Skip to main content
See other licenses

Elastic-2.0

Elastic License 2.0

Source available with three prohibitions: no offering it as a managed service, no defeating the license keys, no removing notices.

On this page

What it does

The Elastic License 2.0 is a short source-available license with exactly three prohibitions and no time limit. You may use, copy, modify and redistribute the software, including inside a product you sell, as long as none of the three applies. It covers Elasticsearch, Kibana, Logstash, Beats, Elastic Agent and parts of the Elastic client libraries, alone or as one arm next to other options. Unlike the Business Source License it never converts to an open-source license on a later date, so the limits it sets are the limits for good.

Details

The first prohibition decides most reviews, and it is narrower than people assume. It stops you offering this software to third parties as a hosted or managed service where they get substantial access to its features. It does not stop you using it inside your own product. Running Elasticsearch as the search backend of your app is fine. Selling hosted Elasticsearch is not. Shipping it inside a binary you sell is allowed, and the same three limits then travel to whoever receives it.

Pros

  • You can read the code, trace bugs, and often use it for non-production work under the published terms.
  • Some licenses convert to OSI terms after a delay, which is a planned path rather than a surprise.

Cons

  • A SaaS or competing-product clause can make the "free" download unusable for the exact product you are building.
  • Procurement will not treat it as open source. Your attestation page should say so plainly.

What it allows and requires

Choose a category to see the full grant in one scannable list. Permissions show what the license allows, limits show what it withholds, and obligations show the conditions your release process must satisfy.

Permissions

  • Private use

    Use inside your company, including internal forks, does not by itself trigger distribution duties.

  • Modify

    You can usually read and change the source. Production use after the change date, or in a competing service, is where these licenses bite.

What Elastic-2.0 requires when you ship

Elastic-2.0 is readable source with use limits. The work is to match your use to the written grant, then keep the text on the record so procurement can read it. Do not treat a source-available identifier as OSI-style open source because the code is on GitHub.

  1. You use the software inside your own product or service rather than offering the software itself to third parties as a hosted or managed service.

  2. You have not circumvented the license-key functionality, and you have not switched on features that a key is meant to protect.

  3. You keep every copyright, licensing and trademark notice intact in the copies you distribute.

  4. You tell downstream recipients that the same three limits travel with the code, when you redistribute it inside something you sell.

  5. You have elected one arm and recorded it when a package is offered under more than one license. Elasticsearch and Kibana have shipped under SSPL or Elastic-2.0 since 7.11, and Elastic added AGPL-3.0 as a third arm in 2024.

The duties named in Elastic-2.0

The written grant is the source of the limits. These rows are the usual conditions teams have to match against their actual use, then keep on the record.

Include license

Keep the license text with the source you received.

Things to be aware of

  • Teams confuse it with the SSPL. The same products carry both, and since 2024 an AGPL-3.0 arm as well, so a reviewer has to pick one arm and record which one governs the component.
  • Teams read source available as no conditions. The notice condition applies, and the managed-service prohibition applies whether or not you charge for the service.
  • Teams strip the license-key checks in a fork to unlock paid features. That is the second prohibition, and it is named explicitly in the text.
  • Teams assume they cannot ship it in a paid product. They can. Redistribution is allowed as long as none of the three prohibitions applies.

What the Elastic License 2.0 does not do

Search results often flatten Elastic License 2.0 into a slogan. These are the usual misreads. Elastic-2.0 is a grant with conditions, not a permission to skip the paperwork below.

  • The Elastic License 2.0 is not OSI-approved open source. The three prohibitions never expire, and the text never converts to Apache-2.0 on a Change Date.
  • It does not stop you using Elasticsearch inside your own product. It stops offering this software to third parties as a hosted or managed service where they get substantial access to its features.

How Elastic-2.0 differs from nearby licenses

These licenses are often confused with Elastic-2.0, but their release duties differ. Each row summarizes what the license requires when you ship. Open the linked page for the full checklist.

Elastic-2.0
Source available with three prohibitions: no offering it as a managed service, no defeating the license keys, no removing notices.
source-available
You can read the code. That is not the same as permission to use it any way you like. Source available is not open source.
SSPL-1.0
SSPL is MongoDB's rewrite of the AGPL. Offer the software as a service and its section 13 asks for the source of your whole service stack.
dual-license
One package, more than one license. OR means you choose an arm and follow that one. AND means every arm binds you at the same time.

Common questions about Elastic License 2.0

Answers to common questions about what Elastic License 2.0 requires, when its duties apply, and what evidence belongs with a release.

What is the Elastic License 2.0?

The Elastic License 2.0 is a short source-available license with exactly three prohibitions and no time limit. You may use, copy, modify and redistribute the software, including inside a product you sell, as long as none of the three applies. It covers Elasticsearch, Kibana, Logstash, Beats, Elastic Agent and parts of the Elastic client libraries, alone or as one arm next to other options. Unlike the Business Source License it never converts to an open-source license on a later date, so the limits it sets are the limits for good.

What does Elastic-2.0 require when you ship a product?

You use the software inside your own product or service rather than offering the software itself to third parties as a hosted or managed service. You have not circumvented the license-key functionality, and you have not switched on features that a key is meant to protect. You keep every copyright, licensing and trademark notice intact in the copies you distribute. You tell downstream recipients that the same three limits travel with the code, when you redistribute it inside something you sell. You have elected one arm and recorded it when a package is offered under more than one license. Elasticsearch and Kibana have shipped under SSPL or Elastic-2.0 since 7.11, and Elastic added AGPL-3.0 as a third arm in 2024.

Is Elastic-2.0 open source?

Not in the OSI sense. Elastic-2.0 is source-available: you can read the code, but the grant restricts how you may use it. Read the actual text.

How is Elastic-2.0 different from Source available licenses?

Elastic-2.0 asks this: Source available with three prohibitions: no offering it as a managed service, no defeating the license keys, no removing notices. Source available licenses asks this: You can read the code. That is not the same as permission to use it any way you like. Source available is not open source. Open the Source available licenses page for what that license requires when you ship. Do not treat the SPDX ids as interchangeable because the short names look similar.

Where do I record Elastic-2.0 for a buyer?

The catalog records Elastic-2.0 as source available, and as a license a network deployment does not clear. A network distribution review item therefore appears on the checklist for SaaS and mixed projects, and publishing stays blocked until a person confirms it. Elastic-2.0 is also treated as a templated license, so the fetch never lands it on confirmed. A filled-in copy is labelled as the license with package-specific parameters instead of modified, and the actual text is put in front of you. The component page also shows a compatibility warning about the managed-service limit when the project context is SaaS or Mixed.

Where do I record Elastic-2.0 for a buyer?

The catalog records Elastic-2.0 as source available, and as a license a network deployment does not clear. A network distribution review item therefore appears on the checklist for SaaS and mixed projects, and publishing stays blocked until a person confirms it.

Elastic-2.0 is also treated as a templated license, so the fetch never lands it on confirmed. A filled-in copy is labelled as the license with package-specific parameters instead of modified, and the actual text is put in front of you.

The component page also shows a compatibility warning about the managed-service limit when the project context is SaaS or Mixed. Read /docs/reviewing-component.

  • When a package declares SSPL, Elastic-2.0 and AGPL-3.0 as alternatives, the review starts with an election, and approval is blocked until somebody chooses an arm.
  • The three prohibitions are limits on use, not paperwork. No checklist item can stand in for reading whether your service is the prohibited one.
  • The stored text is what your attestation page and your exports carry, which is how a downstream recipient learns that the same limits apply to them.

See also

The hub is the pillar for this cluster. Sibling licenses are the other spokes. Product FAQ links explain how SourceTrust records the duty, not the license text itself.

Practical guidance for procurement review, not legal advice. Confirm high-stakes use with counsel.

Ship the proof.

Import Elastic License 2.0 and the rest of what you ship. Free to import and review. You only pay when you publish.

Start for free

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.