Pricing

Free until it's
load-bearing.

1,000 identifications a month, free forever, enough to build and test against. Upgrade when real traffic shows up, billed monthly in US dollars and cancellable at any time. Every plan gets the same product; the only number that changes is volume.

For building

Developer

$0/ month
1,000 identifications, forever
Start free
1,000 identifications / month
For testing and small projects
All smart signals included
Server-side verification API
30-day signal / 90-day event retention
No card, never expires
For shipping

Starter

$39/ month
25,000 identifications included
Choose Starter
25,000 identifications / month
Everything in Developer
Multiple projects and keys
Webhook events
Email support
For scaling

Growth

$99/ month
100,000 identifications included
Choose Growth
100,000 identifications / month
Everything in Starter
Priority support
Upgrade and downgrade any time
10% grace band before rate limiting
For terms on paper

Enterprise

Custom
Your volume, your contract
Talk to us
Custom monthly volume
SLA and support commitments
Invoicing and procurement
Data processing agreement
Direct line to the people who built it
Billing
Monthly in USD by card, through Stripe. Cancel any time and the plan runs to the end of the period you have paid for.
No card
The Developer tier needs no card and never expires.
Over quota
A 10% grace band, then 429s. No surprise overage bills.
More volume
Above 100,000 a month, talk to us. Additional volume is quoted, not metered by surprise.
Cancel
Monthly, no contract. You fall back to Developer, not to a locked account.

Questions worth asking

What counts as one identification?

One call to the matching engine that returns a visitorId and decision. Server-side verification GETs are free and unmetered.

What happens when I hit my limit?

Nothing breaks mid-request. Every plan has a 10% grace band above its quota; past that the API returns 429 until the month rolls over or you upgrade. You are never billed for overage you did not agree to.

How should my code treat a 429?

As no signal available, not as a reason to block the user. WhorlID is a risk input in your own decision, so a 429 (or any error, or a timeout) should fall back to whatever you would do without a device signal. We would rather you let a request through than lock out a real customer because our quota ran out.

Do you charge for bots and datacenter traffic?

Yes, every identification counts, but the same result flags isBot and isDatacenter, so you can drop that traffic at your edge before it costs you again.

Can I use this for advertising or cross-site tracking?

No. Visitor ids are scoped per project and retention is capped in the database. The product is built for fraud prevention and contractually banned for ad tracking.

Pricing | WhorlID