Pricing & plans

Secure access.
A plan for every stage.

From your first deployment to your entire organization. Choose the features and support that fit your team.

Save 17% annually

For small teams

Starter

Secure access for homelabs and small projects.

Free

No credit card required

Start for free

No credit card required

The essentials, included

  • Up to 6 users and 10 service accounts
  • Native clients for every major platform
  • Email and OpenID Connect authentication
  • Resource-level access policies
  • Audit logs and REST API
  • Gateway load balancing and failover
  • Community support

Free for up to 6 users

For growing teams

Team

Everyday zero trust access for your team.

$50

per seat / year

Billed annually · $4.17/seat/mo equivalent

Get started

Self-serve · No contract

Everything in Starter, plus

  • Up to 500 users
  • Full-tunnel routing
  • Conditional access policies
  • Custom account slug
  • Priority email support

Per user or service account in your account How seats work

For mid-sized organizations

Business

Comprehensive zero trust security for your organization.

$80

per seat / year

Billed annually · $6.67/seat/mo equivalent

Get started

Self-serve · No contract

ALL OF FIREZONE’S FEATURES

  • Everything in Team
  • Directory sync for Google, Entra ID, and Okta
  • Device posture checks
  • Log sinks and SIEM integrations
  • Up to 1,000 users, 200 service accounts, and 200 sites

Per active seat · Rolling 30-day window How seats work

For large organizations

Enterprise

All our features, with the assurance and support you need.

Let’s talk

Pricing tailored to your organization

Talk to sales

30-day trial available

Everything in Business, plus

  • Unlimited users, service accounts, sites, admins, and clients
  • SOC 2 and pentest reports
  • 99.9% uptime SLA
  • Dedicated Slack support
  • White-glove onboarding
  • Roadmap acceleration
  • Annual invoicing and flexible payment methods

Active seats · Custom annual agreement How seats work

All prices in USD.

“Firezone's easy-to-setup, sleek, and simple interface makes management effortless. It perfectly met our zero-trust security needs without the complexity found in other products we tested.”

Mark Sim

Mark Sim

Technical Account Manager, Beakon

“At Strong Compute, we have been using Firezone for over 3 years and it is still the most stable and best VPN solution we tested for remote access.”

Cian Byrne

Cian Byrne

Founding Engineer, Strong Compute

Trusted by teams around the world

CorrDynSquare1WolframTeracloudDouble Eleven

The details

Compare every plan.

Start free. Upgrade when you’re ready.

Swipe the table to compare all four plans.

Firezone plan features, usage limits, support, and billing
What’s includedStarterTeamBusinessEnterprise
Usage & limits
UsersIncludes both admins and end-users of your Firezone account65001,000Unlimited
Service AccountsMachine accounts used to access Resources without a user present10100200Unlimited
SitesSites are a collection of Gateways and Resources that share the same network connectivity context. Typically a subnet or VPC.10100200Unlimited
AdminsUsers with account-wide access to deploy Gateways, manage billing, and edit users, Sites, or other configuration11020Unlimited
PoliciesPolicies control access to Resources (e.g. Group “A” may access Resource “B”)UnlimitedUnlimitedUnlimitedUnlimited
ResourcesAnything you wish to manage access to (e.g. database, VPC, home network, web server, SaaS application)UnlimitedUnlimitedUnlimitedUnlimited
Connected ClientsAny device or machine that the Firezone Client connects from3 per user5 per user10 per userUnlimited
Automation
REST APIManage your Firezone account programmaticallyIncludedIncludedIncludedIncluded
MCP serverConnect AI assistants to read and manage your Firezone account using the Model Context ProtocolIncludedIncludedIncludedIncluded
Networking Features
NAT hole punchingConnect to Resources without opening inbound firewall portsIncludedIncludedIncludedIncluded
Native Firezone ClientsNative client apps for all major platformsIncludedIncludedIncludedIncluded
Split tunnelingRoute traffic to Resources through Firezone leaving other traffic unaffectedIncludedIncludedIncludedIncluded
IPv4 and IPv6 ResourcesConnect to Resources over IPv4 or IPv6IncludedIncludedIncludedIncluded
Automatic NAT64Connect to IPv6-only Resources from IPv4-only networks and vice-versaIncludedIncludedIncludedIncluded
DNS-based routingRoute traffic through Firezone based on DNS matching rulesIncludedIncludedIncludedIncluded
Secure DNSResolve queries for non-Firezone Resources using popular DNS-over-HTTPS providersIncludedIncludedIncludedIncluded
Gateway load-balancingSpread traffic across multiple Gateways within a SiteIncludedIncludedIncludedIncluded
Automatic Gateway failoverClients automatically switch from unhealthy Gateways to healthy onesIncludedIncludedIncludedIncluded
Device PoolsDirect, peer to peer access to other devices in your Firezone accountIncludedIncludedIncludedIncluded
Full-tunnel routingRoute all traffic from select Clients through FirezoneNot includedIncludedIncludedIncluded
Authentication & Authorization
Resource-level access policiesControl access to Resources based on user identity and groupIncludedIncludedIncludedIncluded
Email (OTP) authenticationAuthenticate users with a one-time code sent to their emailIncludedIncludedIncludedIncluded
OpenID Connect authenticationAuthenticate users with any OIDC-compatible providerIncludedIncludedIncludedIncluded
Conditional access policiesAllow access based on source IP, authentication method, time of day, or country.Not includedIncludedIncludedIncluded
Custom account slugCustomize the sign-in URL for your account. E.g. https://app.firezone.dev/your-organizationNot includedIncludedIncludedIncluded
Google Workspace directory syncAutomatically sync users and groups from Google Workspace to FirezoneNot includedNot includedIncludedIncluded
Microsoft Entra ID directory syncAutomatically sync users and groups from Microsoft Entra ID to FirezoneNot includedNot includedIncludedIncluded
Okta directory syncAutomatically sync users and groups from Okta to FirezoneNot includedNot includedIncludedIncluded
Security Features
Session-based key rotationRotate WireGuard encryption keys each time a user signs inIncludedIncludedIncludedIncluded
Client verificationRequire Clients to be marked as verified in the admin portal before they can access ResourcesIncludedIncludedIncludedIncluded
GeoIP MappingShow where your users are connecting fromIncludedIncludedIncludedIncluded
Change LogsSee who changed what in your account configuration and whenIncludedIncludedIncludedIncluded
Session LogsSee who connected, from where, and with which deviceIncludedIncludedIncludedIncluded
API Request LogsSee what every API token did, request by requestIncludedIncludedIncludedIncluded
Network Flow LogsSee what traffic flowed between Clients and ResourcesIncludedIncludedIncludedIncluded
Traffic restrictionsRestrict access to specific ports and protocolsIncludedIncludedIncludedIncluded
Device TrustRequire device attestation using trusted X.509 certificates and cryptographic proof of private-key possession over mutual TLS before granting access to ResourcesIncludedIncludedIncludedIncluded
Device PostureRequire device security checks from your MDM and endpoint protection providers before granting access to ResourcesNot includedNot includedIncludedIncluded
Log SinksStream audit logs directly to Splunk, Datadog, Elastic, and other destinationsNot includedNot includedIncludedIncluded
Firezone service compliance reportsIndependent audit reports of Firezone's service for compliance with industry standardsNot includedNot includedNot includedSOC 2
Firezone service pentest reportsPenetration testing for security vulnerabilities in Firezone's service conducted by a third party firmNot includedNot includedNot includedIncluded
Support & Customer success
GitHub issue trackerIncludedIncludedIncludedIncluded
Priority EmailNot includedIncludedIncludedIncluded
Dedicated SlackNot includedNot includedNot includedIncluded
Roadmap accelerationShape the product roadmap with customized features and integrationsNot includedNot includedNot includedIncluded
White-glove onboardingGet personalized deployment support and training for your teamNot includedNot includedNot includedIncluded
Uptime SLAGuaranteed uptime for your Firezone serviceNot includedNot includedNot included99.9%
Billing & payment
Seat countingSee the FAQ for how billable seats are counted.—All users & service accountsActive in past 30 daysActive in past 30 days
Payment by credit cardPay for your subscription using a credit cardNot includedIncludedIncludedIncluded
Payment by ACH transferPay for your subscription using an ACH transferNot includedIncludedIncludedIncluded
Payment by wire transferPay for your subscription using a wire transferNot includedNot includedNot includedIncluded
Annual invoicingPay for your subscription annuallyNot includedNot includedNot includedIncluded

Good to know

Your questions,
answered.

Need help choosing a plan? Talk to our team.

How are seats counted?

Team uses static seats. Every user or service account present in your account is a billable seat, whether or not they sign in.

Business and Enterprise use active, or floating, seats. Seats are counted by unique users or service accounts that signed in from a Firezone Client during the previous 30 days. Multiple client sign-ins by the same user or service account count as one seat, not additional seats.

For example, if your account has 100 users but only 40 signed in from a client in the previous 30 days, that is 40 active seats on Business or Enterprise. On Team, all 100 users count, plus any service accounts present in the account.

What’s the difference between Business and Enterprise?

Business includes all of Firezone’s product features, including directory sync, device posture checks, and log sinks. It’s self-serve, with no contract, and you can choose monthly or annual billing.

Enterprise adds unlimited usage limits, compliance and pentest reports, a 99.9% uptime SLA, dedicated Slack support, white-glove onboarding, roadmap acceleration, and annual invoicing. These services and contractual commitments are not included in Business. Both plans use the same active-seat counting model.

How do seat changes and prorations work?

Increases take effect immediately. We invoice the prorated amount for the added seats for the remainder of your current billing cycle.

Decreases take effect at the end of your current billing cycle, whether monthly or annual. The seats already paid for remain available until renewal.

For example, adding 5 Business seats halfway through an $80-per-seat annual cycle costs 5 × $80 × ½ = $200, invoiced immediately. Reducing your seats takes effect at the new billing cycle.

How does monthly or annual billing work?

Team is $5 per seat per month or $50 per seat per year. Business is $8 per active seat per month or $80 per active seat per year. Annual subscriptions are charged upfront and save approximately 17% compared with 12 monthly payments.

Choose your billing period when upgrading in the admin portal. Enterprise pricing and annual billing are handled by your account manager.

Can I try Firezone before I buy?

Yes. Start with the free Starter plan, with no credit card required. To evaluate Enterprise, contact sales for a 30-day trial.

What payment methods are available?

Team and Business support self-serve payment by credit card or ACH. Business does not offer invoiced payment terms. Enterprise also supports wire transfers and annual invoicing. Starter is free and requires no payment method.

How do I change or cancel my plan?

Manage Team and Business subscriptions in your Firezone admin portal’s Account settings. For Enterprise, contact your account manager. Decreases take effect at the end of the current billing cycle. To delete your account, cancel your subscription first, then schedule account deletion from Settings → Account.

How long does setup take?

A simple deployment takes less than 10 minutes: install the Firezone Client and deploy a Gateway on your infrastructure. Follow our quickstart guide to connect your first resource. You can run Firezone alongside your existing VPN when they access different resources, and migrate at your own pace.

Does my traffic pass through Firezone?

Traffic is end-to-end encrypted and, by default, routes directly to Gateways on your infrastructure. If a direct connection cannot be established, encrypted traffic can pass through our relay network. Firezone cannot decrypt the contents of your traffic.

Can I self-host Firezone?

The full source code is available in our GitHub repository, and you can self-host it for your organization. We do not currently offer documentation or support for self-hosting the entire platform. On every hosted plan, you deploy Gateways on your own infrastructure.

Do you offer nonprofit or education discounts?

Yes. Nonprofits and educational institutions are eligible for a 50% discount. Contact sales to request it.

Your next connection starts here.

Deploy in minutes. Start free, with no credit card required.