ManyLayers has one deployment model: every tenant is an organization, and the gateway scopes teams, keys, conversations, knowledge bases and deployments to the organization the caller belongs to. Self-serve signup, invite flows and the operator console are always available.
There used to be a second model, mode: onprem, which was the default: one implicit organization, no signup endpoint, no entitlement gate. It has been removed. A config file that still carries mode: loads unchanged — the value is ignored — so nothing needs editing to upgrade.Self-hosting is unaffected. Running ManyLayers on your own infrastructure, air-gapped or otherwise, was never what this setting controlled; see Deployment.

License enforcement

A self-hosted deployment optionally enforces a signed license file to control seat counts and expiry:
billing:
  license_file: /etc/manylayers/customer.json
  license_public_key_file: /etc/manylayers/vendor.pub  # omit to use the built-in default
The license file is a signed JSON document:
{"seats": 100, "expires_at": "2026-12-31T00:00:00Z", "sig": "base64..."}
Your ManyLayers account contact issues license files. See On-prem license for setup instructions.
An absent license_file (empty string) keeps unlimited default behavior. A configured but invalid license file causes the gateway to refuse to start — it fails closed.

Organizations

How it works

  1. Signup — customers sign up via POST /auth/signup, which creates a new org and its first admin user.
  2. Approval (optional) — when saas.signup_approval_required: true, new orgs start as pending. All requests return 403 until an operator approves via POST /admin/orgs/{id}/approve.
  3. Invites — org admins invite teammates via POST /admin/org/invites. Recipients accept via POST /auth/invite/{token}/accept.
  4. Org isolation — all data (teams, keys, conversations, knowledge bases, deployments) is fully scoped to the org.

Operator console

As the platform operator, you manage all orgs via admin API key:
EndpointDescription
GET /admin/orgsList all orgs
POST /admin/orgs/{id}/approveApprove a pending org
POST /admin/orgs/{id}/suspendSuspend an org
GET /admin/orgs/{id}/analyticsPer-org analytics
GET /admin/orgs/{id}/usagePer-org usage rollup
PUT /admin/orgs/{id}/subscriptionAssign a plan to an org

SaaS configuration

saas:
  signup_approval_required: false  # true = require manual operator approval for new orgs