LICENSEWARE

Snyk Platform Subscription credits and rate card

This article is about Snyk's credit-based enterprise licence, the Snyk Platform Subscription: the rate card, the five units of measure that draw down credits, and the credit usage policy. For developer- and test-based plans see Snyk contributing developers and test limits.

On This Page

The Snyk Platform Subscription is Snyk’s credit-based licence for enterprise customers. Snyk describes it as “a consumption-based license for Snyk platform capabilities”. Use of the capabilities “draws down Credits from a pre-purchased balance, based on the Rate Card and the units of measure”. When the balance runs out, “any further use will be invoiced as on-demand consumption”.[1] The pricing page summarises the model in three steps: buy credits at the start of the subscription, use them on any capability, and pay at the published rates.[2]

The plan applies to credit-based licences bought on or after 1 January 2026. Credit licences bought on or before 31 December 2025 follow the earlier Snyk Platform Access plan.[6] Catalog proof: Credit-based licences are governed by date of purchase.

Editions

There is one credit licence for new customers. “The Snyk Platform Subscription plan consolidates capabilities and features into a single license for quick, flexible deployment.” Credits can be used “across all generally available Snyk capabilities”, and the Tenant Admin turns each capability on or off in Tenant Settings.[4] The pricing page says the same: “Yes. Credits apply across the full Snyk platform.”[2] Snyk Evo capabilities, including AI Pentesting and Coding Agent Security, need this subscription; they are not on the Free or Team plans.[2] Catalog proof: Evo capabilities require an Enterprise Platform Subscription.

The earlier Snyk Platform Access plan also used credits, but drew them down per monitored test. Snyk says that “Customers can no longer purchase or enroll in this plan.”[4][7]

Metrics

Rate card

The pricing page states “1 credit = $1. The pricing unit for all capabilities.”[2] The policy page gives the consumption rates.[1]

Capability Credits Unit of measure 
Code 1.0 per Active Contributor per day 
Open Source 1.0 per Active Contributor per day 
IaC 0.33 per Active Contributor per day 
Secrets 0.66 per Active Contributor per day 
AI-SPM 0.66 per Active Contributor per day 
Container 0.33 per Monitored Image per day 
API and Web 3.0 per Provisioned Target per day 
Coding Agent Security 1.0 per Active Machine per day 
AI Pentesting 4,000 per Assessment 

Source for the table: Credit Based Billing Details.[1] As an illustration of the arithmetic only: at these rates, one Active Contributor monitored by both Code and Open Source for 365 days consumes 730 credits.

The Snyk Platform Credit row holds the contract definition. The Terms define Credits as “the consumption-based units that form part of your Subscription Allocation”.[3]

Counting / floors

Active Contributor per day

An Active Contributor is “any unique contributor acting for or on your behalf who has made a commit to a private, Snyk-monitored repository during a rolling 90-day period”.[1] The count is taken each day, for each capability, across all repositories that capability monitors.[1]

  • Non-human contributors count. “Active Contributors may be human or non-human.” This covers third-party bots, automated systems and service accounts. Snyk-native bots are excluded.[1] Catalog proof: Active Contributors include bots and service accounts.
  • Full days. “A repository monitored for part of a day consumes a full day’s Credits.” Consumption ends the day after the repository is removed from monitoring.[1] Catalog proof: Partial-day monitoring consumes a full day of credits.
  • Monitoring, not scanning. A repository is monitored when it has been imported and at least one of its projects is active for the capability. “A repository counts as monitored even if it is not actively scanned on a given day.”[1]
  • De-duplication by username. Each unique username counts once, however many monitored repositories it appears in. The username comes from the commit email address: lowercased, with the subaddress and the domain removed. GitHub and GitLab no-reply addresses are resolved to one identity.[1]
  • Exceptions to de-duplication. “Snyk cannot reliably link a personal email address to a corporate one, so a username derived from a personal email address is counted as an Active Contributor.” An email address on an IP-address domain is counted as the whole address. A person with two addresses that resolve to different usernames counts as two Active Contributors.[1] Catalog proof: Personal email addresses count as separate Active Contributors.

Snyk also “reserves the right to review account activity and contributor identity data” where it believes that username manipulation is being used to avoid accurate measurement.[1]

Monitored Image per day

A Monitored Image is “any unique container image imported to Snyk, observed in a synced registry, or tested in the CLI or IDE during that day, that has an open Container project”. Images are identified by SHA-256 digest. Snyk counts each image once per day, however many projects, organizations or groups reference it, and however often it is scanned.[1] Catalog proof: Container images are de-duplicated by SHA-256 digest.

Some details change the count. A mutable tag that is rebuilt to a new digest creates a new Monitored Image. “One-time testing via unmonitored test in CLI does not count toward Monitored Image metering since there is no project created.” Dockerfile scans are not metered on this unit. Deleting or archiving a Container project, or de-syncing a registry, stops consumption from the following day.[1]

Provisioned Target per day

For Snyk API & Web, “Each unique base URL defined in the platform is a provisioned target.” A target consumes credits from the day it is added until the day after it is removed. Part of a day counts as a full day.[1] Catalog proof: API and Web targets are billed per base URL per day. A Provisioned Target includes standard, reduced scope and incremental scans, and retests.[1]

Active Machine per day

For Coding Agent Security, “An Active Machine is a developer surface, comprising either an end user device or virtual environment, that runs AI agents.”[1] A machine is active on a day when an Agent Scan or an Agent Guard hook event occurs. It is billed once for that day, however many events occur, and machines with no qualifying event that day consume nothing.[1]

End user devices are identified by an operating system hardware identifier. Virtual environments are identified by the cloud platform owner login, so many short-lived workspaces under one login count as one Active Machine. A developer who runs agents on both a laptop and a cloud workspace counts as two Active Machines.[1] Catalog proof: Local and cloud workspaces count as separate Active Machines.

Assessment

AI Pentesting is billed per completed Assessment. An Assessment is “a complete run of Snyk’s AI pentesting agents against a single Application, including related microservices called by that Application and any post-remediation retesting triggered as part of the Assessment”.[1] “Only completed Assessments count as billable usage; failed scans are excluded from that count.” Scan Failures, such as missing credentials, an unreachable target or WAF blocking, are not charged.[1]

Snyk applies “a token reasoning limit equivalent to $2,000 USD” during testing. When a run nears that limit, the report flags areas that need further work, and the customer may choose to run them as a separate, billable Assessment.[1] Catalog proof: Failed AI Pentesting runs are not charged.

Test limits

The policy page states that “Snyk products may be subject to test limits, as stated in an applicable Order”. Test limits on a credit licence are therefore set in the Order, not on the public plans page.[1]

Virtualization & partitioning

The units are not tied to servers or processors. Container use is counted by image digest across the whole account, and Coding Agent Security by device or cloud login. Moving workloads between hosts does not change either count.[1]

Cloud / BYOL

There is no bring-your-own-licence right. Credits apply only within the customer’s Snyk tenant.[4]

Programs

Credit Usage Policy

The Credit Usage Policy says: “Credits must be used within the term of the applicable Order, after which any unused Credits will expire and cannot be redeemed, refunded, or credited. Credits are not redeemable for cash and are non-transferable.”[1] The Terms of Service contain the same rule, “Unless otherwise stated on an applicable Order Form”.[3] Catalog proof: Unused credits expire at the end of the Order term.

On-Demand Consumption

Running out of credits does not stop the service. The pricing page states that “Exhausting your prepaid credits will not, in itself, result in you losing access”. Further use is tracked and “invoiced in arrears”, and the account team can add credits during the contract.[2] The policy page sets the price: Snyk may invoice excess credits “at the applicable Credit consumption rates set out in the Rate Card and Customer’s per-Credit price set out in the applicable Order”.[1] Catalog proof: Use after credit exhaustion is invoiced as On-Demand Consumption.

Rate changes and renewal

“Snyk announces any changes to rates, including new products or pricing adjustments, 30 days in advance through the” Billing and Usage dashboard.[4] Catalog proof: Rate changes are announced 30 days in advance. At renewal, unless the Order Form says otherwise, “the rates set forth in Snyk’s then-current rate card applicable to Credits, will apply from the commencement of the Renewal Term”.[3] Catalog proof: Renewals are priced at then-current rates and rate card.

Reporting

Tenant Admins see consumption on the Billing and Usage dashboard. It shows the billing period, the credits available, the number of contributing developers, credits used so far, the days left on the subscription and a “Billable events log”. Credit use can be filtered by Group, product and date range.[5]

Legacy Snyk Platform Access

Under the closed Platform Access plan, credits were drawn per monitored test: 10 tests per credit for Open Source, Container and IaC, and 1 test per credit for Code. Unmonitored tests (IDE, CLI snyk test, pull request checks) were free.[7] That plan has a different rule on exhaustion: the customer agrees to negotiate in good faith to buy more credits and “otherwise true-up” its consumption.[7] Catalog proof: Legacy Platform Access requires good-faith credit true-up.

Out of scope

This article does not cover the customer-specific per-credit price, discounts or committed volumes, which are set in each Order. It does not cover premium support and services, which the pricing page lists as available separately.[2] It also does not cover developer- and test-based plans; see Snyk contributing developers and test limits.

References

  1. Snyk Platform Subscription: Credit Based Billing DetailsPage dated 2026-08-04. Rate card, units of measure, test limits and credit usage policy.Effective 2026-08-04. Retrieved 2026-10-07.
  2. Snyk Plans and PricingPlatform Rate Card and enterprise FAQ. Undated.Retrieved 2026-10-07.
  3. Snyk Terms of ServicePage dated 2026-09-18. Sections 6.1, 6.2 and 6.6; Schedule 1 definition of Credits.Effective 2026-09-18. Retrieved 2026-10-07.
  4. Snyk Platform creditsSnyk User Docs. The page shows only a relative last-updated date.Retrieved 2026-10-07.
  5. Usage settingsSnyk User Docs; Billing and Usage dashboard. The page shows only a relative last-updated date.Retrieved 2026-10-07.
  6. What counts as a test?Snyk User Docs. The page shows only a relative last-updated date.Retrieved 2026-10-07.
  7. Definition of Snyk Platform Access - Billable Credits & Rate CardPage dated 2025-04-22. Closed legacy credit plan.Effective 2025-04-22. Retrieved 2026-10-07.

See also

Catalog Rows Cited

14Rules2SKUs6Metrics2Programs

Esc