---
title: "XID Cloud is free."
description: "No plans, no tiers, no paid features. If XID Cloud ever charges, it bills only for monthly active users. Self-hosted XID has the same features, with billing off unless you turn it on."
locale: "en"
image: "https://xid.dev/og.png"
---

> Documentation Index
> Fetch the relevant documentation index at: https://xid.dev/en/llms.txt
> Use this file to discover all available pages before exploring further.

# XID Cloud is free.

No plans, no tiers, no paid features. If XID Cloud ever charges, it bills only for monthly active users. Self-hosted XID has the same features, with billing off unless you turn it on.

## XID Cloud: Free today

Operated by XID on xid.dev.

- Every feature
- An organization for your company, and one for each of your customers
- Hosted pages on your organization's subdomain of xid.dev

## Self-hosted: Free, MIT licensed

Run it in your own Cloudflare account.

- Every feature
- No license key, and nothing reports back to XID
- You pay Cloudflare for what your account uses

## If XID Cloud starts charging

- **Usage only:** It bills per monthly active user, and nothing else.
- **No plans:** No feature is ever reserved for paying customers. There are no plans to upgrade to.
- **Nothing switches off:** Billing never signs anyone out or turns off a feature you use.

## How usage is counted

A monthly active user is a person who signs in at least once in a calendar month (UTC). Each person counts once per month across your organization and all of its sub-organizations, however often they sign in. Guest sessions don't count. Your console overview shows the number as Monthly active users.

## Everything is included in both

### Sign-in

- Email code and magic link: Production
- Passkeys: Integration-tested
- MFA: authenticator app, SMS, backup codes, passkey: Integration-tested
- Password with breach checks, social sign-in: Integration-tested

### Hosted pages and organizations

- Hosted sign-in page: Production
- Account page, eight interface languages: Integration-tested
- Switch organizations in one console: Production
- Sub-organizations, members, roles, branding, domain verification: Integration-tested

### Enterprise and developers

- Inbound SAML and OIDC SSO, inbound SCIM 2.0, XID as identity provider: Verified end to end, local
- OpenID Connect: authorization code, PAR, DPoP: Verified end to end, local
- Management API: Production, core paths
- Signed webhooks, hash-chained audit log: Implemented
- SDKs: Not yet published to npm

Status comes from the public evidence matrix in the repository. Only rows marked Production are verified on xid.dev. Self-hosted deployments also get the instance console for every organization on the deployment.

## Questions

### Do I need to pay for SSO, SCIM or MFA?

No. There are no plans or tiers. Every feature is available on XID Cloud and when you self-host.

### Is XID ready for production?

XID is pre-1.0. Hosted sign-in, the console and the Management API core paths are verified in production on xid.dev. Enterprise identity providers, social sign-in and SMS are verified locally only.

### Will XID Cloud start charging?

It is free today. If it ever charges, it bills only per monthly active user, and no feature is reserved for paying customers.

### Are there usage limits on XID Cloud?

None by default. If one is set, it only stops creating new sub-organizations or SSO connections. No limit stops sign-in, sign-up, SSO or SCIM provisioning, or token refresh.

### Can I move from XID Cloud to self-hosting?

It's the same code. You can export users with the Management API; password hashes are not exported, and passkeys need to be registered again on the new domain. There is no one-step migration tool.

### What does self-hosting cost?

Nothing to XID. You pay Cloudflare for what your account uses, and sending email to any recipient needs the Workers Paid plan. You also need a domain whose DNS you control.

### Where is my data on XID Cloud?

In XID's Cloudflare account, on D1, KV, R2 and Durable Objects. Choosing a data region isn't available.

### Do you have SOC 2 or ISO 27001?

Not yet.

Pre-1.0. Core paths of hosted sign-in, the console and the Management API are verified in production on xid.dev. Everything else is verified locally.

Source: https://xid.dev/pricing/index.mdx
