aethercert
Documentation

Plans & limits

What each aethercert plan allows: certificate, agent and domain counts, authorities, deploy targets, key types, check-in cadence, and log retention.

Five plans: Free, Standard, Pro, MSP and MSP Plus. This page is the technical matrix - what each one allows and what happens when you reach a limit. Prices and the commercial comparison are on the pricing page.

Capacity

FreeStandardProMSPMSP Plus
Certificates11501,500150150
Agents1751,0007575
Domains152555
Customer workspaces---5 included, more on demand5 included, more on demand

MSP's and MSP Plus's own numbers are Standard's. They govern the reseller organization's own workspace; each customer workspace runs on the tier of the slot assigned to it and gets that tier's numbers.

A customer who pays for their own Standard or Pro subscription keeps it when an MSP takes over managing them, and does not use one of the included places. Their plan and renewal date stay their own - see MSP customer workspaces.

Capabilities

FreeStandardProMSPMSP Plus
Certificate authoritiesLet's Encrypt onlyAny, including your own internal or private CAAnyAnyAny
Deploy targetsWindows Certificate Store, Linux NGINX / Apache / CustomAllAllAllAll
IIS bindingsNoYesYesYesYes
Exportable private keysNoYesYesYesYes
Agent groupsNoYesYesYesYes
Certificate policiesNoYesYesYesYes
Key typesEC-256 onlyEC-256, EC-384, RSA-2048, RSA-4096AllAllAll
DNS providersAll 217All 217All 217All 217All 217
Monitor integrationsNoNoYesYesYes
White-label branding & custom dashboard domainNoNoNoNoYes
Roles, MFA, passkeys, SSOAll plans

MSP Plus is MSP plus white labeling: your customers reach the dashboard on your own hostname, under your own name, logo, colours and typeface. Everything underneath - containers, database, API, agents - is unchanged. Set it up from MSP > Branding once you are on the plan.

The emails your customers receive follow the same branding: workspace invitations and certificate notifications carry your logo, your company name, your accent colour and your support contact instead of ours. Under MSP > Branding > Customer mail you can also pick one of your own mail apps (the same ones you configure under Monitoring > Email Notifications > Mail apps) to send them, so they leave from your domain and pass your SPF, DKIM and DMARC. If a send through your server fails, the message still goes out through aethercert and the fallback is recorded in your event log.

Messages about your account rather than your customers' - billing, sign-in and password mails - stay aethercert's and are always sent by us.

Add a square favicon under MSP > Branding: it is what a customer gets when they add the dashboard to their home screen, along with your company name.

Timing and retention

FreeStandardProMSPMSP Plus
Idle check-in interval3h, fixed1-3h, configurable30 min-3h, configurable1-3h, configurable1-3h, configurable
Event log retention7 days30 days90 days90 days90 days
Agent local log retention7 days, fixedUp to 30 daysUp to 90 daysUp to 30 daysUp to 30 days

The idle interval is only the idle one. Whenever a job or an update is queued, the control plane shortens any agent's next check-in to roughly 10 seconds regardless of plan, so issuance is never held up by the cadence.

What happens at a limit

Limits are enforced by the server, not just by the interface, so a request that would exceed one is refused whatever sent it.

Limit reachedWhat happens
Certificate, agent or domain countCreating the next one is refused with a message naming the limit. Existing objects are untouched and keep renewing.
A capability you do not haveThe control is visible but disabled, with an upgrade hint. Plan-restricted controls are never hidden, so you can always see what a plan would add.
A check-in interval outside your rangeRejected on save, with the allowed range in the message.
A log retention value above your capRejected on save. A stored value that exceeds a newly lowered cap is clamped at read time instead, so a downgrade takes effect immediately without editing anything.

Changing plan

Upgrading applies immediately to your existing organization. Agents, domains and certificates carry over; nothing is re-created, and no agent needs reinstalling.

Downgrading does not delete anything. What exceeds the new plan's limits keeps working and keeps renewing; you simply cannot create more until you are back under. The capability restrictions, though, do apply from the moment the plan changes:

  • A deploy target the lower plan does not allow will fail validation on the next edit or reissue of the certificate that uses it.
  • Configurable values above the new cap are clamped rather than rejected - see log retention above.

The one thing to plan for is Free, which allows only Let's Encrypt and EC-256. A certificate on another authority or key type will not reissue on Free.

Reading the limits in the product

Two places show them:

  • Settings > Organization > Billing shows your current plan and usage against each limit.
  • Each form disables what your plan does not allow, with the reason.

On this page