Documentation

Telegraf Enterprise license enforcement

Telegraf Controller enforces two things based on your license status: how many resources you can create (scale limits) and which features are available. This page describes both kinds of enforcement and how license expiration affects them.

Telegraf Enterprise

Unlock higher configuration and agent limits, enhanced security features, and official support for Telegraf and Telegraf Controller.

Scale limits

Telegraf Controller enforces a maximum number of configurations and a maximum number of reporting agents per instance.

ResourceFree tierTelegraf Enterprise
Configurations20Defined by ent_max_configs in your license (per contract)
Reporting agents100Defined by ent_max_agents in your license (per contract)

The free-tier values are hardcoded into the Telegraf Controller binary and cannot be overridden.

What happens when a limit is reached

  • “Create” endpoints (such as POST /api/configs) return 402 Payment Required with an error body identifying the resource, the current count, and the limit:

    {
      "error": "entitlement_limit_reached",
      "resource": "configs",
      "current": 20,
      "limit": 20,
      "message": "configs limit reached (20/20). Upgrade to Telegraf Enterprise for higher limits."
    }
  • The corresponding create button in the Telegraf Controller UI is disabled and shows a tooltip explaining the limit.

  • The response includes an X-Entitlement-Warning header (see Response headers).

A warning banner appears in the UI when usage reaches 80% of a limit so operators have advance notice before requests start being rejected.

Enterprise feature gating

A valid Telegraf Enterprise license unlocks the following features:

API endpoints that require an enterprise feature return 403 Forbidden when called on a free-tier instance:

{
  "error": "feature_not_licensed",
  "feature": "audit_logging",
  "message": "audit_logging requires a Telegraf Enterprise license."
}

Identity provider environment variables on a free-tier instance

If AUTH_LDAP_* or AUTH_OIDC_* environment variables are set on a free-tier instance, Telegraf Controller starts normally and logs a warning that the feature requires a license. The feature stays inactive until a license is applied and Telegraf Controller is restarted so the variables are re-read.

License expiration lifecycle

A license moves through four stages relative to its license_exp (contractual expiration) date:

Time relative to license_expStatusScale limitsEnterprise featuresUI behavior
More than 30 days beforevalidLicensedEnabledNo banner
1–30 days beforeexpiringLicensedEnabledInfo banner with countdown
0–14 days afterexpired_graceLicensedEnabledError banner with countdown
15 or more days afterexpiredFree tierDisabledError banner

The grace period is fixed at 14 days and is not configurable. Expiration status is re-evaluated hourly, so a status change takes effect within one hour without requiring a restart. To switch back to a valid status sooner, apply a renewed license through the UI. Uploads take effect immediately.

Response headers

Telegraf Controller adds the following headers to HTTP responses when the corresponding condition is true. Monitor these headers in deployment health checks to detect license-related issues before they affect users.

HeaderWhen it appearsValue
X-License-ExpiringLicense expires within 30 daysISO 8601 expiration date
X-License-ExpiredLicense is past expiration but still in gracetrue
X-Entitlement-WarningOne or more entitlements at 90% or more of the limitComma-separated resource current/limit pairs, for example configs 18/20; agents 95/100

Reference: JWT claims

The following table describes the claims contained in a Telegraf Enterprise license JWT. Claims are informational. You don’t author license files yourself, but understanding what each claim controls helps when reading license details, scripting around licensing, or interpreting validation errors.

ClaimTypeDescription
idstring (UUID)Unique license identifier. Use this value when contacting InfluxData support.
issstringIssuer. Always InfluxData Licensing Server for valid licenses.
iatUnix timestampWhen the license was issued.
expUnix timestampJWT token expiration.
license_expUnix timestampContractual license expiration. Drives the enforcement lifecycle.
ent_max_configspositive integerMaximum configurations entitlement.
ent_max_agentspositive integerMaximum reporting agents entitlement.

Was this page helpful?

Thank you for your feedback!


InfluxDB OSS 2.9.0: API tokens are hashed by default

Stronger token security in InfluxDB OSS 2.9.0 — tokens are hashed on disk by default. Existing tokens are hashed on first startup and can’t be recovered afterward. Capture any plaintext tokens you still need before you upgrade.

View InfluxDB OSS 2.9.0 release notes

Hashed tokens authenticate exactly like unhashed tokens — clients and integrations keep working.

Also new in 2.9.0:

  • Configurable backup compression
  • Restore support for backups containing hashed tokens
  • Tighter Edge Data Replication queue validation
  • Flux upgrade
  • Compaction reliability improvements

Key enhancements in Explorer 1.9

Explorer 1.9 is now available with InfluxQL support, an AI-assisted Flux to SQL converter (beta), and new live sample data simulators.

View Explorer 1.9 release notes

Explorer 1.9 includes new features and improvements that make it easier to query, visualize, and manage data.

Highlights:

  • Flux to SQL converter (beta): Convert Flux queries to SQL with an AI-assisted converter.
  • InfluxQL support: Query data with InfluxQL in the Data Explorer and dashboards, and save and load InfluxQL queries.
  • InfluxQL visualizations: Render line and bar charts from InfluxQL results with per-tag series grouping.
  • Query error history: Review a history of query errors in the query tool.
  • Live sample data simulators: Generate continuous live sample data with new bird data and signal generator simulators.

For more details, see Explorer 1.9 release notes

InfluxDB 3.10 is now available

InfluxDB 3 Core 3.10 adds an automatic catalog format upgrade, a configurable query-concurrency limit, and processing engine improvements.

Key updates in InfluxDB 3 Core 3.10:

  • Catalog format upgrade: the on-disk catalog automatically upgrades from format v2 to v3 on first 3.10 startup. Migration is one-way—back up your catalog before upgrading.
  • --max-concurrent-queries: limit concurrent queries (adjustable at runtime).
  • GET /ready endpoint for readiness probes.
  • Processing engine: cross-database queries and trigger lockdown flags.

For more information, see the InfluxDB 3 Core release notes.

InfluxDB 3.10 is now available

InfluxDB 3 Enterprise 3.10 adds automated backup and restore, row-level deletions, and user management, with an automatic catalog format upgrade and performance preview improvements.

Key updates in InfluxDB 3 Enterprise 3.10:

  • Catalog format upgrade: the on-disk catalog automatically upgrades from format v2 to v3 on first 3.10 startup. Migration is one-way—back up your catalog before upgrading.
  • Automated backup and restore (beta)
  • Row-level deletions
  • User management (authentication and RBAC) — preview
  • Performance preview improvements

Backup and restore, row-level deletions, and the performance preview require the Enterprise storage engine upgrade (opt-in beta). Beta and preview features are subject to breaking changes and aren’t recommended for production use.

For more information, see the InfluxDB 3 Enterprise release notes

Telegraf Enterprise is now generally available

Telegraf Enterprise is now generally available, along with Telegraf Controller v1.0.

Telegraf Enterprise combines Telegraf Controller, a centralized management console for Telegraf, with official support from InfluxData. Manage configurations, monitor fleet health, and operate tens of thousands of Telegraf agents from a single system.

InfluxDB Docker latest tag changing to InfluxDB 3 Core

On September 15, 2026, the latest tag for InfluxDB Docker images will point to InfluxDB 3 Core. To avoid unexpected upgrades, use specific version tags in your Docker deployments.

If using Docker to install and run InfluxDB, the latest tag will point to InfluxDB 3 Core. To avoid unexpected upgrades, use specific version tags in your Docker deployments. For example, if using Docker to run InfluxDB v2, replace the latest version tag with a specific version tag in your Docker pull command–for example:

docker pull influxdb:2