Plans and limits
What each aethercert plan allows: certificate, agent and domain counts, authorities, deploy targets, key types, check-in cadence and retention windows.
Five plans: Free, Standard, Pro, MSP and MSP Plus. This page is the technical matrix - what each one allows and what happens when you reach a limit.
Limits are enforced by the server, not just by the interface, so a request that would exceed one is refused whatever sent it.
Capacity
| Free | Standard | Pro | MSP | MSP Plus | |
|---|---|---|---|---|---|
| Certificates | 1 | 150 | 1,500 | 150 | 150 |
| Agents | 1 | 75 | 1,000 | 75 | 75 |
| Domains | 1 | 5 | 25 | 5 | 5 |
| Mail apps | 1 | 3 | 10 | 5 | 5 |
| Customer workspaces | - | - | - | 5 included, more on demand | 5 included, more on demand |
MSP's and MSP Plus's own numbers are Standard's. They govern the reseller organization's own workspace; each customer workspace runs on the tier of the slot assigned to it and gets that tier's numbers.
A customer who pays for their own Standard or Pro subscription keeps it when an MSP takes over managing them, and does not use one of the included places. See MSP customer workspaces.
Capabilities
| Free | Standard | Pro | MSP | MSP Plus | |
|---|---|---|---|---|---|
| Certificate authorities | Let's Encrypt only | Any, including your own internal or private CA | Any | Any | Any |
| Deploy targets | Windows Certificate Store, NGINX, Apache, Custom (Linux) | All 31 | All 31 | All 31 | All 31 |
| IIS bindings | No | Yes | Yes | Yes | Yes |
| Exportable private keys | No | Yes | Yes | Yes | Yes |
| Agent groups and certificate policies | No | Yes | Yes | Yes | Yes |
| Key types | EC-256 only | All four | All four | All four | All four |
| DNS providers | All 217 | All 217 | All 217 | All 217 | All 217 |
| Monitoring integrations and metrics API | No | No | Yes | Yes | Yes |
| Email notifications | Yes | Yes | Yes | Yes | Yes |
| Roles, MFA, passkeys, SSO | Yes, on every plan | ||||
| Reseller: customer workspaces, slots, sharing | No | No | No | Yes | Yes |
| White-label branding and custom dashboard domain | No | No | No | No | Yes |
MSP Plus is MSP plus white labeling and nothing else. Every capacity number above is deliberately identical between the two tiers.
Timing and retention
| Free | Standard | Pro | MSP | MSP Plus | |
|---|---|---|---|---|---|
| Idle check-in interval | 3h, fixed | 1-3h | 30 min-3h | 1-3h | 1-3h |
| Event log and job retention | 7 days | 30 days | 90 days | 90 days | 90 days |
| Agent local log retention | 7 days, fixed | Up to 30 days | Up to 90 days | Up to 30 days | Up to 30 days |
Every plan defaults to a 3-hour idle interval; a plan can only dial it faster, down to its own floor, never slower. And the idle interval is only the idle one: whenever a job or an update is queued, the control plane shortens any agent's next check-in to 10 seconds regardless of plan, so issuance is never held up by the cadence.
What happens at a limit
| Limit reached | What happens |
|---|---|
| Certificate, agent, domain or mail app count | Creating the next one is refused with a message naming the limit. Existing objects are untouched and keep renewing. |
| A capability you do not have | The control is visible but disabled, with an upgrade hint. Plan-restricted controls are never hidden, so you can always see what a plan would add. |
| A check-in interval outside your range | Rejected on save, with the allowed range in the message. |
| A log retention value above your cap | Rejected on save. A stored value that exceeds a newly lowered cap is clamped at read time instead, so a downgrade takes effect immediately without editing anything. |
Changing plan
Upgrading applies immediately. Agents, domains and certificates carry over; nothing is re-created, and no agent needs reinstalling.
Downgrading to a cheaper paid plan is scheduled through Stripe and takes effect at the end of the current period. Until then, the billing page offers to cancel it.
A downgrade deletes nothing. What exceeds the new plan's limits keeps working and keeps renewing; you simply cannot create more until you are back under. The capability restrictions do apply from the moment the plan changes:
- A deploy target the lower plan does not allow fails validation on the next edit or reissue of the certificate that uses it.
- Configurable values above the new cap are clamped rather than rejected - see log retention above.
The case to plan for is Free, which allows only Let's Encrypt and EC-256. A certificate on another authority or key type will not reissue there.
Where to see your usage
Settings > Organization > Billing shows the current plan and usage against each limit. Every form disables what your plan does not allow, with the reason.