiling, set per key on the **API Keys** page (blank means no key budget). Enforcement uses the lower of the two - `min(org spend cap, key budget)` - and a key-budget refusal affects only that key's writes: other keys, user workstations, and reads are untouched. A key refusal names the key in the `402` (`keyLimitCents`, `keyId`).

**Notifications.** Owners and admins get an in-app notification when the cap is approached (50%, 80%, 100%), on the first refusal of a billing period, when a raise or a cleanup lets writes resume, and whenever the cap or a key budget changes. Billing's "approaching plan limits" banner shows the same levels.

## Plan-gated features

Three features are **Starter and above**: private projects, a dedicated per-org storage bucket (the one-way enable on **Settings → Storage**), and an [organization-enforced authentication policy](https://swarmfile.com/docs/admin/identity#authentication-policy-require-mfa-andor-a-verified-email) (require MFA and/or a verified email for members) - a Free-plan org can only create public projects, stored unencrypted (plaintext), and can't turn a policy requirement on; requesting a private project (managed encryption at rest comes with it) from the Free plan, or enabling a policy requirement, is rejected the same way any other plan-gated feature is. A number of others are **Pro and above**: SSO (OIDC), SCIM/LDAP sync, folder ACLs with Windows DACL projection, audit-log export, the [end-to-end-encryption tier](https://swarmfile.com/docs/admin/end-to-end-encryption), [self-hosted seed nodes](https://swarmfile.com/docs/admin/self-hosted-seed-nodes), and [branch-mirror-to-S3](https://swarmfile.com/docs/admin/branch-mirror). A few are **Enterprise-only**: [bring-your-own primary storage](https://swarmfile.com/docs/admin/bring-your-own-storage), SAML SSO (via an adapter - see [Identity](https://swarmfile.com/docs/admin/identity)), and a [self-hosted control plane](https://swarmfile.com/docs/guides/deployment-topologies). (EU/US [data residency](https://swarmfile.com/docs/admin/data-residency) is the exception - available at no extra cost on every paid plan, not an Enterprise upsell; a Free-plan org uses shared storage and can't pin a region.) These are enforced server-side with a real `402` rejection if you try to configure them on a plan that doesn't include them - not just hidden behind UI. Downgrading never disables something you've already configured; it only blocks configuring something new.

For the details on those features themselves, see [Identity](https://swarmfile.com/docs/admin/identity) and [Permissions](https://swarmfile.com/docs/admin/permissions).

## Usage visibility

Plan standing, current usage, and your org's resolved entitlement set are visible to any org member, not just the owner. See [Organizations, Projects & Members](https://swarmfile.com/docs/admin/organizations-projects-and-members) for where that lives. The **Usage** tab (owners) breaks usage down by dimension - storage, egress, collaborators, hosted-CI compute - and includes a **headless API keys** line showing how many of the plan's included keys the org is using; Billing carries the 80% warning banner before minting is refused.
