LICENSEWARE

Checkmarx One Contributing Developer licensing

This article covers the Checkmarx One Contributing Developer metric, its lines-of-code limit, Concurrent Scans, Credits for AI Actions and how these rules changed between License Types versions. For the platform overview, see Checkmarx licensing.

On This Page

Checkmarx One Contributing Developer licensing is the metric Checkmarx uses to sell its Checkmarx One application security platform. The Terms of Service grant a licence to use the Solution for internal business purposes, subject to the License Type restrictions and the quantity and type of licences purchased.[6] For Checkmarx One the License Type is the Contributing Developer. Each licence also carries a lines-of-code allowance, and AI features are metered separately in Credits.[1] Checkmarx’s pricing page lists the number of developers in scope as one of the three inputs to a quote, together with modules and deployment model.[7] For the wider picture, see Checkmarx licensing.

Editions

The Contributing Developer licence applies across the Checkmarx One packages: Essentials, Professional, Enterprise, Start with SAST and Start with Supply Chain.[7] The package decides which scanners a tenant can use. The developer count decides how many people, agents and bots may commit to the repositories those scanners cover. On the License screen, the Account General Information card shows the tenant’s Package Type, Service Type, Activation Date and Expiration Date.[5]

Metrics

Contributing Developer. Under version 2026.09, a Contributing Developer is any Contributor who has made one or more commits to a private Repository scanned by the Software in the last 90 days. A Contributor is an AI agent, bot or individual. A Repository is a set of version-controlled project files used to build a particular named software module or application.[1] Catalog: Contributing Developer; Contributing Developer is a committer to a scanned private repository in the last 90 days; AI agents and bots count as Contributors.

Three points follow from the definition. Only commits count, so users who only read results are not counted. Only private repositories that Checkmarx One scans count. The 90-day window rolls, so the count moves with staffing and project activity.

Lines of code. The Contributing Developer licence type has an account-level usage limit of 15,000,000 lines of code scanned in the last 90 days, multiplied by the number of Contributing Developer licences purchased.[1] A tenant with 100 licences therefore has a pool of 1.5 billion lines scanned per rolling 90 days. Catalog: Lines of code scanned; 15 million lines of code per Contributing Developer licence per 90 days.

Credits. The Credit-Based Consumption licence type covers Checkmarx One AI Products. A Credit meters AI Actions, which are agentic capabilities identified in the Documentation, such as Triage Assist, Remediation Assist and other Checkmarx One Assist agents.[1] Catalog: Checkmarx Credit.

Counting / floors

One person, one count. Version 2024.02 says a Contributing Developer is not counted more than once for contributing through several integrations or to several Repositories. Each developer is counted by the unique email address in the local git configuration.[2] The current License screen documentation describes the same de-duplication by git email address.[5] A practical consequence is that one person who commits with two different email addresses appears as two developers. Git identity hygiene is therefore part of licence management. Catalog: A Contributing Developer is counted once across integrations and repositories; Contributing Developers are identified by git email address.

Estimation. If an exact count of Contributing Developers cannot be determined, Checkmarx will estimate the number with a formula-based approach derived from consumption metrics that reflect actual usage.[1] The formula is not published. Catalog: Checkmarx may estimate Contributing Developers when an exact count is not possible.

Concurrent Scans. A Concurrent Scan is the number of scans that can run in parallel. Version 2024.02 gave Start for SAST packages 1 Concurrent Scan per 20 Contributing Developer licences, and other packages 1 per licence.[2] The current License Types page states no ratio.[1] The License screen shows the tenant’s Concurrent Scans and Queued Scans. Scans over the concurrency limit are added to the queue rather than refused.[5] Catalog: Concurrent Scan; Start for SAST had 1 Concurrent Scan per 20 Contributing Developers (2024.02); Checkmarx One queues scans above the Concurrent Scans limit.

Credit consumption. Credits are deducted each time an AI Action runs, at the rate in the Quote or the Documentation. Customers can watch the balance on a usage dashboard. When the balance reaches zero, AI Actions are suspended until more Credits are bought.[1] The Terms of Service add that unused Credits expire as the Quote, License Type or Documentation specifies, and that Credits are not currency or stored value.[6] The License screen’s Credit Usage section shows credits available, burn rate, estimated depletion date and top consumers.[5] Catalog: Credits are deducted each time an AI Action runs; AI Actions are suspended at a zero Credit balance.

Floors. No minimum number of Contributing Developers is published.

Version history

Checkmarx keeps earlier License Types versions online. Older contracts may still refer to them.

Version Unit Key rules 
2022.07 Developer One Developer licence entitles the customer to scan 3 Repositories, each up to 1 million lines of code. Applies to licences purchased from 2022-07-01 to 2022-08-23.[4] 
2022.08 Contributing Developer Ratio of 1 Contributing Developer to 3 unique Repositories in aggregate. For packages with SAST, a Repository over 1 million lines counts as one more Repository per extra million or part. 1 Concurrent Scan per 50 Developer licences.[3] 
2024.02 Contributing Developer No Repository ratio. Concurrent Scans at 1 per 20 licences (Start for SAST) or 1 per licence. Counted once by git email.[2] 
2026.09 Contributing Developer and Credits AI agents and bots count as Contributors. 15 million lines per licence per 90 days. Estimation where counts cannot be determined. Credits for AI Actions.[1] 

Catalog: Repository; 2022.08 licences allowed 3 Repositories per Contributing Developer; 2022.08 Repositories over 1 million lines counted as several; 2022.08 licences had 1 Concurrent Scan per 50 Developer licences; 2022.07 terms apply to licences bought from 2022-07-01 to 2022-08-23. Versions published between 2024.02 and 2026.09 are not linked from the current page.

Virtualization & partitioning

The metric counts committers, not machines, so virtualization does not affect it. The self-hosted deployment of Checkmarx One is priced through the quote.[7]

Cloud / BYOL

Checkmarx One is offered as SaaS and as a self-hosted deployment. The deployment model is one of the inputs to the quote.[7] Customers moving from on-premises CxSAST can receive temporary migration licences. These may scan only code from developers licensed as Checkmarx One Contributing Developers.[8] Catalog: SAST migration licences only scan code from licensed Contributing Developers.

Audits and compliance

Only the tenant Admin role can open the License screen. Its Developers card shows the Contributing Developers count and Developer Assist seat usage by IDE. A CSV export lists each contributing developer’s email address, a timestamp the documentation describes as that of the last comment, and the Checkmarx One project.[5] Catalog: Checkmarx One exports a Contributing Developers report. Under the Terms of Service, Checkmarx may ask for a signed certification of compliance and for usage records. Excess usage must be bought, with fees running from the date the excess began.[6] Several practical controls follow from these rules:

  • Export the contributing developers report regularly and compare it with the Quote. Watch for duplicate identities caused by several git email addresses.
  • Include service accounts, bots and AI coding agents that commit to scanned repositories. Under version 2026.09 they count.
  • Track total lines scanned per 90 days against the pooled limit, particularly when adding large monorepos.
  • Monitor the Credit balance and burn rate where Checkmarx One Assist is used.

See software license audit.

Out of scope

  • Developer Assist seat terms, which the License screen reports but the License Types page does not define.
  • Credit consumption rates per AI Action, which are set in the Quote or Documentation.
  • Prices and package discounts.

References

  1. Checkmarx One License Types and Restrictions (version 2026.09)Last Updated September 24, 2026. Catalog: Checkmarx One License Types and Restrictions (2026.09)Effective 2026-09-24. Retrieved 2026-10-07.
  2. Checkmarx One License Types and Restrictions V2024.02Last Updated February 19, 2024. Catalog: Checkmarx One License Types and Restrictions (2024.02)Effective 2024-02-19. Retrieved 2026-10-07.
  3. Checkmarx One License Types and Restrictions V2022.08Last Updated August 24, 2022. Catalog: Checkmarx One License Types and Restrictions (2022.08)Effective 2022-08-24. Retrieved 2026-10-07.
  4. Checkmarx One License Types and Restrictions V2022.07Applies to licences purchased 2022-07-01 to 2022-08-23. Catalog: Checkmarx One License Types and Restrictions (2022.07)Effective 2022-07-01. Retrieved 2026-10-07.
  5. Viewing License Info and Upgrading a LicenseLast modified July 27, 2026. Catalog: Viewing License Info and Upgrading a License (Checkmarx One)Effective 2026-07-27. Retrieved 2026-10-07.
  6. Checkmarx Terms of ServiceLicence grant; Credits; Usage Verification. No version date in the text. Catalog: Checkmarx Terms of ServiceRetrieved 2026-10-07.
  7. Checkmarx One Pricing & PackagesUndated. Catalog: Checkmarx One Pricing & PackagesRetrieved 2026-10-07.
  8. Checkmarx SAST License Types and Restrictions (version 2023.02)SAST migration licences. Catalog: Checkmarx SAST License Types and Restrictions (2023.02)Retrieved 2026-10-07.

See also

Catalog Rows Cited

5Metrics16Rules1Programs

Esc