LICENSEWARE

Veracode DAST, training and platform subscriptions

This article covers Veracode DAST (target URLs and scan capacity), the Security Labs and eLearning seat models, and the platform add-on subscriptions named in Veracode's role documentation. For Static Analysis and SCA, see Veracode Static Analysis and SCA licensing.

On This Page

Veracode DAST, training and platform subscriptions are the Veracode products that are not counted by application scan size. Veracode DAST tests running web applications and APIs. Veracode Security Labs and Veracode eLearning provide developer security training. A group of platform add-ons (Analytics, External Attack Surface Management, Mitigation Proposal Reviews, Vendor Application Security Testing and Enhanced Support) enables specific roles and services. All are sold under the Veracode End User Assessment Agreement, with quantities on the Order Form.[15] For the overview, see Veracode licensing.

Editions

Subscription What Veracode documents Unit 
Veracode DAST (Dynamic Analysis licence) Scans of web applications and APIs. Quick scan and Full scan (Enterprise mode) scopes.[5] Target URLs for API scanning; scan capacity for concurrency[1] 
Veracode Security Labs Hands-on secure coding labs, used through the Veracode Platform or a standalone account[7] Learner seats[6] 
Veracode eLearning Two course tracks, eLearning and eLearning Awareness[9] Seats per track[9] 
Veracode Analytics Custom analytics reports and dashboards[3] Subscription 
Veracode EASM External attack surface management[3] Subscription 
Mitigation Proposal Reviews Review of proposed mitigations[3] Subscription 
Vendor Application Security Testing Third-party (vendor) scan requests. Might not be available for all organizations.[3] Subscription 
Veracode Greenlight IDE scanning. Veracode lists it as deprecated.[3] Individual subscription 

Most of these sit on a base Veracode Platform subscription. Veracode’s custom role reference repeatedly says that permissions require it.[12]

Metrics

Target URL (DAST). Using DAST or Dynamic Analysis requires a Dynamic Analysis licence. To scan APIs from specifications or Postman Collections, Veracode counts the target URLs in that licence. Each target URL equates to a unique API server defined in the specifications.[1] The API specification documentation says the same, under a heading on the licence to scan APIs.[2] Catalog: Each API server scanned deducts a target URL.

Scan capacity (DAST). A separate scan capacity subscription determines how many DAST or Dynamic Analysis scans can run concurrently.[1] The public documentation does not give the default capacity.

Learner seat (Security Labs). An organisation has a license pool of a set number of learner seats. Only users with the Security Labs User role consume a seat.[6] Catalog: Each Security Labs User role assignment consumes a seat; Only Security Labs learners consume seats.

eLearning seat. Each eLearning subscription maps to a track. An organisation that subscribes to both tracks has a separate seat allocation for each, and a learner can be assigned to only one track.[9]

Counting / floors

Each API server counts. During a specification scan, Veracode detects the target API server and deducts it from the target URLs available. Scanning the same specification against a second server deducts a second target URL.[2][1] Test, staging and production instances of one API can therefore consume three target URLs. Catalog: Same specification against a second server uses a second target URL. Veracode directs customers to their sales representative to obtain or change a Dynamic Analysis licence.[1]

Dynamic scans in consumption reports. The license consumption reports cover scan activity for both Static Analysis and Dynamic Analysis.[14]

Security Labs: assignment consumes. Every assignment of the Security Labs User role consumes a licence, and removing a Security Labs user frees one. To move a seat from one user to another, the administrator disables the user whose seat is to be moved.[6]

eLearning: access consumes. Assigning a track allocates a seat, but the seat is not used until the learner accesses a course. Until then it can be reassigned. Once a learner launches a course, the seat cannot be removed until the end of the subscription period.[9] A three-year subscription is usually divided into three subscription years. A seat in use can be removed in mid-year only if the learner leaves the organisation. With Auto Extend off, seats can be reallocated at the end of a subscription year.[9] Catalog: An eLearning seat is used only when a course is accessed; An eLearning seat in use stays with the learner for the subscription period.

Auto Extend. Auto Extend is on by default when a learner is assigned a track, and it renews that learner’s seat when the subscription renews. If the organisation reduces its seat count between subscriptions while learners have Auto Extend on, eLearning locks the course tracks for all learners. Access returns only when the number of Auto Extend learners is brought within the available seats.[9] Catalog: Reducing eLearning seats with Auto Extend on locks all tracks. This is the main renewal trap for a licence manager reducing a training subscription.

Floors. No minimum quantities are published for any of these products.

Virtualization & partitioning

DAST counts API servers, not the machines behind them. The EUAA lets a web Application be supplied for Assessment by providing its URL.[15] Training seats are user-based. Neither is affected by virtualization.

Cloud / BYOL

All of these products are delivered from the Veracode Platform. Targets must be externally accessible to Veracode for scanning.[1] Veracode recommends scanning a test or staging system rather than production for invasive scans such as Full scan (Enterprise mode).[5] When creating a target, the user must certify the right to scan the target URL.[4] Under the EUAA, Veracode excludes liability for harm to customer systems arising from penetration tests and simulated attacks.[15]

Programs

Audits and compliance

Training seat usage is visible in the platform. The eLearning Subscription Details page shows total seats, seats assigned, seats used and learners set to Auto Extend for each track.[9] For DAST, the number of target URLs used should be reconciled with the licence before new API environments are added. Each new server counts separately.[2] Automation against the platform is also limited by rate rather than by licence: all REST APIs are limited to 500 calls per minute per IP address.[13] Catalog: REST APIs are limited to 500 calls per minute per IP address. See software license audit and named user licensing.

Out of scope

  • Penetration testing services, which are scoped per engagement.
  • The default scan capacity and target URL quantities in individual contracts.
  • Prices for training seats and add-ons, which Veracode does not publish.

References

  1. Scan web applications and APIsDynamic Analysis licence; scan capacity; licensing for API scanning. Last updated on Sep 2, 2026. Catalog: Scan web applications and APIsEffective 2026-09-02. Retrieved 2026-10-07.
  2. About API specification scansLicense to scan APIs. Last updated on Jun 15, 2026. Catalog: About API specification scansEffective 2026-06-15. Retrieved 2026-10-07.
  3. UI user rolesLicensing column for each role. Last updated on Oct 2, 2026. Catalog: UI user rolesEffective 2026-10-02. Retrieved 2026-10-07.
  4. DAST quickstartFree 14-day trial sign-up; target creation. Last updated on Sep 28, 2026.Effective 2026-09-28. Retrieved 2026-10-07.
  5. DASTQuick scan and Full scan (Enterprise mode). Last updated on Jun 17, 2026.Effective 2026-06-17. Retrieved 2026-10-07.
  6. Manage Security Labs usersSecurity Labs licenses. Last updated on Oct 5, 2026. Catalog: Manage Security Labs usersEffective 2026-10-05. Retrieved 2026-10-07.
  7. Security Labs quickstartAccess routes and 14-day free trial. Last updated on Sep 28, 2026. Catalog: Security Labs quickstartEffective 2026-09-28. Retrieved 2026-10-07.
  8. About Security Labs Community EditionDeprecated on July 31, 2026. Last updated on Aug 10, 2026. Catalog: About Security Labs Community EditionEffective 2026-08-10. Retrieved 2026-10-07.
  9. eLearning subscriptions, tracks, and seat usageLast updated on May 6, 2026. Catalog: eLearning subscriptions, tracks, and seat usageEffective 2026-05-06. Retrieved 2026-10-07.
  10. Schedule a consultationEnhanced Support and next-day consultation subscriptions. Last updated on Sep 2, 2026. Catalog: Schedule a consultationEffective 2026-09-02. Retrieved 2026-10-07.
  11. Technical and Program SupportSupport hours and channels; undated. Catalog: Technical and Program Support pageRetrieved 2026-10-07.
  12. Custom user rolesLicensing prerequisites per permission. Last updated on Oct 2, 2026. Catalog: Custom user rolesEffective 2026-10-02. Retrieved 2026-10-07.
  13. API rate limitingLast updated on Jun 11, 2026. Catalog: API rate limitingEffective 2026-06-11. Retrieved 2026-10-07.
  14. View and download reports (license consumption reports)Consumption reports cover Static Analysis and Dynamic Analysis. Last updated on Sep 2, 2026. Catalog: View and download reports (license consumption reports)Effective 2026-09-02. Retrieved 2026-10-07.
  15. Veracode End User Assessment Agreement (20240610)Application definition (URL for web applications); s.9 liability for penetration tests. Catalog: End User Assessment Agreement (20240610)Effective 2024-06-10. Retrieved 2026-10-07.

See also

Catalog Rows Cited

9SKUs3Metrics11Rules4Programs

Esc