Java is not free or paid. A specific binary, from a specific distributor, at a specific build number, carries a specific license text, and that text is the only thing that decides whether you owe Oracle money. This page maps that text line by line, and names the runtimes that are never an Oracle exposure.
How to Negotiate the Oracle Java Employee Agreement: Honest Leverage in a Captive Deal
Priced per employee, every employee, from $15 down to $5.25. At renewal your leverage is thin and OpenJDK threats rarely land. The one-year runway, trading through the wider Oracle relationship, and containing what you sign.
Java is not free or paid. A specific binary, from a specific distributor, at a specific build number, carries a specific license text, and that text is the only thing that decides whether you owe Oracle money. This page maps that text line by line, and names the runtimes that are never an Oracle exposure.
Because "Java" is a specification, not a product you can license. What you actually run is a build, produced by a distributor, shipped with a license file. Free or paid is a property of that file.
Three facts settle it, and they have to be answered in this order.
License texts found on Java binaries, and what each permits
| License | Where you meet it | Commercial production use | The catch |
|---|---|---|---|
| Binary Code License | Oracle JDK 8 up to and including 8u202, and earlier releases | Permitted for general purpose computing | Commercial features were carved out and needed a paid entitlement |
| Oracle Technology Network terms | Oracle JDK 8 from 8u211, all Oracle JDK 11, Oracle JDK 17 from 17.0.13 | Not permitted without a subscription | Development and testing are free, which is why the binary spreads |
| No Fee Terms and Conditions | Oracle JDK 17 to 17.0.12, JDK 21, JDK 25, and the short lived interim releases | Permitted, free of charge | The window closes for later builds of the same release |
| GPL version 2 with the Classpath Exception | OpenJDK and every mainstream distributor build | Permitted, free of charge, with no end date | No Oracle support, and you choose who patches it |
Two of those four are free for production. Only one of the two has no clock attached to it. That single sentence is most of what a Java governance policy needs to say.
You do not license Java. You license a build, from a distributor, under a license text. Two of those three facts are usually unknown in an enterprise estate, and the unknown ones are the expensive ones.
Open the installation directory and read it. Every mainstream JDK ships its license as a plain file in the root of the installation, and that file is the controlling artefact for that copy of the runtime.
Record all four per host in the same row. A version number on its own is not evidence of anything, and an inventory built only from version numbers will not survive contact with a licensing conversation.
The java.vendor property is not a license signal. Several free builds report Oracle Corporation because they descend from the OpenJDK codebase that Oracle leads, and a scanner keyed on that property will produce a long list of false findings.
Treat the vendor property as a hint and the license file as the fact. If your discovery tooling cannot read files inside the installation directory, it cannot answer the licensing question, whatever its dashboard says. The mechanics of a file level sweep are covered in the discovery gap and shadow install guide.
Every one of the following is an OpenJDK derived build under GPL version 2 with the Classpath Exception, free for commercial production use. Finding them is good news, and they should be cleared out of any exposure list before anyone starts pricing.
That last one causes real confusion, so be precise about it. Oracle publishes both a GPL licensed OpenJDK build and a commercially licensed Oracle JDK. Same company, same version numbers, different license file.
The map below covers the Oracle branded lines an enterprise is likely to hold. Read it by build, not by release, because the boundary always sits between two adjacent build numbers.
Oracle branded JDK lines and the license in force
| Release line | Free boundary | License above the boundary | Practical reading |
|---|---|---|---|
| Oracle JDK 8 | Free through 8u202, released January 2019 | Oracle Technology Network terms from 8u211 | Any build above 8u202 in production needs a subscription |
| Oracle JDK 11 | No free production build in the line | Oracle Technology Network terms throughout | Free for development and testing only, at any build |
| Oracle JDK 17 | Free through 17.0.12, released July 2024 | Oracle Technology Network terms from 17.0.13 | A routine security patch moved estates across the line |
| Oracle JDK 21 | No Fee Terms while the window is open, into September 2026 | Oracle Technology Network terms after the window | Diarize the date now, because the pattern will repeat exactly |
| Oracle JDK 25 | No Fee Terms while the window is open, into September 2028 | Oracle Technology Network terms after the window | Free today, on a clock, like every release before it |
| Interim releases such as 22, 23, 24 and 26 | No Fee Terms for the six month support life | No further updates published | Free, but unsuitable as a production standard |
Oracle publishes the underlying dates in its Java SE support roadmap and the free terms themselves in the No Fee Terms and Conditions. Check both against your own build inventory rather than against a summary, including this one.
Because the boundary sits in the middle of a release that half the enterprise world still runs, and because crossing it was the responsible thing to do. Oracle JDK 8 update 202 was the last free build. Update 211 and everything after it requires a subscription for commercial use.
Nothing about the software changed in a way an operations team would notice. The license changed. Any organization with a functioning patch process moved past 8u202 during 2019 and, absent a subscription, acquired an exposure that grew quietly every year afterwards.
This is the highest yield finding in Oracle's Java work: widely deployed, trivially provable from a build string, and almost never documented on the customer side. If Oracle branded JDK 8 above 8u202 is in your production estate, treat it as live rather than theoretical.
Here is the part almost nobody checks. Oracle JDK 8 builds under the old Binary Code License were free for general purpose computing, but a set of commercial features sat behind an unlock flag and required a paid Java SE Advanced or Suite entitlement.
Flight Recorder, Java Usage Tracker, the enterprise installer and the Advanced Management Console all lived behind that gate. A profiling exercise that switched on the unlock flag in production, on a build everyone believed was free, is a genuine finding on an otherwise clean estate.
Search your startup scripts, container entrypoints and application server configuration for the unlock flag before you conclude that your Binary Code License era estate is safe. What that paid entitlement covered, if you hold one, is set out in the guide to what a pre 2023 entitlement covers.
Because there is no build number to remember. Every Oracle branded JDK 11 build shipped under the Oracle Technology Network terms, so there is no free production door anywhere in the line and no cliff to detect.
The Technology Network terms permit use for developing, testing, prototyping and demonstrating applications, and personal use. They do not permit business, commercial or production data processing.
That carve out is why the binary spreads. A developer downloads it lawfully, it is baked into a base image, the image is promoted, and a permitted use has silently become a prohibited one with no download event to mark the moment.
It closed on 17, and it is open with an end date on 21 and 25. The No Fee Terms give a release free production use, including for commercial organizations, for a defined period tied to the arrival of the next long term support release.
Oracle's published approach ties the free period for a release to roughly one year after the following long term support release becomes available. JDK 17's period ended in September 2024. JDK 21's runs into September 2026. JDK 25's runs into September 2028.
This is a designed treadmill, not an accident. Each release is free long enough to become your standard and then stops being free while you are still running it.
The crossing is almost always invisible. You are on JDK 17, you stay on JDK 17, and a quarterly security update moves you from 17.0.12 to 17.0.13. The version in your CMDB is unchanged. The license is not.
Build the control at the point of change. A patch that moves an Oracle branded build across a published boundary should require the same approval as a purchase, because that is functionally what it is.
Two clauses matter more than the rest, and both surprise people who assumed free means unconditional.
A build you obtained while the free window was open remains free terms software. JDK 17.0.12 does not retroactively become chargeable because the window later closed.
What creates exposure is installing a build published after the window closed. This distinction is worth getting right, because it means the remediation is a patching decision rather than a panic about everything you already run.
Oracle's own JDK licensing FAQ is the primary source for these points and is updated as releases move. Read the version current on the day you decide, and keep a dated copy with your decision record.
We disagree with the standard remedy, which is to chase the free line by version and roll back when you cross it. Version chasing accepts the wrong axis. Oracle sets those boundaries, moves them on a published schedule, and every release you standardize on will eventually stop being free while it is still in production, which means a version led policy guarantees you will have this conversation again in about two years. The durable axis is distributor. Choose a build whose license has no end date, make it the default in your base images and package repositories, and the question stops recurring. Rolling back a patch, by contrast, buys a few months of licence comfort at the price of a known vulnerable runtime, and it does nothing about the period the paid build was already running.
Any mainstream OpenJDK build under GPL version 2 with the Classpath Exception. That license explicitly permits commercial production use, carries no fee and has no expiry, which removes both the build number cliff and the calendar entirely.
It is the clause that makes the license safe for commercial software. Without it, linking your application against the class libraries would raise questions about your own code. With it, running and linking against the runtime does not impose obligations on your application.
The text is short and worth reading once, at the OpenJDK legal page. It is the single most useful licensing document in the Java ecosystem and almost nobody in procurement has seen it.
The Adoptium project publishes its build and certification process openly at adoptium.net, which is worth reading before you shortlist anything. A wider comparison of the options and their migration profiles sits in the guide to Java options beyond the Oracle subscription.
For the overwhelming majority of workloads it is a runtime swap, not a rewrite. The class libraries are the same upstream codebase, so applications built against a given release generally run unchanged on another build of that release.
Plan for the exceptions rather than the norm: anything depending on features that were Oracle specific, older desktop deployment technologies, and vendor supported applications where the vendor certifies a specific runtime. Get the vendor certification question answered early, because it drives the schedule.
Whatever your total headcount costs, not whatever your Java footprint costs. Since January 2023 the product Oracle sells for a paid position is the employee based subscription, and the count is your workforce rather than your users.
The published ladder opens at $15.00 a month for each head in the smallest band and bottoms out at $5.25 across the 40,000 to 49,999 band. Anything larger is not published, and support comes with the subscription.
The arithmetic per band is worked through in the employee tier pricing table, and the metric itself in the employee metric guide.
The consequence for this page is simple. One unlicensed Oracle branded build anywhere in production does not create a small bill sized to that build. It creates a conversation sized to your entire organization, which is why a handful of developers can produce a headcount sized invoice and why the forecast increase is worth modelling before anyone talks to Oracle.
Source: Redress Compliance advisory engagement file, 2024 to 2025, alongside Oracle's published release notes.
Triage rule: what a finding means and what to do about it this week
| What the inventory shows | What it means | Action |
|---|---|---|
| License file names GPL version 2 with the Classpath Exception | No Oracle exposure, whatever the vendor string says | Remove from the exposure list and record why |
| Oracle branded JDK 8 at or below 8u202 | Binary Code License era build | Check for the commercial features unlock flag, then leave it alone |
| Oracle branded JDK 8 above 8u202 in production | Paid position with no entitlement unless you hold one | Name an owner today and plan the swap to a free build |
| Oracle branded JDK 11 anywhere outside development | Technology Network terms, no free production door | Classify the environment honestly, then migrate or license |
| Oracle branded JDK 17 at 17.0.13 or later | Crossed the boundary via a routine patch | Date the crossing from your patch records before anyone asks |
| Oracle branded JDK 21 or 25 inside the open window | Free today, with a published end date | Diarize the date and assign a decision owner now |
The free line is knowable to the build number. Money is lost not because the rules are hidden but because a patch pipeline crosses a commercial boundary that no control was ever built to detect.
If contractors and consultants sit inside your headcount, resolve that number before any pricing conversation begins, using the analysis of who counts as an employee. Governance for the whole estate, including download control, sits in the Oracle Java advisory hub.
Only up to build 8u202, released January 2019. From 8u211 the line moved to the Oracle Technology Network terms, which do not permit commercial production use without a subscription. Most enterprises patched past 8u202 during 2019 for sound security reasons and acquired the exposure at that moment.
Because every build in the line shipped under the Technology Network terms. Those terms permit development, testing, prototyping, demonstration and personal use, and exclude business and production data processing. There is no build number that changes this, which is what makes the line so easy to miss.
On the ordinary reading of the free terms, no. The license attached to the build you obtained while the window was open, and a later closure does not reach back to it. The exposure comes from installing 17.0.13 or later without an entitlement, so check what your patch pipeline has deployed since October 2024.
Yes, under GPL version 2 with the Classpath Exception, which permits commercial production use with no fee and no expiry. What you buy separately, if you want it, is support. Distributors such as Eclipse Temurin, Amazon Corretto, Azul Zulu, Microsoft, Red Hat, BellSoft and IBM all ship builds under that license.
No. The JetBrains Runtime is an OpenJDK build shipped with JetBrains tooling, and it carries the open source license rather than an Oracle one. It appears on flagged inventory lists regularly because of how it is packaged, and it should be cleared off the exposure list rather than counted.
No for 8 and 11, and only up to 17.0.12 for 17. The free terms began with JDK 17 in 2021 and were never retroactive, so no build of Oracle JDK 8 or 11 has ever been covered by them. Oracle's licensing FAQ is the primary source if you need to evidence this internally.
No. The license follows the binary inside the image, not the platform hosting it. A container image with an Oracle branded paid build inside it carries that license everywhere it runs, which is precisely why base image standardization is the most effective control available.
You can, and it is usually the wrong move. Rolling back reintroduces known vulnerabilities, and it does not remove the period during which the paid build was running in production. Migrating that workload to a free distribution at the current patch level addresses both the license and the security position at once.
Everything CIOs need to govern Oracle Java in 2026. Universal Subscription mechanics, the OpenJDK exit path, audit defense, and the 3 year plan that contains
Gated with a work email on the download page. No sales follow up you did not ask for.
Get the White Paper →500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.
One buyer side briefing a week. Renewal signals, audit moves, and the levers that work. No vendor spin.