ThingsBoard 4.4 under BUSL 1.1: What the License Change Means for Operators

Editorial note: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, prices, versions, licensing terms, and external content may change. Please verify the information provided independently, particularly before making business-critical or security-related decisions. This article does not replace individual professional, legal, or tax advice.

Keep running ThingsBoard after the license change? WZ-IT maps your installation to the new licensing paths, updates it to the current LTS patch and operates ThingsBoard on servers in Germany, see ThingsBoard development and operations in the IoT hub. Book a meeting
With version 4.4, released on 29 September 2026, ThingsBoard changed its license. The split into a Community Edition under Apache 2.0 and a commercial Professional Edition is gone. There is now a single product under the Business Source License 1.1 (BUSL) whose source code stays public, but whose production use is free only within defined limits (ThingsBoard, announcement).
For operators of a self-hosted Community Edition, the situation is less urgent than it first appears. Existing versions remain under Apache 2.0, the 4.3 LTS line receives security updates until July 2027, and a Community Grant keeps existing installations free under 4.4 at their current size. What matters are a few deadlines and details: who gets the grant, what counts as a device and a server, that 4.4 expects regular license validation over the internet, and which features the grant does not include. This article assesses the change based on the license text and vendor documentation, as of October 2026.
Table of Contents
- What changes with ThingsBoard 4.4
- Free use under BUSL 1.1
- License key, license validation and usage data
- What happens to the Community Edition
- The Community Grant Program
- Security updates in 4.4, 4.3 and 4.2
- Commercial license and pricing
- Options for operators
- Alternatives with an open license
- Timeline to July 2027
- Our approach at WZ-IT
- Further guides
What changes with ThingsBoard 4.4
| Item | Up to version 4.3 | From version 4.4 |
|---|---|---|
| Editions | Community Edition (CE) and Professional Edition (PE) | one product |
| Platform license | CE: Apache 2.0, PE: commercial | Business Source License 1.1 |
| Source code | CE public, PE closed | fully public on GitHub |
| Production use without license fee | CE unlimited | only within the Additional Use Grant |
| License key | CE: not required | required for every production deployment |
| Feature set | PE features only with a license | same feature set, price based on devices, servers, branding and support |
| Conversion to Apache 2.0 | not applicable | per version, four years after release |
Sources: license text in the ThingsBoard repository, ThingsBoard BUSL page, release 4.4 on GitHub.
The BUSL is a source-available license created by MariaDB (MariaDB, BSL 1.1). It permits copying, modifying, redistributing and non-production use. Production use is only permitted through the Additional Use Grant defined by the licensor or under a commercial license. After the Change Date, the Change License applies, here Apache 2.0. For ThingsBoard 4.4.0 that date is 29 September 2030. ThingsBoard itself describes the platform as source-available and not as OSI-approved open source (Open Source Definition).
Features previously reserved for the Professional Edition, such as integrations, scheduler, reporting, fine-grained permissions, SSO and secrets storage, are in principle available on every licensing path in 4.4. Payment is tied to scale, white-labeling, clusters in commercial production and the help desk.
Free use under BUSL 1.1
The Additional Use Grant in the license text permits free production use in two cases:
| Attribute | Commercial use | Non-commercial use |
|---|---|---|
| Who | companies, including internal use | accredited educational institutions, non-profit organizations, not for profit |
| Devices | at most 100 across the whole organization | at most 1,000 across the whole organization |
| Servers | at most one production server | any number |
| Branding | name, logo and "Powered by ThingsBoard" visible and unmodified | same |
| License key | free key from the vendor, not circumvented | same |
Three definitions in the license text determine whether an installation fits these limits:
- Commercial Purpose: any use in connection with an activity intended for commercial advantage or monetary compensation, explicitly including use in the operations of a for-profit organization. An internal dashboard that three engineers use to watch real machines is production use according to the vendor FAQ.
- Device: each physical or logical data source, connected directly or through a gateway. A gateway counts only for data it originates. The FAQ gives the example of a pump with 13 sensors, a PLC and a gateway that counts as one device, and a gateway connecting 100 rooms that counts as 100 devices.
- Organization: the licensee together with every entity that controls it, is controlled by it or is under common control with it. Group companies therefore share the 100 devices.
The commercial grant applies to one Production Instance, which the FAQ defines as a fully functional deployment corresponding to a single server process. A high-availability cluster in commercial production is therefore not covered by free use. Development, testing and staging need no key. Without a key, the software runs in development mode with a visible notice and at most 30 days of cumulative run time; a free development key removes that limit. A standby system that receives replicated data but serves no users and sends no commands is not production until it is activated (ThingsBoard, announcement FAQ).
License key, license validation and usage data
For operators in production networks this part often matters more than the device limit. Every production installation of 4.4 needs a key from the ThingsBoard License Portal.
| Aspect | Online key (standard) | Offline key |
|---|---|---|
| Available for | Free License, Community Grant, subscription | Perpetual License with authorized offline deployment |
| License validation | about hourly with the license server | encoded in the key, no validation with the license server |
| Connection outage | tolerated for up to 48 hours, then the management interface locks | not relevant |
| Usage snapshot | by default about every 12 hours, can be switched off | not sent |
According to the vendor, the usage snapshot contains aggregate figures: number of tenants, devices, assets and users, features in use, the previous day's processing volumes, database size and version. Telemetry, message content, names, credentials, configuration and scripts are not included. ThingsBoard itself points out that the data is not anonymous because it travels with the identifiers used for license validation, and that the network address of the instance is recorded. The snapshot can be switched off, license validation cannot.
For an installation in an isolated OT network this means: the free Free License requires an outbound connection to the license server. If that connection is down for more than 48 hours, the management interface locks while devices continue to send data. Anyone who has to run without an internet connection needs a Perpetual License with offline authorization or stays on 4.3 for now. Under the GDPR, the connection to the license server belongs in the record of processing activities and in the firewall rules.
What happens to the Community Edition
The Community Edition is no longer developed as a separate product. Existing versions remain usable:
- All versions before 4.4 stay under Apache 2.0 permanently (Community Grant Program, FAQ). A running CE needs no key and will not be shut down.
- The LTS lines continue to be maintained. According to the release policy, as of October 2026:
| Version | First released | Current patch | Status | End of support |
|---|---|---|---|---|
| 4.3.x | 2026-01-20 | 4.3.1.6 (2026-09-29) | Active LTS: security and critical bug fixes | 2027-07-20 |
| 4.2.x | 2025-08-15 | 4.2.2.6 (2026-09-29) | Maintenance LTS: critical security fixes only | 2027-02-15 |
| 4.1.x | 2025-07-03 | 4.1.0 | End of Life | 2026-01-03 |
| 4.0.x | 2025-04-15 | End of Life | 2025-10-15 |
After 20 July 2027 there will be no vendor security updates for the Apache 2.0 line. A fork of 4.3 is legally permitted but shifts all maintenance to the operator, including the dependencies of the Java backend and the web UI. The next section shows how much maintenance that involves.
Contributors now sign a Contributor License Agreement once, which allows ThingsBoard to use contributions under future licenses.
The Community Grant Program
The Community Grant Program allows existing CE installations to move to 4.4 and all later versions without paying for their current size.
| Rule | Value according to the program page |
|---|---|
| Eligible | organizations with a CE installation that was in production before 2026-09-29 |
| Prerequisite for registration | latest 4.3 LTS patch, registration from within the platform |
| Registration deadline | until 2027-07-20 |
| Devices | count as of 2026-09-29 plus 10 percent, rounded up to the next 10; at least 10 and at most 1,000 extra; at least 100 in total |
| Production servers | number as registered, no headroom; high-availability clusters are covered |
| Duration | does not expire, no renewal required |
| Included | 4.4 and later versions, fine-grained permissions, SSO and OAuth2, secrets storage, branding already applied |
| Not included | integrations, scheduler, reporting, white-labeling features, help desk |
| Professional Pack | USD 2,999 once per deployment for the features not included, help desk in the first year |
Example from the program page: an installation with 3,268 devices is granted 3,598 devices, one with 30 devices gets the minimum of 100. Several separate production environments are registered individually and each receives its own capacity. Capacity is calculated once and does not grow. A grant cannot be transferred to another organization.
Registration is done as system administrator via the version card on the platform's home page. A check reads structural data of the installation and produces an encrypted report; according to the vendor, telemetry and device names are not part of it. Registration does not upgrade or restart the installation; the key is only needed when upgrading to 4.4 (registration guide). An offline tool is available for installations without internet access.
According to the program page, anyone who misses the deadline can only move to 4.4 or later with a commercial license if the installation exceeds the free limits.
Security updates in 4.4, 4.3 and 4.2
The release notes of ThingsBoard 4.4 list 26 CVE identifiers as fixed. The underlying changes mainly concern dependencies: npm packages of the web UI and the JavaScript executor as well as Java libraries such as Netty, Jackson, ZooKeeper and FreeMarker (PR 16200, release 4.4).
The same fixes are included in the LTS patches released on 29 September 2026:
| Release | License | Security fixes from the September batch |
|---|---|---|
| 4.4 | BUSL 1.1 | included |
| 4.3.1.6 | Apache 2.0 | included |
| 4.2.2.6 | Apache 2.0 | included |
The release notes of 4.3.1.6 and 4.2.2.6 list only part of the identifiers. According to the Git history, the changes of the third CVE batch are nevertheless contained in both tags. For security, moving to 4.4 is therefore not required until the respective end of support, but updating to the current LTS patch is. Installations on 4.1 or older no longer receive fixes. Ongoing alerts on vulnerabilities in operated components are part of our CVE monitoring.
Commercial license and pricing
According to the vendor, the commercial license matches the previous Professional Edition prices. As of October 2026, the pricing page lists for self-hosted installations:
| Plan | Price per month | Devices | Assets | Production instances | Support | White-labeling |
|---|---|---|---|---|---|---|
| Free | USD 0 | 100 | 100 | 1 | Community | no |
| Pilot | USD 99 | 100 | 100 | 1 | Help desk | yes |
| Startup | USD 299 | 500 | 500 | 2 | Priority help desk | yes |
| Business | USD 499 | 1,000 | 1,000 | 3 | Priority help desk | yes |
Additional devices cost USD 0.10 per device and month on the Business plan. The Perpetual License starts at USD 4,999 one-time; new versions after the first year require an update fee. Subscriptions are month to month. Hosting, operations and maintenance are not included in the prices for self-hosted installations. A cost overview including ThingsBoard Cloud and Private Cloud is in the article ThingsBoard pricing.
Options for operators
| Starting point | Obvious path | Watch out for |
|---|---|---|
| CE in production, stable size | update to 4.3.1.6, register the grant, plan the move to 4.4 before July 2027 | integrations, scheduler, reporting only with the Professional Pack; online license validation |
| CE in production, strong growth planned | register the grant, calculate the cost of growth beyond the headroom using the pricing page | capacity does not grow, headroom at most 1,000 devices |
| New installation, commercial, up to 100 devices, one server | 4.4 with the Free License | branding stays visible, no cluster, key and internet connection |
| New installation with more than 100 devices or high availability | commercial license or open stack | weigh license cost against custom development and operations |
| Client platform with custom branding | commercial license from Pilot | white-labeling is paid at any scale |
| Isolated network without internet access | 4.3 until July 2027, then Perpetual with offline authorization or an alternative | Free License and grant use online validation |
| Educational institution or non-profit organization | non-commercial Free License | at most 1,000 devices, no profit purpose |
| Heavily modified CE source code | fork of 4.3 under Apache 2.0 or port the changes to 4.4 | security maintenance after July 2027 lies with the operator |
The first steps are the same in every case with an existing CE: take stock (version, devices under the counting rule, production servers, branding), update to the current 4.3 LTS patch and register the grant while the deadline is open. Registration does not commit you to 4.4, it only secures the option. A guide to installing and updating on your own infrastructure is in the article install ThingsBoard.
Alternatives with an open license
If you need a platform without a license key and without a device cap, you assemble the functionality from individual components. That does not replace everything ThingsBoard bundles in one system, in particular device management, tenants and customer dashboards.
| Component | Role | License (as of October 2026) |
|---|---|---|
| ChirpStack | LoRaWAN network server, gateway and device management | MIT |
| Node-RED | data flows, decoding, rules and forwarding | Apache 2.0 |
| Grafana | dashboards and alerting | AGPL-3.0 |
| Time-series database, e.g. PostgreSQL with TimescaleDB or InfluxDB | storage of measurements | check per product |
Grafana is licensed under the AGPL-3.0, which triggers disclosure obligations when the Grafana code is modified and made available over a network. For plain use and configuration this is usually unproblematic; for a customized client platform it belongs in the review. How ThingsBoard and ChirpStack complement or differ from each other is covered in ThingsBoard vs. ChirpStack and in the article on the IoT stack with ThingsBoard, Grafana and ChirpStack. An overview of further platforms is in the comparison of open IoT platforms.
For client portals with their own device management and branding, a custom IoT platform based on open components can also make sense if white-labeling license costs would otherwise recur permanently. Managed operation of ThingsBoard, ChirpStack and Grafana is also offered by our IoT partner merkaio as ThingsBoard managed hosting.
Timeline to July 2027
| Date | Event |
|---|---|
| 2026-09-29 | ThingsBoard 4.4 under BUSL 1.1, reference date for devices and servers in the grant, registration opens, LTS patches 4.3.1.6 and 4.2.2.6 |
| 2027-02-15 | end of security fixes for 4.2 |
| 2027-07-20 | Community Grant registration closes, end of maintenance for 4.3 LTS |
| 2030-09-29 | ThingsBoard 4.4.0 becomes Apache 2.0 |
Sources: Community Grant Program, release policy, license text.
Our approach at WZ-IT
- Inventory. Version, devices under the vendor's counting rule, production server processes, branding changes, integrations and network connectivity of the installation.
- Update to the current LTS patch. Backup, update to 4.3.1.6 and functional check, so that security fixes are in place and grant registration becomes possible.
- Choose the licensing path. Comparison of Free License, Community Grant, Professional Pack and commercial license, and of an open stack. You purchase licenses directly from the vendor.
- Plan the move to 4.4. Firewall rule for the license server, decision on the usage snapshot, test in a staging environment, update with a rollback path.
- Operations. Monitoring, backups, updates and security patches, support, consulting and implementation by WZ-IT, see ThingsBoard managed hosting.
For a structured assessment of the entire IoT architecture, from devices and protocols to the platform choice, there is the IoT architecture check at a fixed price of €1,490 excluding VAT.
Further guides
- ThingsBoard Community vs. Professional Edition, feature differences of the previous editions and what remains under BUSL.
- ThingsBoard pricing, licensing paths, cloud plans and total cost compared.
- Install ThingsBoard, installation and updates on your own infrastructure.
- ThingsBoard vs. ChirpStack, IoT platform or LoRaWAN network server.
- Open IoT platforms compared, alternatives to ThingsBoard.
- IoT solutions from WZ-IT, the hub with LoRaWAN, ThingsBoard, Grafana and platform development.
Clarify the licensing path for your ThingsBoard installation We take stock, update to the current LTS patch and plan grant registration, the move to 4.4 or an open stack. Book a meeting
Sources
- ThingsBoard, One ThingsBoard: source-available (announcement and FAQ)
- ThingsBoard, license text (LICENSE) in the platform repository
- ThingsBoard, Business Source License
- ThingsBoard, Community Grant Program
- ThingsBoard, register the Community Grant
- ThingsBoard, release policy and version table
- ThingsBoard, pricing
- GitHub, ThingsBoard release 4.4
- GitHub, ThingsBoard release 4.3.1.6
- GitHub, ThingsBoard release 4.2.2.6
- GitHub, pull request 16200 (CVE fixes in the web UI)
- MariaDB, Business Source License 1.1
- Open Source Initiative, Open Source Definition
- GitHub, ChirpStack license
- GitHub, Node-RED license
- Grafana Labs, licensing
- GitHub, ThingsBoard Edge
- GitHub, ThingsBoard IoT Gateway
- GitHub, TBMQ
Choose your ThingsBoard licensing path after the move to BUSL
We review device count, servers, branding and network connectivity of your installation, map it to the new licensing paths and plan the update, grant registration or an alternative.
Frequently Asked Questions
Answers to important questions about this topic
No, not in the sense of the Open Source Definition. ThingsBoard 4.4 is licensed under the Business Source License 1.1 and is therefore source-available: the source code stays public on GitHub, but production use is free only within the Additional Use Grant. All versions before 4.4 remain under Apache 2.0 permanently. Each BUSL version becomes Apache 2.0 four years after its release, so ThingsBoard 4.4.0 converts on 29 September 2030.
Production use is free for commercial use with no more than 100 devices across the whole organization on no more than one server, and for non-commercial use by educational institutions and non-profit organizations with no more than 1,000 devices on any number of servers. In both cases a free license key from ThingsBoard is required, and the name, logo and the 'Powered by ThingsBoard' attribution must stay visible. Development and testing work without a key.
No. Versions before 4.4 remain under Apache 2.0 and need no license key. A running CE 4.3 or 4.2 keeps working unchanged. Costs only arise if you move to 4.4 or later and exceed the free limits without having registered a Community Grant first.
ThingsBoard CE 4.3 is Active LTS and receives security and critical bug fixes until 20 July 2027. Version 4.2 is Maintenance LTS with critical security fixes until 15 February 2027. After that, vendor maintenance of the Apache 2.0 line ends.
The Community Grant keeps existing CE installations free when they move to 4.4. Installations that were in production before 29 September 2026 are eligible. The grant covers the devices as of 29 September 2026 plus 10 percent headroom (rounded up to the next 10, at least 10 and at most 1,000 extra devices, at least 100 in total) and the number of production servers at that date. Registration requires the latest 4.3 LTS patch and is possible until 20 July 2027. The grant does not expire afterwards.
No. The CVE fixes in ThingsBoard 4.4 are also included in the LTS patches 4.3.1.6 and 4.2.2.6, released on the same day (29 September 2026). Until the respective end of support, the current LTS patch is sufficient for security.
With a standard online key, yes. The instance validates its license with the license server about hourly and tolerates interruptions of up to 48 hours. After that, the management interface locks until the next successful check; connected devices keep sending data and nothing is deleted. An offline key is only available for a Perpetual License whose order authorizes offline deployment.
No. In addition to license validation, an online instance by default sends a usage snapshot about every 12 hours with aggregate figures such as the number of tenants, devices and users, features in use, database size and version. According to the vendor, telemetry, message content, names, credentials and scripts are not included. The snapshot is not anonymous and can be switched off with a configuration flag; license validation continues.
Nothing changes for ThingsBoard Cloud; the change concerns the self-hosted platform. The BUSL applies only to the platform repository. Products in separate repositories keep their own licenses; as of October 2026, ThingsBoard Edge, IoT Gateway and TBMQ list Apache 2.0 on GitHub.
Each monitored or controlled unit counts, not each sensor or data point. A pump with several sensors, a PLC and a gateway is one device. A gateway forwarding data from 100 rooms counts as 100 devices, one per room. The limits apply to the whole organization including affiliated companies; multiple instances do not multiply the Free License.
According to the vendor, nothing breaks. Existing devices, data and services keep working; only new device connections are refused until capacity is increased. This applies equally to the Free License, the Community Grant and the commercial license.
Yes. The license does not restrict consulting, integration, configuration or operations. If the client is the licensee, it uses its own key and its own limits. If the provider runs one instance for several clients under its own key, their devices count toward the provider's limits and the ThingsBoard branding must stay visible.

Written by
Timo Wevelsiep
Co-Founder & CEO
Co-Founder of WZ-IT. Specialized in cloud infrastructure, open-source platforms and managed services for SMEs and enterprise clients worldwide.
LinkedInLet's Talk About Your Idea
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.





