Pricing
Pay for volume and reach, not for features
Every plan reaches the whole dataset through every interface we ship: REST, MCP, TAXII, MISP and the web. What changes is how much you can pull in a day and how far back you can look. Each step is ten times the credits for about three and a half times the price. Open research is free, with Pro volume and the full history, by application rather than by card.
| Plan | Free | Solo | Most common Pro | By application Research | Team |
|---|---|---|---|---|---|
Free no card, no expiry | €29/mo €290/yr, two months free | €99/mo €990/yr, two months free | Free open research, non-commercial | €349/mo €3,490/yr, two months free | |
| Enough to find out whether the data answers your question. | Thirty days of history rather than seven, so a repeat visitor stops looking like a one-off. Ten times the budget, and alerts the same day. | Ninety days, fifty thousand credits a day and payload search, for integrations other people depend on. | Academic, independent, CERT or student work that will be published where anyone can read it. | One budget across a team and everything it automates, with the full archive behind every question. | |
| Daily credits1 | 500 | 5,000 | 50,000 | 50,000 | 500,000 |
| Requests per minute | 10 | 30 | 60 | 60 | 300 |
| Query window2 | 7 days | 30 days | 90 days | Full history | Full history |
| Watchlists3 | 10 | 25 | 100 | 100 | 1,000 |
| Feed tokens per watchlist4 | 2 | 5 | 10 | 10 | 50 |
| Alert subscriptions | 3 | 10 | 25 | 25 | 200 |
| Fastest alert cadence | Weekly | Daily | Daily | Daily | Hourly |
| Fastest feed digest | Daily | Hourly | Hourly | Hourly | Hourly |
| Support | Community, best effort | Priority, with onboarding help | |||
| Create a free account | Apply for Research |
Every number above is read from the same registry the quota middleware enforces, so
this page cannot promise a limit the platform does not apply. Responses carry an
X-HoneyLabs-Quota-Remaining header so an integration can watch its own budget.
Applying for research access
No cost, 12 months, renewableThe dataset exists because people run sensors and publish what they find. If your work is going to be public, we would rather have it built on real data than on a sample. Academic, independent, CERT and student work all count, and we do not ask for an institution.
You get Pro's volume with the full history, because depth is the limit that decides whether a piece of work is possible at all. A ninety day window cannot answer a question about a campaign that ran longer than ninety days, at any request rate.
- You publish openly. A paper, blog post, talk, dataset or repository that anyone can read without paying or signing up.
- You credit HoneyLabs. A link back, using one of the snippets below. That is the whole payment.
- You share findings, not the raw dataset. Aggregates, figures and the specific indicators your work discusses are all fine. Republishing bulk raw data as a competing feed is not.
- It is not inside a commercial product. Research that later turns into something commercial is fine, just talk to us when it does.
Email info@honeylabs.net with what you are looking into and roughly where it will be published. Two sentences is plenty, and if the work is already out there just send the link.
Any of these is fine. A plain link in the text works too.
HoneyLabs, honeypot threat intelligence. https://honeylabs.net (accessed 2026-08-27).
Data from [HoneyLabs](https://honeylabs.net)
@misc{honeylabs,
title = {HoneyLabs: honeypot threat intelligence},
author = {{HoneyLabs}},
year = {2026},
url = {https://honeylabs.net},
urldate = {2026-08-27}
}Bulk delivery to a bucket you own, an on-premise copy, or a redistribution licence if HoneyLabs data is going into something you sell. None of that fits a credit budget, so it is priced against what you actually need rather than a tier.
In every plan, including Free
- Full lookup, search and payload search
- CVE probing data and early-actor attribution
- REST API, MCP endpoint and TAXII 2.1
- MISP feeds and Microsoft Sentinel connector
- IOC feeds for firewalls and SIEMs
Questions worth answering up front
What is a credit?
One row of data returned. An enrichment lookup costs one credit, a hundred-row list costs a hundred. The meter follows what you actually pulled, so a careful query stays cheap.
What happens when I run out?
Requests return a quota error until the day rolls over at midnight UTC. Nothing is charged automatically and no overage appears on an invoice. If you hit the ceiling often, the next plan up is cheaper than the time you spend working around it.
Why is the history window the interesting limit?
Volume decides how many questions you can ask. Reach decides which questions can be answered at all. Tracking a campaign, or showing that a CVE was probed before it was published, needs history no request rate can substitute for.
Can I put this in a product I sell?
Yes on Team, and talk to us first so we can size it properly. Redistributing the raw dataset as a competing feed is the one thing no plan covers.
Are the free MISP feeds going away?
No. The exploiter and malware-infrastructure feeds ship in MISP's own defaults and stay anonymous and unmetered. They are how most people meet us and they are not a trial.
Can I cancel?
Any time, from the dashboard. Monthly plans stop at the end of the period you have paid for. Annual plans are refunded pro rata for whole unused months.