HashiCorp Vault licensing covers the commercial editions of Vault, HashiCorp’s secrets management product. Vault Enterprise is self-managed. HCP Vault Dedicated is a HashiCorp-hosted cluster service, and HCP Vault Radar is a hosted secret-scanning service. The usual unit of measure is the Vault client. “Anything that connects and authenticates to Vault to accomplish a task is a client.”[1] This covers human users, applications and microservices, servers and platforms such as virtual machines, containers and Kubernetes pods, orchestrators and CI/CD pipelines, and Vault agents and proxies.[1] Since Vault Enterprise 1.21, a cluster can instead be licensed by the number of certificates issued through the PKI secrets engine.[4] Licence keys control how long Vault Enterprise can be used and which features are available.[4] The contractual quantity is whatever the Order Form states as Entitlements.[13]
Editions
| Edition | Delivery | Published price[10] |
|---|---|---|
| Vault Enterprise Essentials, Standard, Premium | Self-managed | Custom pricing; Premium support included |
| HCP Vault Dedicated Development | Hosted | From USD 0.62 per cluster per hour; up to 25 clients |
| HCP Vault Dedicated Essentials | Hosted | From USD 1.58 per cluster per hour, plus USD 73 per Vault client per month |
| HCP Vault Dedicated Standard | Hosted | From USD 1.85 per cluster per hour, plus USD 73 per Vault client per month; adds multi-datacenter replication |
| HCP Vault Radar Essentials | Hosted | From USD 7.00 per active contributor per month; 30-day free trial with product limits |
The pricing page lists agentic IAM as an add-on for Vault Enterprise.[10] HCP billing definitions also name a Starter edition of HCP Vault Dedicated, which is not available on Flex Multiyear.[9]
When Vault Enterprise is bought through IBM Passport Advantage Online, the licence key names an entitlement. The server must select it with a license_entitlement stanza. The documented entitlements and IBM part numbers are:[5]
| IBM offering | Part number | license_entitlement |
|---|---|---|
| IBM Vault Self-Managed Essentials | D1015ZX | edition = “essentials” |
| IBM Vault Self-Managed Standard | D101FZX | edition = “standard” |
| IBM Vault Self-Managed Premium | D101AZX | edition = “premium” |
| IBM Vault Self-Managed PKI Certificate Add-On Install | D1406ZX | edition = “premium”, add_ons = “pki-only” |
| IBM Vault Self Managed Platform Standard Install | D15FQZX | edition = “platform-standard” |
| IBM Vault Self Managed Platform Standard including KMIP Install | D155LZX | edition = “platform-standard”, add_ons = “kmip” |
Passport Advantage Online keys do not yet support the Advanced Data Protection (ADP) Key Management and Transform add-ons. Clusters that need those must keep using a HashiCorp licence key.[5] If the configured entitlement does not match the key, Vault fails to start. If several entitlements match, it uses the one with the termination date farthest in the future.[5]
Metrics
Vault counts four kinds of client:[2]
- Standard entities: one per identity, based on the authentication method. Entity aliases let a client authenticate with several methods but still count as one entity.[1]
- Constructed entities for non-entity tokens. Since Vault 1.9, non-entity tokens with the same namespace and policy assignments count as one client.[1]
- Certificate entities for ACME connections. All ACME requests for the same certificate identifier count as one entity.[1]
- Secret sync clients: each secret synced to at least one destination. One secret synced to several destinations counts once.[1]
The documented formula per cluster is the sum of unique standard entities, unique constructed entities, unique certificate entities and unique synced secrets.[2] In agentic workflows (Enterprise), an AI agent becomes a client on its first successful API action. When it acts on behalf of a subject, the agent and the subject are counted as separate clients.[2]
For HCP Vault Dedicated, the HCP Vault Dedicated Client is defined as a unique application, service or user that consumes the service. The cluster is charged per hour from creation to deletion, with partial hours charged by the minute, at a rate set by edition and cluster size.[9] The Vault PKI certificate issued metric applies to PKI-only clusters.[4] HCP Vault Radar is charged per active contributor, a human or machine identity that contributed to a scanned data source in the month.[9]
Counting / floors
Billing period. Only clients active in the billing period count, and each counts once however often it authenticates. The billing period is monthly on HCP and annual for self-managed Vault (catalog rule).[3] Vault records a client once per calendar month. At month end it de-duplicates against earlier months, so a client active every month counts once for the year.[2] The billing start date defaults to the licence start date (or the Passport Advantage entitlement start date). From Vault 1.16.7 and 1.17.3 it rolls forward each year, so reports cover one year of use.[8]
Per cluster. Vault does not aggregate or de-duplicate clients across clusters (catalog rule).[2] On HCP Vault Dedicated, a client that authenticates to several clusters counts as several clients. Development and Starter clusters are the exception (catalog rule).[9]
Namespaces and mounts. A client that authenticates in a parent namespace keeps the same entity in its child namespaces. A client that authenticates across namespace boundaries counts as two entities (catalog rule).[1] From Vault 1.10, migrating mounts across namespaces duplicates clients, and migrating within a namespace does not.[3]
Shared identifiers. Multiple instances of a microservice that share one AppRole role ID count as one client. HashiCorp says distinct clients should therefore be configured with distinct identifiers.[1] Tokens created outside the identity system with no entity count as one client each in production.[1] Nomad’s Vault integration with Workload Identity counts one client per Nomad job when the recommended user_claim of nomad_job is used.[3]
Certificates. Vault Enterprise 1.21 and later count every certificate issued across all PKI mounts without de-duplication. Two certificates with the same CN and SANs count twice (catalog rule).[6] Counts are persisted about every two minutes, and counts from that interval may be lost if a node terminates before persisting them. Certificates issued at the end of a day may be counted on the next day.[6] A PKI-only cluster rejects API requests to any secrets engine other than PKI and hides the client usage dashboard.[4]
Floors. HCP Vault Dedicated Development allows at most 25 clients per month (catalog rule).[9] HCP trial organizations may create only one Vault Dedicated cluster.[11]
Utilization reporting
Vault Enterprise reports utilization to IBM in one of two ways. Automated reporting makes an outbound HTTPS call about every 24 hours. Manual reporting means exporting the data and uploading it. The licence agreement may require reporting at a set cadence (catalog rule).[7] From Vault 1.16.0, 1.15.6 and 1.14.10, client counting cannot be disabled because manual utilization reporting is always on.[3] A cluster can be marked as non-production with development_cluster = true. The designation must comply with the licence agreement and be applied consistently across replicated clusters (catalog rule).[7] Under the General Terms, usage above Entitlements must be reported to IBM and is added to the Order Form.[13]
Virtualization & partitioning
The client metric counts identities, not servers or cores, so the number of Vault nodes and their virtualization do not change the count. Clusters do matter, because counts are kept per cluster.[2] Activity logs and precomputed reports are included in disaster recovery replication.[2] If the development_cluster setting differs across replicated clusters, a DR secondary may start reporting after a failover. A promoted performance-replication secondary uses its own setting.[7]
Cloud / BYOL
Vault Enterprise licence keys do not apply to HCP Vault Dedicated clusters.[4] HCP Vault Dedicated is billed as a service, per cluster hour and per client, through PAYG or Flex Multiyear. Its Starter edition is excluded from Flex Multiyear.[9] Self-managed Vault Enterprise may run in any cloud the customer chooses (see HashiCorp licensing).
Licence keys and expiry
Each Vault Enterprise licence key has a start date and an expiration date. Vault versions released after the expiration date cannot start, restart or unseal, so security fixes released after expiry cannot be applied. Versions released before expiry keep working (catalog rule).[4] Some keys also enforce a termination date, after which no version of Vault can start, restart or unseal:[4]
| Key type | Issued | Termination date[4] |
|---|---|---|
| Commercial | After September 2025 | 60 days after expiration |
| Commercial | Before September 2025 | Non-terminating, or 10 years after expiration |
| Trial | Any | On, or one day after, expiration |
IBM Passport Advantage Online keys always enforce the termination date (catalog rule).[4] The customer must comply with the licence agreement whatever the key enforces. Continued use after the subscription period expires may breach the agreement (catalog rule).[4]
Programs
Vault Enterprise is sold under the self-managed terms described in HashiCorp licensing, directly or through IBM Passport Advantage (program row).[5] HCP Vault Dedicated and HCP Vault Radar are sold through PAYG or Flex Multiyear. HCP Vault Radar is available only on Flex Multiyear according to the billing definitions.[9] Vault Enterprise v1.19 is the last LTS version, supported until April 2027. Later releases follow IBM’s Support Cycle-2 or the March 2025 to April 2026 support addendum.[12]
Out of scope
This article does not cover Vault Community Edition (see HashiCorp Business Source License), KMIP client counting (which the client count API does not report),[3] or anonymous product usage reporting. Contract prices for Vault Enterprise and the ADP add-ons, which HashiCorp does not publish, are also excluded.