JFrog self-managed licensing covers the JFrog Platform when the customer installs it in its own data centre or cloud account. Under the JFrog Subscription Agreement - Self-Managed, JFrog grants a revocable, non-transferable licence for the Subscription Term. The licence lets the customer download, install, access and use the features listed in the Order Form, solely for internal use.[1] The commercial self-managed editions are Pro X, Enterprise X and Enterprise+. JFrog also offers non-commercial editions, which are free.[5] In practice, the licence unit is the Artifactory licence key. Each Artifactory service, and each node of a high-availability cluster, needs one.[2][4]
Editions
| Component | Non-commercial | Pro X | Enterprise X | Enterprise+ |
|---|---|---|---|---|
| Artifactory servers | 1 | 1 | 3 | 6 |
| JFrog Xray | No | Yes | Yes | Yes |
| JFrog Advanced Security (JAS) | No | No | Yes | Yes |
| Xray HA | No | No | Yes | Built in |
| Multi-site push replication, load balancing | No | No | Yes | Yes |
| Distribution Edge nodes, Access Federation | No | No | No | Yes |
All rows are from JFrog’s Feature Comparison Matrix.[5] Pro X includes Xray’s base capabilities: recursive security, licence-compliance and vulnerability scanning. These are separate from JFrog Advanced Security, which requires Enterprise X or Enterprise+.[5] List prices start at USD 27,000 per year for Pro X and USD 51,000 per year for Enterprise X. Enterprise+ is priced on request.[7] Catalog: Self-managed packages include 1, 3 or 6 Artifactory servers; Base Xray scanning comes with Pro X; Advanced Security needs Enterprise X or Enterprise+.
The non-commercial editions are JFrog Container Registry, JFrog Artifactory Open Source (OSS) and JFrog Artifactory Community Edition for C/C++. They provide basic artifact and repository management on one server.[5] Catalog: Non-commercial Artifactory editions; Non-commercial Artifactory editions exclude Xray, HA and replication.
Metrics
Artifactory server licence. Artifactory HA is supported with Enterprise X, Enterprise+ and Edge licences. “Each node in the cluster must be activated with a different license.”[2] Each Artifactory licence activates only one Artifactory service at a time. It can be moved to a different service as long as it remains valid.[4] Catalog: Each Artifactory HA node needs its own licence; One Artifactory licence activates one service at a time and can be moved.
Distribution Edge. Artifactory Edge requires an Enterprise+ licence. An Edge node is created by applying an Edge licence during installation.[6] External Users may download releases from a Distribution Edge, at one Edge per External User, only under Enterprise+ or above.[1] Catalog: Artifactory Edge requires an Enterprise+ licence; External users only through Distribution Edges under Enterprise+.
Contributing Developer. JFrog Advanced Security is charged per Contributing Developer in self-managed deployments too. Enterprise X includes 50 base Contributing Developers and Enterprise+ includes 200.[7] Catalog: Advanced Security is charged per Contributing Developer over 90 days.
Instance. An Instance is a service of the JFrog Platform hosted and managed by the customer, or a Distribution Edge that JFrog hosts for the customer. The number of Instances is one of the Platform Metrics an Order Form may bill on.[1]
Counting / floors
High availability. HA clusters of two or more nodes on one LAN are supported only on self-hosted Enterprise X or Enterprise+. JFrog recommends at least three nodes, and three are required for upgrades without downtime. An external database is mandatory.[3] So a three-node Enterprise X cluster uses all three of the package’s server licences. Any further node, or a separate test instance, needs another licence. Catalog: High availability requires Enterprise X or Enterprise+.
License buckets. A self-managed subscription that includes JFrog Mission Control can use license buckets. Licences are pooled in a bucket and attached to JFrog Platform Deployments (JPDs) through the UI, the JFrog CLI or the REST API.[4] When a bucket is assigned to a service, the JPD works out the minimum number of licences that service needs. An administrator cannot attach fewer than that minimum.[4] Buckets can be split for isolated environments such as development, staging and production.[4] The bucket report shows the highest number of licences ever in use at the same time during the bucket’s validity period. JFrog suggests using that figure when sizing a renewal.[4] Releasing a licence that a running JPD uses invalidates that JPD’s licensing.[4] Catalog: License buckets (Mission Control); License buckets need Mission Control and report peak concurrent licences.
Minimum term. Self-hosted licences are bought on contracts of at least one year. Multi-year contracts are available for Enterprise X and Enterprise+.[7] Fees are paid in advance and are non-refundable unless the agreement says otherwise.[1] Catalog: Subscriptions run at least twelve months unless the Order Form says otherwise; Subscription fees are payable in advance and non-refundable.
Virtualization & partitioning
Licences are counted per Artifactory service or node, not per processor, so a node on a virtual machine or in Kubernetes needs its own licence like a physical server.[2][4] Artifactory can run on Amazon ECS only as a single-node installation, on an instance of up to 16 vCPUs, and without Xray or Distribution.[2] The documents reviewed publish no separate rule for passive disaster-recovery servers; the Order Form governs them. Catalog: Artifactory on Amazon ECS is limited to a 16 vCPU single node. See virtualization and partitioning.
Licence keys and expiry
Termed licences. JFrog licences used to be perpetual. Since Artifactory 7.41, licences are termed: they expire when the contract ends and must be replaced. After expiry, and until renewal, the JFrog Platform becomes read-only.[4] Catalog: An expired self-managed licence makes the platform read-only.
Dynamic License Expiration. On connected platforms, the JFConnect microservice fetches the renewed expiry date from the JFrog Entitlements Server, so no new licence file is needed. The licence file still shows the original date. A new licence must be installed manually in three cases: when the subscription type changes (for example from Enterprise X to Enterprise+), on versions below 7.77.11, or whenever JFConnect cannot load entitlements. Air-gapped installations load entitlements manually.[4] Catalog: Renewed expiry dates load automatically only on connected platforms above 7.77.11.
Programs
Support. Enterprise X includes 24/7 SLA Support and Enterprise+ includes 24/7 High Touch Support. Gold support is optional on Enterprise X and Enterprise+, and Platinum on Enterprise+.[7] Standard Support includes remote support over SSH or VPN. JFrog may change these terms by posting a new version.[10] The customer must keep the platform on a version released within the last eighteen months. Otherwise JFrog is not liable under the platform warranty and need not provide maintenance and support.[1] Catalog: Self-managed platforms must run a version released within 18 months; Standard Support terms can be changed by posting a new version. See software maintenance and support.
Hybrid. A self-managed subscription that includes JFrog-hosted SaaS Features is contracted under the Hybrid agreement instead.
Legacy perpetual licences
Older Artifactory licences were sold under an end user licence agreement. The agreement granted a perpetual licence for internal use, and each licence allowed “a single instance of the Software” on “a single specific hardware system at any time”.[8] Exchanging a licence key terminated the previous key.[8] The Enterprise+ EULA allowed the number of instances set in the Order Form. It also allowed Artifactory Edge to be redistributed or sublicensed, with each Edge instance going to one end user. At JFrog’s request, an authorized officer had to attest how many Edge instances had been sublicensed.[9] Catalog: Legacy Artifactory EULA licences one instance on one hardware system; Legacy Enterprise+ EULA: officer attestation of sublicensed Edge instances.
Contract terms
Customer responsibilities. The Self-Managed agreement makes the customer responsible for several things. It must host the platform to JFrog’s minimum specifications and back up its artifacts. It must not install third-party extensions, plug-ins or workers without JFrog’s written approval. It must monitor its Platform Metrics and report them accurately through MyJFrog when JFrog asks.[1] Catalog: Third-party extensions or plug-ins need JFrog approval; Self-managed customers must monitor and report Platform Metrics on request.
Restrictions and termination. The restrictions forbid giving third parties access by any mechanism, including proxying or caching. They also forbid service bureau use and using any means to avoid fees.[1] If JFrog reasonably believes these restrictions were breached, it may terminate immediately on written notice. For other material breaches there is a 30-day cure period.[1] When the subscription ends, the customer must stop using the JFrog Materials.[1] Catalog: Proxying or caching to avoid fees or give third parties access is prohibited; JFrog may terminate immediately for breach of the licence restrictions.
Resellers. If a reseller fails to pay JFrog, JFrog may collect the fees directly from the customer.[1] Catalog: JFrog may collect directly if a reseller does not pay.
Audits and compliance
The customer must keep complete and accurate records of its use. The records must be good enough to calculate or verify fees and to detect a breach. They must be kept for the term and at least two years after it. During that Audit Period, JFrog, or a third-party auditor it appoints, may audit on reasonable advance written notice, including by email. The customer must cooperate.[1] JFrog may also collect Usage Data about setup, configuration, logs and consumption. One stated purpose is monitoring compliance with the licence restrictions.[1] An effective licence position should count active Artifactory services and HA nodes against purchased server licences, using bucket reports where available. It should then count Edge nodes, and Contributing Developers for Advanced Security. Catalog: Records kept two years after the term; JFrog or a third party may audit. See software license audit and effective license position.
Out of scope
- Negotiated Order Forms and multi-year discounts.
- JFrog Connect device licensing and MLOps bundles.
- SaaS consumption, covered in JFrog SaaS consumption licensing.
- Gold and Platinum support terms in detail.