Editions & Plans
Feature availability by edition and plan.
This page documents edition and plan differences for product usage. It is not a pricing page. Commercial deployments are arranged with rstream and are not public downloadable SKUs.
rstream has four distinct operating models:
| Model | Who operates it | Intended use |
|---|---|---|
| Hosted Basic and Pro | rstream | Public hosted projects for individuals, developers, and teams. |
| Enterprise | rstream, or a customer environment under contract | Organizations that need dedicated capacity, Workspace Protection, audit, and support. |
| Integrator Edition | Partner or managed service provider | Partners that operate rstream capabilities inside their own customer environments. |
| Self-hosted Community Edition | Customer | Free direct engine runtime without the hosted Control plane product surface. |
The public self-hosted engine is Community Edition. Hosted rstream, Enterprise deployments, and Integrator Edition can run additional runtime modules for project-backed authentication, advanced listeners, managed policies, protected workspace data, and persisted operational integrations.
Community Edition
Community Edition runs the core engine with the TLS listener, HTTP and TLS tunnel support, static certificate configuration, JWT authentication, and Prometheus metrics.
Use hosted rstream or contact rstream for a private deployment when the runtime must enforce managed project controls, certificate-backed authentication, browser-based access flows, network access policies, persisted operational history, additional listener families, package distribution, or automatic certificate management.
Hosted, Enterprise, and Integrator runtimes
Hosted rstream and private deployments can enable additional runtime capabilities such as QUIC and DTLS listeners, plain HTTP CONNECT, HTTP/3 Extended CONNECT protocols, mTLS authentication, ECH policy, identity provider integration, project-backed authorization, location or IP policies, package distribution, automatic certificate management, persisted events, and additional metrics sinks.
Plan gates are enforced by the runtime. In the hosted project matrix, fine-grained resources.tunnels boundaries are available on Basic, Pro, and Enterprise projects. Agent mTLS authentication is available on Basic, Pro, and Enterprise projects when the runtime enables certificate-backed agent authentication. The Engine HTTP API is token-authenticated. Published Tunnel mTLS is available on Pro and Enterprise projects when the runtime enables published mTLS enforcement. Plain CONNECT follows the HTTP tunnel support available in the runtime. Pro and Enterprise projects can use private tunnels, datagram tunnels, published QUIC tunnels, DTLS tunnels, HTTP/3 upstream, WebTransport, CONNECT-UDP, CONNECT-IP, GeoIP policies, trusted IP policies, custom ALPNs, custom TLS ciphers, rstream Auth, challenge mode, and project webhooks. Basic projects have HTTP/3 downstream support and can use QUIC for the engine control channel when the QUIC listener is enabled, but the other advanced tunnel and policy features remain gated.
Some private-runtime integrations are documented as part of the deployment package when they apply.
For the public self-hosted path, use Self-Hosted, which documents the CE runtime and its configuration contract.
Integrator Edition
Integrator Edition is a commercial partner edition for integrators, managed service providers, and infrastructure platforms. It is designed for teams that operate their own runtime infrastructure, deploy rstream capabilities into customer environments, integrate the product with their own platform, and deliver secure tunnels, WebTTY, policy, logs, and APIs under their own service model.
Integrator Edition is not the free self-hosted Community Edition. It is also not a hosted Enterprise workspace operated as a normal rstream customer account. It is a contract model with source access, deployment rights, white-label or private-label options, partner enablement, and a deployment boundary agreed with rstream.
WebTTY availability
WebTTY has a lightweight WebTTY tunnel surface and a managed registered-server surface. The lightweight WebTTY tunnel surface follows tunnel capabilities. The registered-server surface depends on hosted or private managed runtime modules because it needs durable server records, session state, recording storage, policy, and live collaboration APIs.
Integrator Edition gives partners access to the Enterprise WebTTY capability set under the deployment and support boundary defined in the partner agreement. The table below therefore keeps the product capability comparison focused on CE, hosted projects, and Enterprise workspaces.
| Capability | Self-hosted CE | Basic hosted project | Pro hosted project | Enterprise workspace |
|---|---|---|---|---|
| Lightweight WebTTY tunnel | Yes | Yes | Yes | Yes |
| Registered WebTTY server inventory | No | Yes | Yes | Yes |
| Managed session recordings | No | 24 hours | 30 days | Contract-defined |
| Live active-session listing | No | Yes | Yes | Yes |
| Spectator attach and control request | No | View-only product path | Yes | Yes |
| Explicit-key WebTTY E2E | Runtime/client configured | Yes | Yes | Yes |
| Workspace-managed WebTTY E2E | No | No | No | Yes |
| Workspace Protection, trusted browsers/devices, Recovery Kit | No | No | No | Yes |
Self-hosted CE remains useful for direct engine deployments and lightweight remote access. It does not include the hosted Control plane product objects required for managed WebTTY recordings, workspace-managed key custody, or Enterprise workspace protection.
The difference between explicit-key E2E and Workspace Protection is important. Explicit-key WebTTY E2E is a local operator ceremony: the server owns an identity, clients trust its public key, and the operator decides how keys are distributed. Workspace Protection is the Enterprise workspace ceremony: rstream stores encrypted workspace envelopes, trusted browsers/devices are approved through workspace policy, and the Recovery Kit provides the offline recovery path.
Billing model
Hosted Basic and Pro are project plans. Enterprise is a workspace plan. In an Enterprise workspace, projects created inside that workspace are covered by the workspace contract instead of being individually upgraded through the public project plan flow.
Private deployments can be supervised by rstream or operated in a customer environment depending on the contract. Dedicated data-plane resources are the Enterprise baseline. Dedicated Control plane resources, source-code audit access, escrow terms, and operational SLAs are contract terms rather than public self-service toggles.
Integrator Edition is not billed through public project checkout. It is governed by a partner agreement that defines deployment rights, customer environments, support boundaries, branding, source access, and redistribution or adaptation rights.
Control plane and data plane
The Control plane is the hosted product surface: account, workspace, project, server inventory, policy, billing, tokens, logs, and protected workspace metadata. The data plane is the engine runtime that carries tunnel, WebTTY, QUIC, DTLS, HTTP, TLS, and related traffic.
This distinction matters for self-hosted CE. A CE engine can be deployed by a customer, but it does not include the hosted Control plane product modules that manage Enterprise workspaces, registered WebTTY inventory, Workspace Protection, or encrypted recording workflows.
Source and audit access
The public client and SDK surfaces are inspectable where they are published. For Enterprise contracts, rstream can provide server-side source-code access for audit or escrow review under the contract terms. This is source-code access for inspection and assurance; it is not a transfer of intellectual property ownership.
Integrator Edition can include broader source access and adaptation rights under a written partner agreement. Those rights are contract-specific and do not change the license of public Community Edition artifacts.