Appearance
Editions
Keel has three editions. Free includes everything needed to run an application in production. Pro adds workflows for growing teams, while Enterprise will add identity, policy, and audit controls for organisations with stricter security requirements.
Free is the default edition. Moving to Pro or Enterprise adds capabilities while keeping your infrastructure and data in your own AWS account.
Coming soon
Pro and Enterprise are coming soon.
Where the line falls
The principle is simple: the security floor is free; organisational scale is paid.
Free contains the complete authentication model: three least-privilege IAM roles, MFA enrolment and enforcement, an IAM user per person, and eight-hour STS sessions. None of that moves behind a licence, because the free product should not be less secure than the paid one.
A licence covers the needs that emerge around a growing team: finer-grained access, non-developers who need to reach internal tools, an auditor asking who ran what, and environments that appear and disappear with branches.
Side by side
| Free | Pro | Enterprise | |
|---|---|---|---|
| Provision, deploy, roll back | ✓ | ✓ | ✓ |
| The dashboard | ✓ | ✓ | ✓ |
| Declared environments (staging, production) | ✓ | ✓ | ✓ |
| A shared VPC and cluster across applications | ✓ | ✓ | ✓ |
| IAM roles, MFA, and a team roster | ✓ (up to 3 people) | ✓ | ✓ |
| Tunnels and a database shell | ✓ | ✓ | ✓ |
| Cost estimates and budgets | ✓ | ✓ | ✓ |
| A preview environment per branch | — | ✓ | ✓ |
| Alarms on application health | — | ✓ | ✓ |
| Internal-only services behind a login | — | ✓ | ✓ |
| A provisioned identity provider | — | ✓ | ✓ |
| Deploy on push, from CI | — | ✓ | ✓ |
| Auditable production shell sessions | — | ✓ | ✓ |
| Attributable, per-person database access | — | ✓ | ✓ |
| A locked, review-only shared platform | — | ✓ | ✓ |
| Operators without AWS keys, with per-capability grants | — | ✓ | ✓ |
| Authorization decision log, including denials | — | ✓ | ✓ |
| Per-app and per-environment roles | — | Planned | Planned |
| Approval gates and deploy windows | — | Planned | Planned |
| Federated identity (Okta, Entra) | — | — | Planned |
| A segregated audit account with Object Lock | — | — | Planned |
The optional Keel control plane itself is not an Enterprise-only product. It can cache shared reads for IAM sessions in every edition and remains removable; direct AWS operation is always available. Pro uses that same account-local control plane to authorize operators and broker narrowly scoped operations.
Enterprise includes everything in Pro. A capability described on the Pro page is never excluded from Enterprise.
What upgrading does not change
Changing edition never changes how a running application works. Services that discover each other through Cloud Map DNS continue to do so after an upgrade. Pro makes an internal load balancer available as an option; it does not migrate services automatically. The edition boundary never reaches into application code.
A lapsed licence never removes access or infrastructure. Keel continues to issue credentials, and it never tears down, disables, or degrades resources it already provisioned. After a 30-day grace period, the CLI stops allowing new use of paid capabilities; access to the AWS account and existing infrastructure remains intact.
How a licence works
A licence is a signed document, not a session with a server: an Ed25519 signature over a small payload, verified against a key compiled into the binary. There is no activation server or network licence check. Keel therefore works in an air-gapped environment and does not depend on Keel-operated infrastructure being available.
bash
# per machine
cp acme.json ~/.keel/license
# or once per AWS account, so a renewal is a single write
export KEEL_LICENSE=ssm:///keel/licenseThe SSM form reads a parameter that you place in your own AWS account, using your own credentials. Keel is not in that path.
Two properties are worth knowing before purchase:
- Perpetual fallback. A licence records the date paid through. Any release built before that date continues to work at the licensed edition permanently, so a lapsed subscription costs access to newer releases rather than the version already paid for.
- Failure resolves to Free. If a licence is missing, unreadable, beyond its grace period without a perpetual fallback, or cannot be verified, Keel runs as Free instead of failing every command. This works because Free is a complete product.
keel license reports the edition in force, where the licence was read from, and the full list of gated capabilities:
bash
keel license
keel license --jsonPricing
Pro will be priced per app-environment and Enterprise per AWS account. Prices and purchasing details will be published before either edition goes on sale.