LICENSEWARE

Cloudflare Zero Trust seat licensing

This article is about how Cloudflare licenses Cloudflare Zero Trust (Cloudflare One) per Seat, and how seats are consumed, held and released. For the overall picture see Cloudflare licensing.

On This Page

Cloudflare Zero Trust seat licensing describes how Cloudflare sells its security service edge and SASE services for a workforce. The Service-Specific Terms describe Cloudflare Zero Trust as “a suite of cloud-based security solutions” for use by a customer’s authorized End Users. Depending on what is bought, it may include Cloudflare Access (zero trust application access), Cloudflare Gateway (secure web gateway and DNS filtering), remote browser isolation, email security (formerly Area 1), a cloud access security broker (CASB) and data loss prevention.[2] Cloudflare One is the single-vendor SASE platform that combines these workspace security services with network services.[1] The licence unit is the Seat: “Cloudflare Zero Trust is made available on a Seat licensing basis, unless a different unit of measurement is specified on your Order Form.”[2] Catalog proof: Zero Trust is licensed per Seat, with substitution allowed.

Editions

The SASE / Zero Trust tab of the pricing page lists three plans.[1]

Plan Intended for List price (USD) User limit Support Standard log retention 
Free “Teams under 50 users or enterprise proof-of-concept tests.” $0 50 users Community forums and Discord Up to 24 hours 
Pay-as-you-go “Teams over 50 solving narrow SSE use cases without enterprise support.” $7 per user per month No limit Chat and ticket Up to 30 days 
Contract “Organizations building toward full-featured SASE or workspace security.” Custom, annual price per user No limit Phone, chat and ticket; professional services as an add-on Up to 6 months; Logpush to SIEM or cloud storage 

Enterprise SASE is also packaged. The Units of Measurement define Interna Essentials, Interna Advantage and Interna Premier as the packages of Services identified on the Interna page.[3] That page describes connecting “remote, hybrid, and branch users with a single per-seat price”, states that devices with the user agent installed are not charged for bandwidth, and says every user license contributes to a shared bandwidth pool for offices and data centres.[6] Add-ons listed for the Interna packages include Dedicated Gateway Egress IPs, Dedicated Gateway DNS Resolver IPs, File Sandbox, the Data Localization Suite and Log Explorer.[6] Catalog proof: Interna seats carry no user bandwidth charges.

Metrics

The Seat is defined in the Units of Measurement as “an employee, agent, contractor, or other third party, in each case, authorized by you to use a Cloudflare Service, as applicable”.[3] The definition is broad. Contractors and other third parties who use the service need seats just like employees.

Gateway DNS filtering adds a volume metric, Average Monthly DNS Queries, which limits how much DNS traffic each Seat covers.[2] The usage-based billing page lists Zero Trust as billing on “Seats and usage-based services”.[7]

Counting / floors

When a seat is consumed

“Cloudflare One subscriptions consist of seats that active users in your account consume.” A user consumes a seat through an authentication event. For Access, this is any Cloudflare Access authentication, such as a login to the App Launcher or an application. For Gateway, it is when any device associated with the user connects within the configured period.[4] The FAQ puts it the same way: users count against a seat when they authenticate to an application or enroll their agent into the Cloudflare One Client.[5]

The count is one seat per person, not per application or login: the user “will occupy and consume a single seat regardless of the number of applications accessed or login events from their user account”. When all seats in the subscription are consumed, “additional users who attempt to log in are blocked”.[4] Exceeding the purchased number of seats therefore causes an access failure rather than an overage charge. Catalog proof: One seat per user, consumed on authentication.

Machine access does not need seats. If there are more accounts than users, Cloudflare suggests an Access bypass policy, and “you can use Access service tokens to allow access to applications without consuming seats”.[4] Catalog proof: Service tokens and bypass policies avoid seat consumption.

How long a seat is held

Seats do not expire by default. “A user who authenticates will hold their seat until you remove the user from your account”, and inactive users are not removed automatically unless seat expiration is turned on.[4] Two dashboard actions are easily confused:

  • Revoke ends active sessions and logs out devices “but will not remove the user’s consumption of an active seat”.[4]
  • Remove frees the seat. The user then shows as Inactive and no longer counts against the seat total, but consumes a seat again on the next authentication. Removing a user also deletes all of that user’s device registrations.[4]

Neither action stops a person from logging in again. To do that, the administrator must change the Access or device enrollment policies, or the identity provider.[5] User records cannot be deleted or archived, but inactive users do not count towards billing.[4] Catalog proof: Seats are held until the user is removed; Revoking a user does not free the seat.

Seat expiration automates the clean-up. When it is on, Cloudflare One removes any user who has not logged in to an Access application and whose devices show no Gateway activity for a chosen period “between one month and one year”. The check runs once a day per account.[4] SCIM provisioning can also remove users when they are deactivated in the identity provider.[4] Catalog proof: Seat expiration removes inactive users after one month to one year.

Substitution and reductions

The Service-Specific Terms allow reassignment: a customer “may substitute an existing End User that occupies a Seat with a new End User in the event of the existing End User’s termination or reassignment to another job function, without incurring an additional Fee”.[2] Seats are added, removed or revoked in the dashboard under Settings, Cloudflare One plan. “If all seats are currently consumed, you must first remove users before decreasing your purchased seat count.”[5] An upgrade is billed when it is selected, and a downgrade applies from the next billing cycle.[5] Catalog proof: Seat count can be lowered only after freeing seats.

Gateway DNS query limit

DNS-only use of Gateway carries a volume floor per seat. “Cloudflare Gateway DNS only is subject to an Average Monthly DNS Queries limit of 150,000 per Seat which is the equivalent of 5,000 DNS queries per Seat per day (assuming a 30-day month).” Cloudflare may monitor Gateway use monthly and may require the customer to buy more Seats if the average is exceeded.[2] The terms give a worked example. A customer with 1,000 Seats is covered for 150,000,000 queries a month. If it sends 200,000,000 queries the next month, the new Seat count is (200,000,000 / 30) / 5,000 = 1,334 Seats, because Cloudflare “will always round up to the next whole number of Seats”. For a purchase in the middle of a month, only the days subscribed are used.[2] This works like a true-up driven by traffic rather than by headcount. Catalog proof: Gateway DNS-only is limited to 150,000 queries per Seat per month; Gateway DNS-only is limited to 150,000 queries per Seat per month.

Virtualization & partitioning

Seats are counted per authorized person, not per device, server or virtual machine, so partitioning rules do not apply. One user with several devices holds one seat.[4] For the Interna packages, Cloudflare says customers get unlimited software connectors and private interconnects to clouds and data centres at no cost and are charged “only” for seats or bandwidth.[6]

Cloud / BYOL

There is no bring-your-own-licence model. The customer is responsible for forwarding users’ DNS queries and traffic to Cloudflare through supported mechanisms (for example the WARP client or GRE tunnels) and for configuring its own identity provider.[2]

Resale is restricted. “You shall not resell Cloudflare Zero Trust to any third parties (e.g., in an ASP, managed security services, outsourcing, time-sharing or service bureau relationship) unless expressly permitted by Cloudflare in writing.” A violation is a material breach and grounds for immediate termination.[2] The Enterprise Subscription Agreement adds a general rule that services are for the customer’s internal business purposes only.[8] A managed security service provider therefore needs Cloudflare’s written permission before using its own subscription for clients. Catalog proof: Zero Trust may not be resold or used for managed services; Enterprise services are for internal business purposes and may not be resold.

Programs

Out of scope

This page does not cover per-domain application services plans (see Cloudflare application services plans), network services billed on bandwidth or prefixes such as Cloudflare WAN, the WAN Connector appliance, or detailed pricing of Zero Trust add-ons, which Cloudflare does not publish.

References

  1. Cloudflare plans and pricingSASE / Zero Trust tab. Catalog: Cloudflare plans and pricingRetrieved 2026-10-07.
  2. Service-Specific Terms: Zero Trust ServicesLast updated September 28, 2026. Catalog: Cloudflare Service-Specific Terms: Zero Trust ServicesEffective 2026-09-28. Retrieved 2026-10-07.
  3. Service-Specific Terms: Other Terms (Units of Measurement)Last updated September 28, 2026. Catalog: Cloudflare Service-Specific Terms: Other Terms (Units of Measurement)Effective 2026-09-28. Retrieved 2026-10-07.
  4. Seat management (Cloudflare One)Last updated May 1, 2026. Catalog: Cloudflare One seat managementEffective 2026-05-01. Retrieved 2026-10-07.
  5. Getting started with Cloudflare Zero Trust FAQLast updated Apr 30, 2026. Catalog: Getting started with Cloudflare Zero Trust FAQEffective 2026-04-30. Retrieved 2026-10-07.
  6. Interna packagesUndated. Catalog: Cloudflare Interna packagesRetrieved 2026-10-07.
  7. Usage-based billingLast updated May 29, 2026. Catalog: Cloudflare usage-based billingEffective 2026-05-29. Retrieved 2026-10-07.
  8. Cloudflare Enterprise Subscription AgreementEffective September 12, 2025. Catalog: Cloudflare Enterprise Subscription AgreementEffective 2025-09-12. Retrieved 2026-10-07.
  9. Preview servicesLast updated May 29, 2026. Catalog: Cloudflare preview servicesEffective 2026-05-29. Retrieved 2026-10-07.

See also

Catalog Rows Cited

12Evidence3SKUs2Metrics5Programs

Esc