Skip to content
PRICING — UPDATED FOR 2026

Pricing that respects the free tier and Pro when you need it

OpenLib's free tier is a real product. Unlimited public libraries, the full 1.2M+ package index, and the same 180 ms query speed that paid teams get. Pro at $19/month unlocks private package mirroring, SBOM-aware license audits, and 15-minute CVE alerts — the tooling that legal and security teams actually ask for. Team adds the governance layer for engineering organizations.

Indexing 1,247,392 packages · updated 12s ago · live query API →
COMPARE TIERS

Three tiers — pick what you ship today, upgrade when your team grows

Free is built to be useful on its own. Pro is for engineers who run private infrastructure. Team is for organizations that need governance, SSO, and audit trails.

FREE
$0/forever

For individual developers and OSS maintainers curating public lists.

  • Unlimited public library curation
  • Full access to the 1.2M+ package index
  • Production Readiness Index (0–100) on every package
  • Cross-ecosystem search: npm, PyPI, Maven, crates.io, Go, RubyGems
  • Public API: 1,000 requests / day
  • Community support
CREATE FREE LIBRARY
TEAM
$39/seat / mo

For engineering organizations that need governance across many libraries.

  • Everything in Pro
  • Up to 50 seats per workspace
  • SSO (SAML 2.0, OIDC) — Pro+ tier includes SOC 2 Type I controls
  • Audit log + admin console
  • Centralized policy rules (license allow/deny, min. score)
  • Public API: 250,000 requests / day
  • Priority support, 4-hour business SLA
  • Dedicated solutions engineer
START TEAM TRIAL

All prices in USD. Education & qualifying non-profits: Pro is free — request access →

CAPABILITY MATRIX

Everything in each tier, side by side

Audit exactly what's gated. Library curation, private mirroring, SBOM exports, CVE alerts, team seats, SSO, and priority support — across all three tiers.

Capability FREE PRO · $19/mo TEAM · $39/seat
Public library curation Unlimited Unlimited Unlimited
Catalog size indexed 1.2M+ packages 1.2M+ packages 1.2M+ packages
Production Readiness Index Full visibility Full visibility Full visibility
Cross-ecosystem search npm · PyPI · Maven · crates · Go · RubyGems npm · PyPI · Maven · crates · Go · RubyGems npm · PyPI · Maven · crates · Go · RubyGems
Private package mirroring npm · PyPI · Maven · Go npm · PyPI · Maven · Go · RubyGems
CVE alerts (15-min refresh) Yes Yes
SBOM-aware license audit Yes — per library Yes — org-wide policies
Parquet catalog download Latest snapshot, CC-BY-SA 4.0 Daily snapshots Daily snapshots + delta feeds
Public API requests 1,000 / day 50,000 / day 250,000 / day
Seats per workspace 1 1 Up to 50
SSO (SAML 2.0 / OIDC) Included
Audit log + admin console Included
Support SLA Community Email · 1 business day Priority · 4 hours
Dedicated solutions engineer Included
CUSTOMERS

Trusted by 380,000+ developers — including the teams shipping your favorite tools

Engineering organizations on Pro and Team plans use OpenLib to standardize dependency decisions across hundreds of services.

1.2M+
packages indexed across 6 ecosystems
180ms
average query latency, full catalog
9.4M
public API requests served daily
99.97%
API uptime, trailing 12 months
FAQ

Common questions about upgrading, billing, and what "Pro" actually unlocks

The honest answers to the questions engineering leads ask before they put a card on file.

What does "free tier is genuinely useful" mean in practice?

On Free you get unlimited public libraries, the full 1.2M+ package index, the Production Readiness Index on every package, and 1,000 public API requests per day. Solo developers and OSS maintainers run their entire dependency workflow on Free — including the Parquet snapshot, which is published under CC-BY-SA 4.0. The free tier is not a trial. There is no countdown.

When is a 15-minute CVE refresh actually enough?

For most engineering teams, yes. Pro and Team tiers pull from upstream advisories (GHSA, NVD, OSV) every 15 minutes, which is faster than the median commit-to-deploy window. OpenLib is not a real-time WAF or runtime blocker — it's a discovery and audit layer. If you need sub-minute alerting, pair OpenLib with your existing SIEM; we ship webhooks on every CVE update.

How does private mirroring differ from npm private or GitHub Packages?

OpenLib mirrors your private registry as a read-through cache that scores every package against the Production Readiness Index and adds CVE tracking. You point your CI at the OpenLib registry URL; we proxy to your upstream (npm Private, GitHub Packages, Artifactory, etc.) and annotate every install with score, license fitness, and any open CVEs. Nothing leaves your VPC boundary.

Do you offer discounts for students, non-profits, or OSS maintainers?

Yes to all three. Pro is free for verified students (.edu or equivalent) and for qualifying non-profits (501(c)(3) and EU equivalents). OSS maintainers whose projects are in the top quartile of OpenLib's Production Readiness Index get a permanent Pro seat per maintainer. Email us at [email protected] with a link to your project or institution.

START FREE

Start with the free tier — it never asks for a credit card

Unlimited public libraries. The same 99.97% uptime and 180 ms query speed as paid. Upgrade to Pro only when you need private mirroring, 15-minute CVE alerts, or SBOM-aware license audits.

  • · No credit card to start
  • · Cancel Pro any month, keep your libraries
  • · SOC 2 Type I (Type II in progress)