Administration Billing

Billing

Invoices priced off the metering ledger: the authoritative record of what was actually billed, reconciled to the cent.

Budgets is the pre-call check: it can refuse a call before it spends anything. Billing is the after-the-fact ledger of every call that did spend, priced and totalled.

Every figure on this page reconciles to SUM(metering_events.cost_usd) for the period, the same ledger the budget gate checks against, not a separate analytics pipeline. This page never depends on the observability stack being up.

Reading an invoice

Pick a billing month, a single day, or a date range from the calendar picker. A single day or a whole month gets a real invoice with reconciliation and a pricing snapshot; a multi-day range only has a plain usage summary; there is no per-range invoice.

SectionWhat it shows
ReconciliationThe invoice total compared against the ledger sum for the period. A green "Reconciled" badge means they're equal; a red alert means they aren't, and the ledger figure is the one to trust.
Line itemsCost broken down by model: calls, tokens, and the billable cost. A "recomputed" column re-prices the same tokens through the current rate card for transparency; per-call floors mean it can differ slightly from the billed figure.
Daily spendA day-by-day chart and table for the period, clickable to narrow the whole page to one day.
Pricing snapshotThe exact rate card this invoice was priced with, identified by a content-addressed id, so the invoice is reproducible later, not just a number you have to trust.
Invoice total equals the ledger sum: the reconciliation block shown open
Invoice total equals the ledger sum: the reconciliation block shown open

Download the current view as CSV with Download CSV: the same line items shown on screen, serialized client-side.

Your plan

The plan card: current tier, its limits, and a button per other plan. On the top tier those buttons only read Downgrade; on a lower plan the same slots read Upgrade to <plan>, $<price>/mo instead.
The plan card: current tier, its limits, and a button per other plan. On the top tier those buttons only read Downgrade; on a lower plan the same slots read Upgrade to <plan>, $<price>/mo instead.

The plan card at the top of this page shows your current tier, its price, and a button for every other self-serve plan you could move to. The Limits table beneath it is read live off the plan catalog, so it's never a copy that can drift from what's actually enforced. The table below is the full picture: every numeric limit and every page-level entitlement, side by side.

Limit / featureFreeProEnterprise
Price$0/month$99/monthCustom
TenancyShared gateway and observability infrastructureIsolated: dedicated Langfuse and gateway pods, own trace database, queue, and encryption keysIsolated, same as Pro, plus dedicated database instances available
Seats325Unlimited
Workspaces per org11Multiple
Default monthly budget cap$10$250$1,000
Agents2UnlimitedUnlimited
MCP servers225Custom
Governed requests/month10,000500,000Custom
Tool calls/month10,0001,000,000Custom
Hash-chained audit log—365 daysConfigurable
Trace retention3 days (not yet enforced server-side)30 daysConfigurable
SSO—
SCIM provisioning——
Approvals—
Cost / invoice reporting—
Agent lifecycle (versioning, rollback, retire)—
Outbound guardrails (PII/secrets/denylist scanning, auto-pause)—
RAG and Visual Builder modules—
Durable runs (Temporal)——
Session Insights (Claude Code, Codex, Cursor, and more)——
Signed usage exports——
BYOC / air-gapped deployment——

Every row above is enforced server-side at the same chokepoint that admits or rejects a call, not a marketing description: hitting a numeric limit returns 402 at the API, and opening a page without the entitlement shows the lock card below instead of the feature.

Upgrading

  1. Open Billing

    Every self-serve plan above your current one shows its own button: Upgrade to <plan>: $<price>/mo.

  2. Click it

    You're sent to Stripe Checkout to complete payment.

  3. Complete checkout

    On return, a banner confirms: Payment received: your plan is being activated. The plan card and every newly-unlocked page update once the payment webhook lands.

Already on a paid plan and just need to update a card or see past invoices? Manage billing on the same card opens the Stripe customer portal directly; no plan change involved.

Downgrading

  1. Click the lower plan's button

    Reads Downgrade to <plan>; free reads Downgrade to Free.

  2. If you have more than one active workspace, choose which to keep

    Downgrading allows only one active workspace. A Select Workspace to Keep Active dialog opens automatically, defaulted to your primary workspace; change the selection if a different one should stay live.

  3. Confirm

    Every workspace other than the one you kept freezes immediately: read-only, not deleted. Their data, agents, and logs are preserved untouched, and re-upgrading to a plan with multiple workspaces unfreezes all of them again.

Export & License

Reading a live ledger works when Forgebench can see it. When Forgebench runs inside your own cluster (BYOC or air-gapped), nobody outside it can, so billing has to travel out as a document instead, and entitlement has to be verified locally rather than checked against a server you control. Export & License, linked from this page, is that surface:

BlockWhat it is
LicenseAn offline-verified (Ed25519-signed) entitlement: tier, caps, and how much headroom remains against live usage. This is the same entitlement the chokepoint checks before admitting a call; what shows red here is what returns a 402 there.
Signed usage reportA usage total for a billing month, anchored to the immutable audit hash-chain (a seq range, head row hash and Merkle root per tenant) and signed by the deployment's key. Altering one governed call changes the Merkle root; the number is tamper-evident, not just asserted.
True-upLicensed allowance vs. metered usage vs. overage vs. total due: what gets billed on top of the flat tier, computed the same way regardless of who's reading the report.

A recipient of the signed report re-canonicalizes it and verifies the signature against the deployment's published public key (also shown on this page), so the report is self-verifiable without trusting whoever sent it.

Next