Cloud billing preview and dashboard telemetry
Loomup Cloud rates each workspace on a plan-anniversary period. The current release calculates usage and estimated charges only: it does not collect payment details, charge a card, or create a legal invoice. Estimates can change when delayed usage arrives.
Launch plans
All prices are USD per workspace per month.
| Plan | Base | Projects | Members | Database | Objects | Outbound | MAU |
|---|---|---|---|---|---|---|---|
| Free | $0 | 2 | 1 | 0.5 GB | 1 GB | 5 GB | 50,000 |
| Pro | $29 | 3 | 5 | 10 GB | 100 GB | 250 GB | 100,000 |
| Scale | $99 | 10 | 20 | 50 GB | 250 GB | 1 TB | 500,000 |
| Enterprise | Custom | Custom | Custom | Custom | Custom | Custom | Custom |
Pro and Scale overages are $10 per additional project-month, $0.15 per database GB-month, $0.03 per object GB-month, $0.10 per outbound GB, and $0.0035 per additional monthly active user. An overage alert is informational and never suspends service.
Workspace owners can upgrade immediately; the base plan price is prorated to the second for each plan segment. A downgrade is scheduled for the next plan anniversary. A downgrade is rejected while the workspace has more projects or members than the target plan permits.
The catalog stores integer USD micros and immutable plan-version IDs such as pro-v1. Consumers should use the returned version and must not duplicate prices for rating.
Workspace REST API
Browser users authenticate with a platform session. A separate server-rendered dashboard or backend-for-frontend should use an lbsk_ dashboard service key in Authorization: Bearer ....
GET /platform/api/v1/pricing/plans
GET /platform/api/v1/workspaces/{workspace_id}/billing
GET /platform/api/v1/workspaces/{workspace_id}/usage
GET /platform/api/v1/workspaces/{workspace_id}/telemetry/snapshot
GET /platform/api/v1/workspaces/{workspace_id}/telemetry/stream
GET /platform/api/v1/workspaces/{workspace_id}/dashboard-service-keys
POST /platform/api/v1/workspaces/{workspace_id}/dashboard-service-keys
POST /platform/api/v1/workspaces/{workspace_id}/dashboard-service-keys/{key_id}/rotate
DELETE /platform/api/v1/workspaces/{workspace_id}/dashboard-service-keys/{key_id}
Owners issue a key with one or more narrowly scoped permissions:
usage:readreads workspace usage and usage events.billing:readreads plans, estimates, and billing/plan events.health:readreads project runtime health.
The raw secret is returned only when issued or rotated. Store it in a server secret manager; do not embed it in browser JavaScript. Rotation gives the previous key a ten-minute grace window. Revocation is immediate.
The usage response deliberately includes authenticated user IDs and emails in usage.subjects for authorized customer and operator dashboards. Treat it as personal data: restrict access, avoid client-side persistence, and apply the retention rules for your product. The billing and health snapshot endpoints omit subjects, even when the same key also has usage:read; fetch the usage endpoint when that detail is needed.
Use limit (default 100, maximum 1000), numeric cursor, and optional project_id on the workspace usage endpoint. The response includes pagination.next_cursor, pagination.has_more, and pagination.total_subjects.
SSE contract
The telemetry endpoint returns text/event-stream. It begins with a versioned snapshot event and then emits persisted events such as usage.updated, plan.updated, billing.updated, and alerts.updated. Billing and alert events are lightweight invalidation messages with refresh_required: true; fetch the billing or usage endpoint for the newly rated snapshot. Each event has an integer id; reconnect with the standard Last-Event-ID header to resume within the retention window. If that cursor is no longer valid, the first event is reset and contains a fresh snapshot. Live health.snapshot events are emitted every five seconds, and a keepalive comment is sent every 15 seconds.
GET /platform/api/v1/workspaces/ws_123/telemetry/stream?topics=usage,billing,health
Authorization: Bearer lbsk_...
Accept: text/event-stream
Last-Event-ID: 481
Event data contains schema_version, occurred_at, workspace_id, project_id, and data. Consumers must ignore unknown fields and event types. Fetch the snapshot again when a cursor is outside the retained window.
Topic names are strict. Supported values are usage, billing, health, plan, and alerts; an unknown topic returns HTTP 400 instead of silently broadening the subscription.
Operator dashboards use GET /platform/api/v1/operator/overview and /platform/api/v1/operator/telemetry/stream. The overview omits per-subject IDs and emails; use a workspace usage request or authorized usage event when that detail is required. Bootstrap an operator key with the management-authenticated POST /platform/api/v1/operator/dashboard-service-keys; its scopes must include operator:read. Do not use the management token in the dashboard process.
Rollout and enforcement
Billing launches in observe mode by default so existing managed installations can compare estimates before enabling limits. Set LOOMUP_BILLING_MODE=enforce to enforce Free-plan project and workspace-member gates. Paid plans permit project overages; resource usage and alerts remain observable and non-destructive in this preview.
The rating precision field currently reports daily_gauge_preview: outbound transfer and active-user counts are durable period counters, while database and object storage are based on daily operational gauges. They are suitable for a preview, not invoice-grade byte-second settlement.
The complete HTTP contract is in openapi-platform.yaml.