aethercert
Dokumentation
Referenz

Plans and limits

What each aethercert plan allows: certificate, agent and domain counts, authorities, deploy targets, key types, check-in cadence and retention windows.

Five plans: Free, Standard, Pro, MSP and MSP Plus. This page is the technical matrix - what each one allows and what happens when you reach a limit.

Limits are enforced by the server, not just by the interface, so a request that would exceed one is refused whatever sent it.

Capacity

FreeStandardProMSPMSP Plus
Certificates11501,500150150
Agents1751,0007575
Domains152555
Mail apps131055
Customer workspaces---5 included, more on demand5 included, more on demand

MSP's and MSP Plus's own numbers are Standard's. They govern the reseller organization's own workspace; each customer workspace runs on the tier of the slot assigned to it and gets that tier's numbers.

A customer who pays for their own Standard or Pro subscription keeps it when an MSP takes over managing them, and does not use one of the included places. See MSP customer workspaces.

Capabilities

FreeStandardProMSPMSP Plus
Certificate authoritiesLet's Encrypt onlyAny, including your own internal or private CAAnyAnyAny
Deploy targetsWindows Certificate Store, NGINX, Apache, Custom (Linux)All 31All 31All 31All 31
IIS bindingsNoYesYesYesYes
Exportable private keysNoYesYesYesYes
Agent groups and certificate policiesNoYesYesYesYes
Key typesEC-256 onlyAll fourAll fourAll fourAll four
DNS providersAll 217All 217All 217All 217All 217
Monitoring integrations and metrics APINoNoYesYesYes
Email notificationsYesYesYesYesYes
Roles, MFA, passkeys, SSOYes, on every plan
Reseller: customer workspaces, slots, sharingNoNoNoYesYes
White-label branding and custom dashboard domainNoNoNoNoYes

MSP Plus is MSP plus white labeling and nothing else. Every capacity number above is deliberately identical between the two tiers.

Timing and retention

FreeStandardProMSPMSP Plus
Idle check-in interval3h, fixed1-3h30 min-3h1-3h1-3h
Event log and job retention7 days30 days90 days90 days90 days
Agent local log retention7 days, fixedUp to 30 daysUp to 90 daysUp to 30 daysUp to 30 days

Every plan defaults to a 3-hour idle interval; a plan can only dial it faster, down to its own floor, never slower. And the idle interval is only the idle one: whenever a job or an update is queued, the control plane shortens any agent's next check-in to 10 seconds regardless of plan, so issuance is never held up by the cadence.

What happens at a limit

Limit reachedWhat happens
Certificate, agent, domain or mail app countCreating the next one is refused with a message naming the limit. Existing objects are untouched and keep renewing.
A capability you do not haveThe control is visible but disabled, with an upgrade hint. Plan-restricted controls are never hidden, so you can always see what a plan would add.
A check-in interval outside your rangeRejected on save, with the allowed range in the message.
A log retention value above your capRejected on save. A stored value that exceeds a newly lowered cap is clamped at read time instead, so a downgrade takes effect immediately without editing anything.

Changing plan

Upgrading applies immediately. Agents, domains and certificates carry over; nothing is re-created, and no agent needs reinstalling.

Downgrading to a cheaper paid plan is scheduled through Stripe and takes effect at the end of the current period. Until then, the billing page offers to cancel it.

A downgrade deletes nothing. What exceeds the new plan's limits keeps working and keeps renewing; you simply cannot create more until you are back under. The capability restrictions do apply from the moment the plan changes:

  • A deploy target the lower plan does not allow fails validation on the next edit or reissue of the certificate that uses it.
  • Configurable values above the new cap are clamped rather than rejected - see log retention above.

The case to plan for is Free, which allows only Let's Encrypt and EC-256. A certificate on another authority or key type will not reissue there.

Where to see your usage

Settings > Organization > Billing shows the current plan and usage against each limit. Every form disables what your plan does not allow, with the reason.

Auf dieser Seite