Plan limits
This is the canonical reference for TokenTimer Cloud plan limits. Prices and plan selection are on the Pricing page.
Core limits
| Limit | Free | Pro | Team |
|---|---|---|---|
| Tokens | 25 per workspace | 500 per organization | 5,000 per organization |
| Workspaces | 1 | 10 | Unlimited |
| Members per organization | 1 | 10 | Unlimited |
| Alert deliveries per month | 30 | 1,000 | 10,000 |
Alert delivery counters reset monthly (UTC, first day of the month). You are warned at 80% of a limit.
On the Free plan the token cap applies per workspace; on Pro and Team it applies across your whole organization (all workspaces you own combined).
Alerting and channels
Channel and recipient limits. See Alerts & thresholds and Contact groups & channels for how these features work.
| Limit | Free | Pro | Team |
|---|---|---|---|
| Email alerts | Yes | Yes | Yes |
| Webhooks (Slack, Teams, Discord, PagerDuty, generic) | No | Yes (5 per workspace) | Yes (5 per workspace) |
| WhatsApp alerts per month (per organization) | 30 | 400 | 1,200 |
| WhatsApp per-minute throttle (per organization) | 10/min | 60/min | 180/min |
| Contact groups per workspace | 3 | Unlimited | Unlimited |
| Members per contact group | 1 | 3 | 10 |
| Weekly digest | No | Yes | Yes |
Integrations and discovery
Automatic credential discovery via integrations (Vault, GitHub, GitLab, AWS, Azure, GCP) and the Domain Checker (subdomain discovery and bulk certificate import).
| Limit | Free | Pro | Team |
|---|---|---|---|
| Integration scans per workspace per month | 3 | Unlimited | Unlimited |
| Domain Checker discovery results per lookup | Not available | 500 | 5,000 |
| Domain Checker certificate imports | Not available | 500 | 5,000 |
Certificates (CertOps)
CertOps is the managed certificate operations layer; machine API tokens authenticate your renewal scripts against it. See Certificates.
| Limit | Free | Pro | Team |
|---|---|---|---|
| Active managed certificate slots per workspace | 0 | 25 | 250 |
| Machine API tokens and executor API | No | Yes | Yes |
| Endpoint SSL monitoring (ssl_cert tokens) | Yes | Yes | Yes |
Only active managed certificates count toward the slot limit; retiring a certificate to revoked or decommissioned frees its slot. See Certificates.
Audit
The audit log records security-relevant actions and alert delivery outcomes.
| Limit | Free | Pro | Team |
|---|---|---|---|
| Audit log access | No (events are still recorded) | Yes | Yes |
| Audit retention | - | 90 days | 1 year |
| Audit export (CSV/JSON) | No | Yes | Yes |
What happens at a limit
- Creations are blocked: reaching a cap (for example the token limit) blocks new creations until you upgrade or clean up. The API returns a limit error; the dashboard shows the limit state.
- Alert deliveries stop: when the monthly delivery cap is reached, further alerts are blocked for the month and recorded as
ALERT_BLOCKED_PLAN_LIMITaudit events. Delivery resumes on the next monthly reset. - Pending invitations count: the member limit check is
active_members + pending_invitations + 1 <= limit. Cancel stale invitations to free slots. See Teams. - Downgrades: see Billing & plans for how limits are applied when moving to a smaller plan.