Skip to main content
Endor Labs is licensed per contributor per year, with Core and Pro tiers across the Open Source and Code product lines. Each seat comes with a daily scan credit allocation that pools across your contract term, plus support for onboarding multiple repositories. License consumption is measured from the Code Contributors who commit to your monitored repositories. You can track consumption against your contracted count, along with scan credit usage and license details. See license consumption to learn more.

License tiers and SKUs

All license tiers are priced per Code Contributor per year. A Code Contributor is any person who authored or co-authored one or more commits to a private source code repository monitored by Endor Labs in the last 90 days. This is the unit that license consumption is measured in. The current SKU lineup and per-SKU feature lists are maintained on the Endor Labs pricing page. That page is the authoritative source for Endor Labs SKUs and licenses. Each license is sold standalone and priced per code contributor per year. Endor Open Source and Endor Code licenses have scan credit allocations based on the license and the number of code contributors. If you exhaust your scan credits, you need to buy the add-on license Endor Additional Code Scans (EL-ADD-SCANS). This extends scan capacity beyond your per-seat scan credit pool. It is sold in buckets of 10,000 scans.

Entitlements and limits

This section describes how seats, scan credits, repository caps, and overage work across product licenses. The limits described in the following sections are fair usage limits, sized to the number of seats you purchase. The limits are generous and you will never be blocked from scanning. Teams running scan-intensive workflows can purchase additional scan credits if they need to, but most organizations won’t need to.

Per-seat scan credit allocation

Daily allocations accumulate into a shared pool across your contract term. You can draw from this pool flexibly so that a high-volume PR day isn’t blocked as long as the pool has remaining credits.
When a code contributor is licensed for more than one tier, daily allocations stack. For example:
  • OSS Core + Code Core = 2 additional scans / code contributor / day
  • OSS Pro + Code Pro = 3 additional scans / code contributor / day (1.5 + 1.5)
  • OSS Core + Code Pro = 2.5 additional scans / code contributor / day

Included and additional scans

Each code contributor seat supports unlimited default branch scans (typically main or master) for up to 5 repositories. Beyond that, default branch scans are counted as additional scans. A non-default branch scan is any scan you trigger against a branch other than your default branch, such as a feature, release, or hotfix branch. A scan counts based on where you run it and whether it uploads results, not on the scan type you run. These scan types can all count toward scan credits:
  • Dependency scan
  • SAST scan
  • AI SAST scan
  • Secrets scan
  • Source control misconfiguration scan
  • CI/CD tools scan
  • AI model discovery scan
The following scans count toward your credits:
  • Pull request scans
  • Non-default branch scans
  • Default branch scans for repositories beyond the 5 × seats limit
  • AI SAST diff scans without --dry-run
  • MCP scans without --dry-run
The following scans do not count toward your credits:
  • Default branch scans within the 5 × seats repository limit
  • Any scan run with --dry-run, including local IDE scans and AI SAST diff scans
  • SBOM uploads
  • On-premises container scans
  • Binary or package scans

Credit pooling

Credits pool across the full duration of your contract:
  • Annual billing: Credits unlock yearly at each renewal anniversary.
  • Prepaid multi-year contracts: All credits across the full term are available upfront.
For example:
  • 100 OSS Core seats × 1 year = 36,500 scan credits for use during that contract year.
  • 100 OSS Pro seats × 1 year = 54,750 scan credits for use during that contract year (Pro allocates 1.5 / seat / day).
  • 100 OSS Core seats × 3 years prepaid = 109,500 scan credits available upfront across the full term.
Pools provide flexibility within the contract. High-volume PR days are supported as long as the pool has credits remaining.

Overage

If your scan credit pool is exhausted, you can purchase additional scans in buckets of 10,000 scans as Endor Additional Code Scans (EL-ADD-SCANS). The platform continues to function without interruption if you exceed your allocation. Overage is handled through your account team.