Enterprise is a fleet
you size yourself.
No per-seat tax, no “contact sales” wall. Size a cloud fleet by the work you run — active sandboxes, headless slots, and schedulers — under one OpenEng account. Need it inside your own infrastructure? Talk to us: no on-prem edition is announced yet. Launching Q4 2026.
How to buy
Size a cloud fleet. Ask us about on-prem.
Enterprise is a cloud-coordinated fleet you size yourself — active sandboxes, headless slots, and schedulers. Launching Q4 2026; pricing announced at launch. If you need OpenEng AI inside your own infrastructure, talk to us; no on-prem edition is announced yet.
Launching Q4 2026
Enterprise — per-fleet, not per-seat
You size three numbers — active sandboxes, headless slots, and schedulers, up to 100, 100, and 1,000. Nothing can be bought until launch, and pricing is announced then; you can talk to us now, including about on-prem, which is not an announced offering yet.
Enterprise fleet pricing is announced at launch (Q4 2026). Enterprise covers OpenEng AI. The five engineering apps (Terminal, Kubernetes, Data, Git, and Chat) are free for every team, every feature: see the apps.
Why per-fleet
Per-seat pricing taxes the wrong thing.
An agent platform's value is the work it runs unattended, not the number of humans logged in. So Enterprise prices the fleet — the machines and jobs doing the work — and has no seat line at all.
Scale up without renegotiating
Transparent by design
The ceiling
One account. A fleet up to 100 / 100 / 1,000.
A single OpenEng account governs the whole cloud fleet: up to a hundred active sandboxes, a hundred headless slots, and a thousand schedulers — all resolving the same versioned configs, all under one identity.
Those are the limits of the self-serve cloud fleet. Configs are never capped: author and version as many as you need, and every machine started with one of your keys pulls them by name.
Identity & trust
One OpenEng account. The same guarantees, at fleet scale.
One account, and every machine started with one of your keys — laptop, build agent, or scheduled box — resolves your published configs by name. The privacy model that protects a single developer protects the whole fleet, unchanged.
one identity
Author once, run on every machine
On-device inference
Source never transits a third-party API unless you point a role at a hosted model (the included Cloud Planner among them) or attach an MCP server or cell.
No engine telemetry
No analytics SDK, usage beacon, or crash phone-home in the engine. It contacts OpenEng to register its key, fetch your configs, reach the Broker, poll for approvals, and check for updates.
Sealed replies
Every hop is encrypted, and the engine’s streamed replies are sealed end-to-end to your browser: the Broker that relays them cannot read them.
Placeholder secrets
Configs carry ${ENV} names only; real values resolve from the machine env, or from the optional vault if you choose.
The fleet runtime
Headless leases that heal themselves — once the scheduler ships.
The work is designed to run without a browser or a babysitter: a headless box either starts whole or refuses with a precise reason, and never limps along half-configured at 2 a.m. Today the published engine’s openeng headless checks its key, prints the driver it would run, and exits — the work-pull and scheduler loops ship later. This is how the fleet runtime is built to work.
Headless — Pro & Enterprise · the driver ships later
leased
Headless fleet leases
self-heal
Self-healing runners
declared once
Schedulers in the config
Governance
Humans get one session. Servers get keys.
Two auth models, on purpose: an interactive sign-in holds one session per surface with explicit takeover, while every server starts with its own API key — so a fleet scales without fighting your own login.
interactive
One interactive session per surface
HTTP 409 session_exists naming the device that holds the session — so a forgotten or hijacked session is visible, and takeover is always explicit, never silent.servers
A key per machine, revocable centrally
OPENENG_KEY is registered with the API when the engine starts and is never sent to the Broker; a key is shown once, stored server-side only as a hash, and can be rebound or revoked in the Console. A revoked key can’t register an engine again, so a running engine is cut off when its Broker session ends (within 24 hours).auditable
Append-only headless logs
integrity
Checksum-verified updates
Size your fleet, then talk to us.
Tell us about your fleet — write to hello@openeng.app and we’ll walk through headless, keys, and rollout. Paid plans open in Q4 2026, and trial terms are announced at launch. Until then, your team can use the five engineering apps free.