Go to home page

Fair Use Policy

1. Purpose

This Fair Use Policy (“FUP”) is designed to ensure that WSO2 Identity Platform SaaS remains a fast, reliable, and secure Identity and Access Management (IAM) service for all customers. WSO2 Identity Platform SaaS can be deployed as a multi-tenant platform, the actions of one user can impact the performance of others. This policy sets out reasonable expectations for service usage.

2. Definitions

"Fair Use" means the use of WSO2 Identity Platform SaaS resources (including APIs, Console access, authentication flows, and other platform resources) in a manner consistent with the intended use of the Services and that does not, as reasonably determined by WSO2, adversely affect, degrade, impair, or create an unreasonable or disproportionate burden on the performance, availability, security, stability, or operation of the Services or WSO2's infrastructure.

3. Usage Limits and Thresholds

Your use of WSO2 Identity Platform SaaS is subject to your Order, WSO2 Identity Platform Pricing page and Fair Use. Creating multiple "dummy" organizations to bypass these limits is prohibited.

Further all WSO2 Identity Platform subscriptions will also shave API Rate Limits and those endpoints are subject to a default rate limit (e.g., 200 requests per minute per IP address). Deliberate attempts to circumvent these limits via IP rotation or distributed requests are considered a violation of this FUP.

4. Prohibited Activities

Under this FUP, the following activities are strictly prohibited:

  • Automated Abuse: Using automated scripts or bots to create large volumes of accounts (Account Harvesting) or to perform continuous login/logout cycles.
  • Load and Penetration Testing: Customers shall submit the performance testing form in advance to WSO2 if they wish to perform any high volume performance testing or security penetration testing. Any testing shall be conducted only after WSO2 accepts the form, informs the Customer of this and 14 days after the WSO2 acceptance date. Denial of Service (DoS) testing is strictly prohibited under all circumstances.
  • Resource Scraping: Using automated means to scrape data from the WSO2 Identity Platform console or My Account portal.
  • Spamming: Using WSO2 Identity Platform SaaS’s email or SMS triggers (such as OTPs or invitations) for marketing or bulk messaging unrelated to identity verification.

5. Monitoring and Enforcement

WSO2 monitors usage patterns across the platform to identify anomalies. If your usage exceeds the "Fair Use" thresholds or disrupts the Service for other tenants, WSO2 reserves the right to do any of the following:

  • Issue a Warning: We will attempt to contact you to discuss your usage and recommend a more appropriate subscription tier or optimization.
  • Throttle Traffic: Temporarily limit the rate of requests to your tenant to protect the platform.
  • Suspend Service: In cases of extreme abuse or where the integrity of the platform is at risk, we may suspend your organization immediately without prior notice. Extreme abuse shall be where WSO2 identifies that there is a system performance degradation due to the actions of the Customer which affects the customer and all other users of WSO2 Identity Platform SaaS to the extent where WSO2 Identity Platform SaaS cannot carry out its normal operations.

6. Operational Messaging (Email, and Push Notifications)

WSO2 Identity Platform SaaS provides certain "out-of-the-box" communication facilities including but not limited to Email, and Push Notifications to support standard identity operations (such as One-Time Passwords (OTP), account recovery, and registration invitations).

  • Not Unlimited: These operational messaging resources are limited, even if your subscription tier does not specify an express usage limit. Their use is subject to this Fair Use Policy and is permitted only for legitimate identity-related transactions.
  • Usage Thresholds: WSO2 reserves the right to impose daily or monthly volume caps on messages sent through WSO2 Identity Platform SaaS’s default shared providers in order to prevent abuse and protect the platform's sender reputation.
  • High-Volume Requirements (BYO Provider): If your business requirements exceed the default Fair Use limits for messaging (e.g., high-frequency login spikes, large-scale user migrations, or bulk invitations), you must Bring Your Own (BYO) messaging provider. In such cases, you must configure your own external messaging gateway (e.g., Twilio, SendGrid, Amazon SES, or Custom SMTP) within your WSO2 Identity Platform SaaS settings.
  • Costs for BYO: When using a BYO messaging provider, you are solely responsible for all costs, delivery rates, and compliance associated with that third-party service.

7. Resources Labeled as "Unlimited"

Any feature, capacity, or resource (including but not limited to Users, Applications, Groups) designated as "Unlimited" in WSO2 Identity Platform SaaS marketing materials, pricing pages, or documentation is intended for normal business operations and is subject to the conditions of this Fair Use Policy.

  • Not Infinite Consumption: "Unlimited" does not mean an absolute right to infinite or extreme consumption of resources that could jeopardize the stability, security, or performance of the multi-tenant WSO2 Identity Platform SaaS.
  • Performance Safeguards: If your consumption of "Unlimited" resources significantly exceeds the average usage patterns of similar organizations or results in technical degradation of the platform, WSO2 reserves the right to impose temporary technical limits (such as throttling) or require you to migrate to a dedicated Enterprise tier better suited for your volume.
  • Prohibited Bulk Use: Use of "Unlimited" resources for high-frequency automated testing, data scraping, or any non-human identity management processes that exceed reasonable industry standards is strictly prohibited.

8. Policy Updates

WSO2 may update this FUP from time to time to reflect changes in service architecture or industry standards. Continued use of WSO2 Identity Platform SaaS after such changes constitutes acceptance of the updated policy.