LICENSEWARE

Kong Gateway open-source and Enterprise licensing

This article is about how self-managed Kong Gateway is licensed: the Apache 2.0 open-source edition, the Enterprise licence file, its expiry behaviour, licence reports, Kubernetes deployment and version support. Konnect pricing is covered in the Konnect article and Kong Mesh in its own article.

On This Page

Kong Gateway is Kong’s API gateway, a reverse proxy that manages and routes requests to APIs and can be extended with plugins.[13] The software is distributed in two licensing forms. The open-source repository is licensed under the Apache License, Version 2.0.[3][4] The commercial form, Kong Gateway Enterprise, adds enterprise features and requires a licence file that Kong issues with a subscription.[1] A third form is not self-managed: when the gateway runs under Kong Konnect, the Gateway introduction states that “all licensing is handled automatically by Konnect”.[13] Catalog proof: Kong Gateway open-source repository is licensed under Apache 2.0.

For a software asset manager the practical questions are which edition a given node is running, whether the node carries a valid licence file, and what a lapsed or missing licence does. This article answers them from Kong’s documentation and release notes, and it explains how self-managed Gateway fits the contracts in Kong Customer Agreement and Product-Specific Terms.

Editions

Edition Licence Deployment topologies Notes 
Kong Gateway OSS Apache License 2.0[3] Traditional and DB-less only[5] The migration guide gives 3.9.3 as the latest supported OSS version[5] 
Kong Gateway Enterprise Subscription; licence file[1] Traditional, DB-less and hybrid mode[5] Fully self-hosted gateways are sold separately with fully custom pricing[11] 
Kong Gateway under Konnect Licensing handled by Konnect[13] Hybrid data planes, Kong-hosted gateways See Kong Konnect plans and usage pricing 

The migration guide states that “Kong Gateway OSS supports only traditional and DB-less deployments”, while Enterprise “also introduces hybrid mode, which separates the control plane and the data plane”.[5] It warns that migration from OSS to Enterprise is irreversible and recommends backing up production data first.[5] The guide’s steps are to install the Enterprise package that matches the installed OSS version, point it at the same data store, and run kong migrations up and kong migrations finish.[5] Catalog proof: Kong Gateway OSS supports only traditional and DB-less deployments; Migration from OSS to Enterprise is irreversible.

Kong’s version support policy lists only Enterprise versions as supported: 3.16, 3.15, 3.14 LTS, 3.13 and 3.10 LTS.[6] The policy defines a Community Edition Patch for versions such as 2.8.3 and 3.3.0, and describes OSS patch numbering, but the supported list contains no OSS release.[6] An inventory should therefore record, for every Gateway node, the edition, the version and the licence source.

Metrics

Self-managed Gateway Enterprise has no single published metric. The licence file is a signed payload. Kong’s documentation shows an example whose fields include admin_seats, customer, dataplanes, license_creation_date, license_expiration_date, license_key, product_subscription and support_plan.[1] The documentation presents the payload as an example only. It does not state in prose how the dataplanes or admin_seats values are enforced, so a catalog row for the licensed data plane field records the fields, not a counting rule. The rate card and the Product-Specific Terms refer to “purchased usage limits under an Order Form”, which are the authoritative figures.[8]

AI plugins add two measures to the licence. Release 3.11.0.0 (2025-07-03) logs a licence model_hours exceeded warning when LLM model usage exceeds the limit.[2] Release 3.13.0.0 (2025-12-18) added a shared filter that marks requests using AI Enterprise plugins for licence enforcement so that AI requests do not “double-dip” on API requests.[2] Catalog proof: Gateway logs a warning when LLM model usage exceeds the licensed model hours; AI Enterprise plugin requests are flagged so they are not double-counted against API requests.

Counting / floors

Where the licence is loaded from. In traditional and hybrid modes Kong Gateway checks, in this order, the KONG_LICENSE_DATA environment variable, the default file /etc/kong/license.json, the file named by KONG_LICENSE_PATH, and a licence deployed through the /licenses Admin API.[1] Each node checks independently when its process starts, and “network connectivity isn’t required for license validation”.[1] Catalog proof: Enterprise licence file is issued with the subscription and checked at node start without network access; Gateway checks licence sources in a fixed order at start-up. Under the Customer Agreement, delivery of Software is complete when Kong makes it available for download and provides the licence key.[12] Catalog proof: Software delivery is complete when the licence key is made available.

How data planes receive it. A licence configured through the /licenses endpoint is sent by the control plane to all data planes in the cluster, and the data planes use the licence with the most recent updated_at. The documentation calls this “the only method that automatically applies the license to data planes”.[1] With a licence file or an environment variable, the control plane does not propagate the licence: each data plane node must start with it, and it cannot be added after the node has started.[1] In DB-less mode a licence in the declarative configuration overrides KONG_LICENSE_DATA.[1] Catalog proof: Only the Admin API method propagates a licence from control plane to data planes.

Expiry. Licences expire at midnight on the expiration date, in the time zone of the control plane. Kong Manager warns 15 days before expiry, and the gateway logs alerts 90 and 30 days before expiry and on and after the expiration date.[1] After expiry, entity configurations become read-only, proxy traffic continues with the existing configuration, nodes can still restart and scale in traditional mode, and “new nodes can’t come up and restarts will break in DB-less mode and KIC”.[1] Release 3.5.0.0 (2023-11-08) already allowed OSS features to keep working with an expired licence and configured Enterprise features to continue in read-only mode, with a daily critical log message during a 30-day grace period.[2] Catalog proof: An expired licence makes entities read-only but proxy traffic continues; Expired licences keep OSS features working and Enterprise features read-only during a 30-day grace period.

No free mode. Release 3.10.0.0 (2025-03-27) removed free mode: “Starting Kong without a license will now function the same as Kong with an expired license”.[2] Release 3.15.0.0 (2026-07-02) made this explicit as a breaking change: without a configured licence, the Admin API is read-only, the proxy continues to serve previously configured traffic, and the /licenses endpoint and keyring recovery endpoints stay writable so a new licence can be uploaded.[2] Catalog proof: Free mode was removed in Kong Gateway 3.10; Without a licence the Admin API is read-only from Kong Gateway 3.15. A team that relied on running the Enterprise image without a licence on versions before 3.10 should check what its nodes do after upgrade.

Licence key as a control. Kong’s malicious-code warranty states that a licence key limiting duration, functionality or scope of use to the purchased subscription is not code that breaches the warranty.[12] Catalog proof: A licence key may limit duration, functionality or scope.

Virtualization & partitioning

Kong Gateway documentation does not tie the licence to processors, sockets or cores. The licence report records the number of online processors of the node that produced it, together with counts of Services, Routes, Consumers, Workspaces, RBAC users and plugin usage by tier (free, enterprise, custom), and request counters.[1] The documents retrieved contain no hard-partitioning or sub-capacity rule of the kind described in virtualization and partitioning.

Cloud / BYOL

Customers run Kong Gateway on their own infrastructure, including third-party clouds, because the Customer Agreement defines the Customer Network Environment to include servers of providers such as AWS, Azure or Google Cloud.[12] The same licence file works in Kubernetes. Kong Ingress Controller version 3.1 introduced a KongLicense resource that applies a licence through the Admin API, and “if a KongLicense resource also exists, it takes precedence over the static KONG_LICENSE_DATA license”.[9] Updating the KongLicense propagates the new licence to all managed Gateway instances without restarting Pods.[9] Kong Operator treats KongLicense as cluster-scoped, so a single resource is shared by all Gateway instances that one Kong Operator installation manages, and one per tenant or namespace is not needed.[10] Catalog proof: KongLicense in Kong Ingress Controller overrides a static licence variable; A single KongLicense is shared by all Gateways managed by one Kong Operator installation.

Programs

Verification and reporting

For Kong API Gateway Enterprise, Kong AI Gateway (on-prem) and Kong Mesh, the Product-Specific Terms require the customer, at Kong’s request, to promptly provide a Software-generated report specified in the Documentation, or data reasonably requested by Kong, to verify use in accordance with the Agreement and purchased limits.[8] The licence report fits that description. The Gateway documentation says the report is generated manually through the Admin API, cannot be scheduled and “doesn’t send data to Kong servers”, and that the customer may share it with Kong Support for a health-check analysis.[1] The terms also allow the customer to disable the Software feature that transmits Usage Data to Kong, after which Kong does not collect Usage Data automatically.[8] Catalog proof: Customer must provide a Software-generated report on request; Licence reports are generated manually and are not sent to Kong; Customer may disable usage-data telemetry from the Software.

Out of scope

This article does not cover Konnect plans (Kong Konnect plans and usage pricing), Kong Mesh (Kong Mesh licensing) or the legal clauses of the Customer Agreement. It does not list individual plugins or say which are free and which require Enterprise, because the retrieved pages describe plugin tiers only as the counts “free, enterprise, custom” in the licence report. Self-managed Enterprise has no published list price, so no price figures are given.[11]

References

  1. Licenses - Kong Gateway | Kong DocsLicence file, loading order, deployment methods, expiry, reports. Undated.Retrieved 2026-10-08.
  2. Kong Gateway changelog | Kong Docs3.5.0.0 grace period; 3.10.0.0 free mode removed; 3.11.0.0 model_hours; 3.13.0.0 AI request counting; 3.15.0.0 read-only Admin API.Retrieved 2026-10-08.
  3. kong/LICENSE at master (Kong/kong on GitHub)Apache License, Version 2.0 text.Retrieved 2026-10-08.
  4. Kong/kong README (GitHub)Licence notice and description of the gateway.Retrieved 2026-10-08.
  5. Migrate from Kong Gateway OSS to Kong Gateway Enterprise | Kong DocsDeployment topologies; irreversible migration; latest supported OSS version 3.9.3. Undated.Retrieved 2026-10-08.
  6. Kong Gateway version support policy | Kong DocsLTS schedule, sunset support, supported Enterprise versions. Undated.Retrieved 2026-10-08.
  7. Kong Support and Maintenance Policys.7(i) Gateway Enterprise support periods; s.8 feature deprecation. Last updated August 31, 2026.Effective 2026-08-31. Retrieved 2026-10-08.
  8. Kong Product-Specific TermsVerification report and telemetry opt-out for Kong API Gateway Enterprise. Last updated September 1, 2026.Effective 2026-09-01. Retrieved 2026-10-08.
  9. Apply an Enterprise license with Kong Ingress Controller | Kong DocsKongLicense CRD and static licence. Undated.Retrieved 2026-10-08.
  10. Enterprise license | Kong Operator DocsKongLicense is cluster-scoped. Undated.Retrieved 2026-10-08.
  11. Kong Pricing for API and AI Connectivity PlatformSelf-hosted gateways are a separate Gateway Enterprise offering with custom pricing.Retrieved 2026-10-08.
  12. Kong Customer Agreements.8.2 delivery of Software and licence key; s.14.3 licence keys. Last updated August 10, 2026.Effective 2026-08-10. Retrieved 2026-10-08.
  13. Kong Gateway | Kong DocsProduct introduction; licensing in Konnect is handled automatically.Retrieved 2026-10-08.

See also

Catalog Rows Cited

22Rules3Metrics1Programs

Esc