August 4, 2026
Snyk Platform Subscription
Understanding the Snyk Platform Subscription
The Snyk Platform Subscription is a consumption-based license for Snyk platform capabilities. Use of these capabilities draws down Credits from a pre-purchased balance, based on the Rate Card and the units of measure described below. Once the pre-purchased Credit balance is exhausted, any further use will be invoiced as on-demand consumption.
Credits Rate Card
Capability | Credit Consumption Rate | Unit of Measure |
Secrets | 0.66 credits | per Active Contributor per Day |
API and Web | 3.0 credits | per Provisioned Target per Day |
How We Calculate "per Active Contributor per Day"
Credit consumption for platform capabilities measured “per Active Contributor per Day” is determined by the daily count of Active Contributors across all repositories monitored by that capability. Consumption begins on the day monitoring begins and ends the day after the repository is removed from monitoring. A repository monitored for part of a day consumes a full day's Credits.
An Active Contributor is any unique contributor acting for or on your behalf who has made a commit to a private, Snyk-monitored repository during a rolling 90-day period. Active Contributors may be human or non-human. They include, for example, your employees, independent contractors, agents, third-party bots, automated systems, and service accounts. Snyk-native automated bots, such as <snyk-bot@snyk.io>, are excluded from this count.
A repository is monitored by a capability when it is imported into an organization and at least one of its projects is active for that capability. When a project is created for a capability, its status is set to active and remains active until it is deactivated. A repository counts as monitored even if it is not actively scanned on a given day.
To count Active Contributors for a given capability, Snyk identifies each contributor by username across all repositories monitored by that capability. Each unique username counts as one Active Contributor, no matter how many monitored repositories it appears in.
Snyk derives a username from a contributor's email address by lowercasing it, trimming extra spaces, dropping any subaddress (including the plus sign as well as any characters between the parsed username and domain), and removing the domain. The deduplication logic also recognizes common variations of the same identity — such as standard email aliases and the private no-reply addresses used by GitHub and GitLab — to resolve them to a single username. The examples below show how different email formats reduce to a username.
Snyk reserves the right to review account activity and contributor identity data where it reasonably believes username manipulation or other identity patterns are being used to avoid accurate Active Contributor measurement.
Two important callouts:
Personal email addresses: Snyk cannot reliably link a personal email address to a corporate one, so a username derived from a personal email address is counted as an Active Contributor.
IP address domains: An email address whose domain is an IP address is not reduced to a username; the full email address counts as one Active Contributor.
Scenario | Example Email Address | Active Contributor Username |
|---|---|---|
Standard domain email address | john.doe@snyk.io | john.doe |
GitHub private email address | 12345678+jane.doe@users.noreply.github.com | jane.doe |
GitLab private email address | 12345678+john.doe@users.noreply.gitlab.com | john.doe |
Email alias (plus addressing) | jane.doe+qatest@gmail.com | jane.doe |
IP address domain | root@192.0.2.5 | root@192.0.2.5 |
User with Two Emails | mike.smith@snyk.io | mike.smith |
Illustrative Example:

How We Calculate "per Provisioned Target per Day"
Credit consumption for API and Web is based on the number of provisioned targets in your account each day. Consumption begins on the day a target is added and ends the day after it is removed. Any target provisioned for part of a day will consume a full day’s credits.
Each unique base URL defined in the platform is a provisioned target. Admins can view and manage provisioned targets in the Targets section of the API and Web platform.

When a target is deleted, its records are discarded and cannot be recovered.
Provisioned targets include access to various scan types:
Type of Scan | Definition |
Standard Scan | A comprehensive security test that attempts to cover the target application’s entire attack surface. A standard scan maps accessible pages available through the target URL. |
Reduced Scope Scan | A targeted security test that focuses on a defined subset of the application's attack surface. A reduced scope scan is limited to certain URLs, paths, or areas defined by the scan configuration. |
Incremental Scan | A partial scan that scans only new or updated URLs. Incremental scans require a completed standard scan as the baseline. |
Retest | A microscan that retests a vulnerability to confirm that a fix was successfully applied. Retests scan a specific endpoint for a specific vulnerability, enabling you to quickly check if fixes were effective. |
Test Limits
Snyk products may be subject to test limits, as stated in an applicable Order and further detailed on this page.
Credit Usage Policy
Snyk Platform Credits (“Credits”) are a part of the issued subscription allocation and limited license grant to Snyk products and services. When Customer uses Credits, Snyk deducts the number of Credits required for the applicable services from Customer's Credit balance. Credits must be used within the term of the applicable Order, after which any unused Credits will expire and cannot be redeemed, refunded, or credited. Credits are not redeemable for cash and are non-transferable. Upon Customer's exhaustion of its prepaid Credits, Snyk may invoice Customer for any Credits consumed in excess of Customer’s prepaid Credit allocation at the applicable Credit consumption rates set out in the Rate Card and Customer’s per-Credit price set out in the applicable Order.