WZ-IT Logo

ThingsBoard 4.4 under BUSL 1.1: What the License Change Means for Operators

Timo Wevelsiep
Timo Wevelsiep
•
#ThingsBoard #IoT #BUSL #License #OpenSource #SelfHosted #CommunityEdition

Editorial note: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, prices, versions, licensing terms, and external content may change. Please verify the information provided independently, particularly before making business-critical or security-related decisions. This article does not replace individual professional, legal, or tax advice.

ThingsBoard 4.4 under BUSL 1.1: What the License Change Means for Operators

Keep running ThingsBoard after the license change? WZ-IT maps your installation to the new licensing paths, updates it to the current LTS patch and operates ThingsBoard on servers in Germany, see ThingsBoard development and operations in the IoT hub. Book a meeting

With version 4.4, released on 29 September 2026, ThingsBoard changed its license. The split into a Community Edition under Apache 2.0 and a commercial Professional Edition is gone. There is now a single product under the Business Source License 1.1 (BUSL) whose source code stays public, but whose production use is free only within defined limits (ThingsBoard, announcement).

For operators of a self-hosted Community Edition, the situation is less urgent than it first appears. Existing versions remain under Apache 2.0, the 4.3 LTS line receives security updates until July 2027, and a Community Grant keeps existing installations free under 4.4 at their current size. What matters are a few deadlines and details: who gets the grant, what counts as a device and a server, that 4.4 expects regular license validation over the internet, and which features the grant does not include. This article assesses the change based on the license text and vendor documentation, as of October 2026.

Table of Contents

  1. What changes with ThingsBoard 4.4
  2. Free use under BUSL 1.1
  3. License key, license validation and usage data
  4. What happens to the Community Edition
  5. The Community Grant Program
  6. Security updates in 4.4, 4.3 and 4.2
  7. Commercial license and pricing
  8. Options for operators
  9. Alternatives with an open license
  10. Timeline to July 2027
  11. Our approach at WZ-IT
  12. Further guides

What changes with ThingsBoard 4.4

Item Up to version 4.3 From version 4.4
Editions Community Edition (CE) and Professional Edition (PE) one product
Platform license CE: Apache 2.0, PE: commercial Business Source License 1.1
Source code CE public, PE closed fully public on GitHub
Production use without license fee CE unlimited only within the Additional Use Grant
License key CE: not required required for every production deployment
Feature set PE features only with a license same feature set, price based on devices, servers, branding and support
Conversion to Apache 2.0 not applicable per version, four years after release

Sources: license text in the ThingsBoard repository, ThingsBoard BUSL page, release 4.4 on GitHub.

The BUSL is a source-available license created by MariaDB (MariaDB, BSL 1.1). It permits copying, modifying, redistributing and non-production use. Production use is only permitted through the Additional Use Grant defined by the licensor or under a commercial license. After the Change Date, the Change License applies, here Apache 2.0. For ThingsBoard 4.4.0 that date is 29 September 2030. ThingsBoard itself describes the platform as source-available and not as OSI-approved open source (Open Source Definition).

Features previously reserved for the Professional Edition, such as integrations, scheduler, reporting, fine-grained permissions, SSO and secrets storage, are in principle available on every licensing path in 4.4. Payment is tied to scale, white-labeling, clusters in commercial production and the help desk.

Free use under BUSL 1.1

The Additional Use Grant in the license text permits free production use in two cases:

Attribute Commercial use Non-commercial use
Who companies, including internal use accredited educational institutions, non-profit organizations, not for profit
Devices at most 100 across the whole organization at most 1,000 across the whole organization
Servers at most one production server any number
Branding name, logo and "Powered by ThingsBoard" visible and unmodified same
License key free key from the vendor, not circumvented same

Three definitions in the license text determine whether an installation fits these limits:

  • Commercial Purpose: any use in connection with an activity intended for commercial advantage or monetary compensation, explicitly including use in the operations of a for-profit organization. An internal dashboard that three engineers use to watch real machines is production use according to the vendor FAQ.
  • Device: each physical or logical data source, connected directly or through a gateway. A gateway counts only for data it originates. The FAQ gives the example of a pump with 13 sensors, a PLC and a gateway that counts as one device, and a gateway connecting 100 rooms that counts as 100 devices.
  • Organization: the licensee together with every entity that controls it, is controlled by it or is under common control with it. Group companies therefore share the 100 devices.

The commercial grant applies to one Production Instance, which the FAQ defines as a fully functional deployment corresponding to a single server process. A high-availability cluster in commercial production is therefore not covered by free use. Development, testing and staging need no key. Without a key, the software runs in development mode with a visible notice and at most 30 days of cumulative run time; a free development key removes that limit. A standby system that receives replicated data but serves no users and sends no commands is not production until it is activated (ThingsBoard, announcement FAQ).

License key, license validation and usage data

For operators in production networks this part often matters more than the device limit. Every production installation of 4.4 needs a key from the ThingsBoard License Portal.

Aspect Online key (standard) Offline key
Available for Free License, Community Grant, subscription Perpetual License with authorized offline deployment
License validation about hourly with the license server encoded in the key, no validation with the license server
Connection outage tolerated for up to 48 hours, then the management interface locks not relevant
Usage snapshot by default about every 12 hours, can be switched off not sent

According to the vendor, the usage snapshot contains aggregate figures: number of tenants, devices, assets and users, features in use, the previous day's processing volumes, database size and version. Telemetry, message content, names, credentials, configuration and scripts are not included. ThingsBoard itself points out that the data is not anonymous because it travels with the identifiers used for license validation, and that the network address of the instance is recorded. The snapshot can be switched off, license validation cannot.

For an installation in an isolated OT network this means: the free Free License requires an outbound connection to the license server. If that connection is down for more than 48 hours, the management interface locks while devices continue to send data. Anyone who has to run without an internet connection needs a Perpetual License with offline authorization or stays on 4.3 for now. Under the GDPR, the connection to the license server belongs in the record of processing activities and in the firewall rules.

What happens to the Community Edition

The Community Edition is no longer developed as a separate product. Existing versions remain usable:

  • All versions before 4.4 stay under Apache 2.0 permanently (Community Grant Program, FAQ). A running CE needs no key and will not be shut down.
  • The LTS lines continue to be maintained. According to the release policy, as of October 2026:
Version First released Current patch Status End of support
4.3.x 2026-01-20 4.3.1.6 (2026-09-29) Active LTS: security and critical bug fixes 2027-07-20
4.2.x 2025-08-15 4.2.2.6 (2026-09-29) Maintenance LTS: critical security fixes only 2027-02-15
4.1.x 2025-07-03 4.1.0 End of Life 2026-01-03
4.0.x 2025-04-15 End of Life 2025-10-15

After 20 July 2027 there will be no vendor security updates for the Apache 2.0 line. A fork of 4.3 is legally permitted but shifts all maintenance to the operator, including the dependencies of the Java backend and the web UI. The next section shows how much maintenance that involves.

Contributors now sign a Contributor License Agreement once, which allows ThingsBoard to use contributions under future licenses.

The Community Grant Program

The Community Grant Program allows existing CE installations to move to 4.4 and all later versions without paying for their current size.

Rule Value according to the program page
Eligible organizations with a CE installation that was in production before 2026-09-29
Prerequisite for registration latest 4.3 LTS patch, registration from within the platform
Registration deadline until 2027-07-20
Devices count as of 2026-09-29 plus 10 percent, rounded up to the next 10; at least 10 and at most 1,000 extra; at least 100 in total
Production servers number as registered, no headroom; high-availability clusters are covered
Duration does not expire, no renewal required
Included 4.4 and later versions, fine-grained permissions, SSO and OAuth2, secrets storage, branding already applied
Not included integrations, scheduler, reporting, white-labeling features, help desk
Professional Pack USD 2,999 once per deployment for the features not included, help desk in the first year

Example from the program page: an installation with 3,268 devices is granted 3,598 devices, one with 30 devices gets the minimum of 100. Several separate production environments are registered individually and each receives its own capacity. Capacity is calculated once and does not grow. A grant cannot be transferred to another organization.

Registration is done as system administrator via the version card on the platform's home page. A check reads structural data of the installation and produces an encrypted report; according to the vendor, telemetry and device names are not part of it. Registration does not upgrade or restart the installation; the key is only needed when upgrading to 4.4 (registration guide). An offline tool is available for installations without internet access.

According to the program page, anyone who misses the deadline can only move to 4.4 or later with a commercial license if the installation exceeds the free limits.

Security updates in 4.4, 4.3 and 4.2

The release notes of ThingsBoard 4.4 list 26 CVE identifiers as fixed. The underlying changes mainly concern dependencies: npm packages of the web UI and the JavaScript executor as well as Java libraries such as Netty, Jackson, ZooKeeper and FreeMarker (PR 16200, release 4.4).

The same fixes are included in the LTS patches released on 29 September 2026:

Release License Security fixes from the September batch
4.4 BUSL 1.1 included
4.3.1.6 Apache 2.0 included
4.2.2.6 Apache 2.0 included

The release notes of 4.3.1.6 and 4.2.2.6 list only part of the identifiers. According to the Git history, the changes of the third CVE batch are nevertheless contained in both tags. For security, moving to 4.4 is therefore not required until the respective end of support, but updating to the current LTS patch is. Installations on 4.1 or older no longer receive fixes. Ongoing alerts on vulnerabilities in operated components are part of our CVE monitoring.

Commercial license and pricing

According to the vendor, the commercial license matches the previous Professional Edition prices. As of October 2026, the pricing page lists for self-hosted installations:

Plan Price per month Devices Assets Production instances Support White-labeling
Free USD 0 100 100 1 Community no
Pilot USD 99 100 100 1 Help desk yes
Startup USD 299 500 500 2 Priority help desk yes
Business USD 499 1,000 1,000 3 Priority help desk yes

Additional devices cost USD 0.10 per device and month on the Business plan. The Perpetual License starts at USD 4,999 one-time; new versions after the first year require an update fee. Subscriptions are month to month. Hosting, operations and maintenance are not included in the prices for self-hosted installations. A cost overview including ThingsBoard Cloud and Private Cloud is in the article ThingsBoard pricing.

Options for operators

Starting point Obvious path Watch out for
CE in production, stable size update to 4.3.1.6, register the grant, plan the move to 4.4 before July 2027 integrations, scheduler, reporting only with the Professional Pack; online license validation
CE in production, strong growth planned register the grant, calculate the cost of growth beyond the headroom using the pricing page capacity does not grow, headroom at most 1,000 devices
New installation, commercial, up to 100 devices, one server 4.4 with the Free License branding stays visible, no cluster, key and internet connection
New installation with more than 100 devices or high availability commercial license or open stack weigh license cost against custom development and operations
Client platform with custom branding commercial license from Pilot white-labeling is paid at any scale
Isolated network without internet access 4.3 until July 2027, then Perpetual with offline authorization or an alternative Free License and grant use online validation
Educational institution or non-profit organization non-commercial Free License at most 1,000 devices, no profit purpose
Heavily modified CE source code fork of 4.3 under Apache 2.0 or port the changes to 4.4 security maintenance after July 2027 lies with the operator

The first steps are the same in every case with an existing CE: take stock (version, devices under the counting rule, production servers, branding), update to the current 4.3 LTS patch and register the grant while the deadline is open. Registration does not commit you to 4.4, it only secures the option. A guide to installing and updating on your own infrastructure is in the article install ThingsBoard.

Alternatives with an open license

If you need a platform without a license key and without a device cap, you assemble the functionality from individual components. That does not replace everything ThingsBoard bundles in one system, in particular device management, tenants and customer dashboards.

Component Role License (as of October 2026)
ChirpStack LoRaWAN network server, gateway and device management MIT
Node-RED data flows, decoding, rules and forwarding Apache 2.0
Grafana dashboards and alerting AGPL-3.0
Time-series database, e.g. PostgreSQL with TimescaleDB or InfluxDB storage of measurements check per product

Grafana is licensed under the AGPL-3.0, which triggers disclosure obligations when the Grafana code is modified and made available over a network. For plain use and configuration this is usually unproblematic; for a customized client platform it belongs in the review. How ThingsBoard and ChirpStack complement or differ from each other is covered in ThingsBoard vs. ChirpStack and in the article on the IoT stack with ThingsBoard, Grafana and ChirpStack. An overview of further platforms is in the comparison of open IoT platforms.

For client portals with their own device management and branding, a custom IoT platform based on open components can also make sense if white-labeling license costs would otherwise recur permanently. Managed operation of ThingsBoard, ChirpStack and Grafana is also offered by our IoT partner merkaio as ThingsBoard managed hosting.

Timeline to July 2027

Date Event
2026-09-29 ThingsBoard 4.4 under BUSL 1.1, reference date for devices and servers in the grant, registration opens, LTS patches 4.3.1.6 and 4.2.2.6
2027-02-15 end of security fixes for 4.2
2027-07-20 Community Grant registration closes, end of maintenance for 4.3 LTS
2030-09-29 ThingsBoard 4.4.0 becomes Apache 2.0

Sources: Community Grant Program, release policy, license text.

Our approach at WZ-IT

  1. Inventory. Version, devices under the vendor's counting rule, production server processes, branding changes, integrations and network connectivity of the installation.
  2. Update to the current LTS patch. Backup, update to 4.3.1.6 and functional check, so that security fixes are in place and grant registration becomes possible.
  3. Choose the licensing path. Comparison of Free License, Community Grant, Professional Pack and commercial license, and of an open stack. You purchase licenses directly from the vendor.
  4. Plan the move to 4.4. Firewall rule for the license server, decision on the usage snapshot, test in a staging environment, update with a rollback path.
  5. Operations. Monitoring, backups, updates and security patches, support, consulting and implementation by WZ-IT, see ThingsBoard managed hosting.

For a structured assessment of the entire IoT architecture, from devices and protocols to the platform choice, there is the IoT architecture check at a fixed price of €1,490 excluding VAT.

Further guides

Clarify the licensing path for your ThingsBoard installation We take stock, update to the current LTS patch and plan grant registration, the move to 4.4 or an open stack. Book a meeting

Sources

Enquiry

Choose your ThingsBoard licensing path after the move to BUSL

We review device count, servers, branding and network connectivity of your installation, map it to the new licensing paths and plan the update, grant registration or an alternative.

Which decision are you facing?

How should we get back to you?

Frequently Asked Questions

Answers to important questions about this topic

No, not in the sense of the Open Source Definition. ThingsBoard 4.4 is licensed under the Business Source License 1.1 and is therefore source-available: the source code stays public on GitHub, but production use is free only within the Additional Use Grant. All versions before 4.4 remain under Apache 2.0 permanently. Each BUSL version becomes Apache 2.0 four years after its release, so ThingsBoard 4.4.0 converts on 29 September 2030.

Production use is free for commercial use with no more than 100 devices across the whole organization on no more than one server, and for non-commercial use by educational institutions and non-profit organizations with no more than 1,000 devices on any number of servers. In both cases a free license key from ThingsBoard is required, and the name, logo and the 'Powered by ThingsBoard' attribution must stay visible. Development and testing work without a key.

No. Versions before 4.4 remain under Apache 2.0 and need no license key. A running CE 4.3 or 4.2 keeps working unchanged. Costs only arise if you move to 4.4 or later and exceed the free limits without having registered a Community Grant first.

ThingsBoard CE 4.3 is Active LTS and receives security and critical bug fixes until 20 July 2027. Version 4.2 is Maintenance LTS with critical security fixes until 15 February 2027. After that, vendor maintenance of the Apache 2.0 line ends.

The Community Grant keeps existing CE installations free when they move to 4.4. Installations that were in production before 29 September 2026 are eligible. The grant covers the devices as of 29 September 2026 plus 10 percent headroom (rounded up to the next 10, at least 10 and at most 1,000 extra devices, at least 100 in total) and the number of production servers at that date. Registration requires the latest 4.3 LTS patch and is possible until 20 July 2027. The grant does not expire afterwards.

No. The CVE fixes in ThingsBoard 4.4 are also included in the LTS patches 4.3.1.6 and 4.2.2.6, released on the same day (29 September 2026). Until the respective end of support, the current LTS patch is sufficient for security.

With a standard online key, yes. The instance validates its license with the license server about hourly and tolerates interruptions of up to 48 hours. After that, the management interface locks until the next successful check; connected devices keep sending data and nothing is deleted. An offline key is only available for a Perpetual License whose order authorizes offline deployment.

No. In addition to license validation, an online instance by default sends a usage snapshot about every 12 hours with aggregate figures such as the number of tenants, devices and users, features in use, database size and version. According to the vendor, telemetry, message content, names, credentials and scripts are not included. The snapshot is not anonymous and can be switched off with a configuration flag; license validation continues.

Nothing changes for ThingsBoard Cloud; the change concerns the self-hosted platform. The BUSL applies only to the platform repository. Products in separate repositories keep their own licenses; as of October 2026, ThingsBoard Edge, IoT Gateway and TBMQ list Apache 2.0 on GitHub.

Each monitored or controlled unit counts, not each sensor or data point. A pump with several sensors, a PLC and a gateway is one device. A gateway forwarding data from 100 rooms counts as 100 devices, one per room. The limits apply to the whole organization including affiliated companies; multiple instances do not multiply the Free License.

According to the vendor, nothing breaks. Existing devices, data and services keep working; only new device connections are refused until capacity is increased. This applies equally to the Free License, the Community Grant and the commercial license.

Yes. The license does not restrict consulting, integration, configuration or operations. If the client is the licensee, it uses its own key and its own limits. If the provider runs one instance for several clients under its own key, their devices count toward the provider's limits and the ThingsBoard branding must stay visible.

Timo Wevelsiep

Written by

Timo Wevelsiep

Co-Founder & CEO

Co-Founder of WZ-IT. Specialized in cloud infrastructure, open-source platforms and managed services for SMEs and enterprise clients worldwide.

LinkedIn

Let's Talk About Your Idea

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.

Arrange a callback

Callback

Arrange a callback

Leave your number and we will call back — at the latest on the next business day.

For a longer conversation you can book an appointment instead.

Companies worldwide trust WZ-IT

  • ml&s
  • Rekorder
  • Keymate
  • Führerscheinmacher
  • SolidProof
  • ARGE
  • Boese VA
  • nextGYM
  • SweetConnect GmbH
  • Golem.de
  • Millenium
  • Paritel
  • Yonju
  • EVADXB
  • Mr. Clipart
  • Aphy AG
  • Negosh
  • ABCO Water Systems
1/3 - Topic Selection33%

What is your inquiry about?

First select the service area that best matches your project.