Contents
Key takeawaysWhat PAH isWhat PAH excludesPAH vs other grantsThe registration formWorked cost exampleWhat we have seenChecking your grantReplies and contract termsWhat to do nextFAQAn Oracle PAH license allows you to run your own application as a service for third party users from your own environment. Its scope is set by one registration form, and the grant type goes wrong more often than the quantity.
- Four conditions define the grant. Your own application, run in your environment, delivered as a commercially available service, with users who gain no rights to the Oracle programs.
- Internal systems stay on full use. Finance, HR and reporting systems need their own full use licenses even when they share a data center with the hosted service.
- One form sets the scope. The registration form records the application, architecture, programs and target customers, and the gap between it and what you sell is the standard audit finding.
- Single tenant deployments are exposed. Oracle describes hosting as a one to many offering, so a dedicated environment for one client needs written treatment in the order.
- Support does not change with the grant. Support is charged on the license base, so the grant you choose sets the support bill for every year you renew.
- Settle the grant before the count. In the 20 to 30 hosting reviews we ran in 2024 and 2025, the rights on the order caused more findings than the processor count.
What is an Oracle PAH license?
An Oracle PAH (Proprietary Application Hosting) license allows you to use Oracle programs to deliver your own proprietary application to third party end users, from your own environment, as a service those users access remotely. That sentence is the whole grant, and each part of it is tested in an audit.
The grant exists because Oracle's standard agreement limits the programs to your internal business operations. Once the programs serve a third party's business, Oracle requires hosting language on the ordering document, and ordinary licenses carry none.
Which four conditions must the service meet?
- It is your application. You own the intellectual property. Hosting another vendor's package, or an application a client owns, falls outside the grant.
- It runs in your environment. Your data center, colocation space or cloud tenancy qualifies. An installation at the end user site does not.
- Users reach the service, never the programs. End users consume what you deliver and gain no rights to the Oracle software underneath.
- It is commercially available. The service is offered to a market. A single dedicated environment run for one client is a different arrangement.
What happens when one condition fails?
That deployment becomes unlicensed. The conditions define what you bought, so there is no exception to argue for later. The terms behind every Oracle grant are in the licensing definitions and rules.
What does the PAH license not permit?
It does not permit installation at customer sites, resale, your own internal systems or any application you have not registered. Most software companies expect the grant to reach further than that, which is why the registration form deserves more attention than the unit price.
- Installation at the end user site. Once the software lands on customer infrastructure you are distributing it, and distribution needs an application specific or embedded arrangement.
- Resale or assignment. You cannot transfer, sublicense or bundle the license to the end user.
- Your internal business operations. Your own finance, people and reporting systems still need full use licenses, even when they sit in the same data center as the hosted service.
- Unregistered applications. A second product line, a spin out or an acquired platform is not covered by a form that describes the first one.
Why doesn't a single tenant environment qualify?
A dedicated environment for one named customer sits uncomfortably against a grant written for a commercially available service. Oracle's hosting guidance describes the grant as suitable only for a one to many offering, and says it cannot be used to host a custom developed application for a single end user.
Some providers argue that a dedicated copy of their standard product is still one to many, because many clients buy it. That argument is rarely won twice. If you sell private editions, get their treatment written into the order before you sign. The master terms sit in the contracts library.
Oracle CIO Guide
Grant types, renewal timing and the contract terms that limit Oracle cost, in one download.
Get the white paper →How does PAH differ from full use, ASFU and embedded licenses?
The four grants differ by who holds the license, where the software runs and who may touch it. They are the four practical ways Oracle technology reaches a third party, and picking the wrong one costs money in either direction.
| Grant | Who holds it | Where it runs | What it permits |
|---|---|---|---|
| Full use | The end customer | Anywhere the customer chooses | Any application, for that customer's internal business operations |
| Application specific full use | The end customer, sold through a partner | At the customer site | Use only with the partner application it was sold with |
| Embedded software license | The software vendor | Inside the vendor product, at the customer site | Technology embedded and hidden, with no direct end user access |
| Proprietary application hosting | The hosting company | In the hosting company's environment | Delivering one registered application to third party users as a service |
The partner sold variant is covered in our application specific full use guide and the vendor held variant in the embedded license guide. The full catalog of grant types is in the license types reference.
Which grant fits your delivery model?
Work through these questions in order and stop at the first yes.
- Is the workload your own business, such as payroll, finance or a customer portal for your own products? Buy full use.
- Does your software install on the customer's servers with Oracle hidden inside it? Look at the embedded license.
- Does your software install on the customer's servers, with their staff administering the database? Look at application specific full use.
- Do you run your own application in your environment and sell access to it? That is the hosting grant.
- Do you run an application that belongs to someone else, for them? That is outsourcing: the customer normally holds full use licenses for its own operations, and you run them on its behalf.
Which metric and edition apply under the hosting grant?
The grant sets what you may do, and the program metric sets how much you need. The database is counted on the terms in our database licensing guide, and the edition limits that catch smaller hosting setups are in the standard edition reference. Published rates for every program are on the technology price list.
A public service is almost always counted by Processor. Named User Plus counts every authorized individual at the multiplexing front end, so users behind your application tier still count. Our note on internet facing Named User Plus covers why that metric fails for hosted services.
- Physical servers. Cores times the factor in the core factor table, explained in our core factor guide.
- VMware. Oracle treats VMware as soft partitioning and expects every physical host the database can move to be licensed, as the virtualization guide explains.
- AWS or Azure. The authorized cloud environment rules replace the core factor with vCPU counting.
What does the PAH registration form commit you to?
It ties the grant to a written description of your product, and Oracle will hold you to that description. The document carries different names depending on the vintage of your contract. It typically records the application name, the architecture, the Oracle programs used and the intended end customers.
One form defines the entire scope of the grant. It has no price attached, so procurement rarely reads it, and it decides more about your exposure than the quantity on the order does.
| Field | What to write | What goes wrong |
|---|---|---|
| Application name | The product family as customers know it, with successor names | A rebrand or new module name reads as an unregistered application |
| Architecture | The tiers and hosting locations, described at a level that survives change | A move to a new cloud region or provider no longer matches the form |
| Oracle programs used | Every program and option the service runs, including tools used by operations staff | An option switched on later sits outside the registered description |
| Intended end customers | The market you sell to, by segment and geography | A new segment or a single dedicated client falls outside the stated market |
How should you write the application description?
- Describe the product, not the release. A description tied to a specific version or module set needs renegotiating the first time the roadmap changes.
- Keep it current. Update the form whenever the product changes materially, and keep the approved version with your ordering documents.
Why does the form matter most in an audit?
The gap between the registered description and the service you deliver is the standard audit finding. Treat the form as a scoping document and review it with product management every year, and the finding never arises.
What does a PAH deployment cost to license?
You pay for the processors the hosted service runs on, plus separate full use licenses for your internal systems, plus annual support on both. Hosting rights are agreed on the order and have no separate line on the public price list, so the example below uses the published Technology list as the reference point.
Say your service runs on Oracle Database Enterprise Edition. Production uses two x86 servers of 16 cores each, staging and test one 8 core server, and your finance and HR database another 8 core server. Enterprise Edition lists at $47,500 per Processor, with support at $10,450 a year.
| Environment | Grant needed | Processor licenses | License at list | Support per year |
|---|---|---|---|---|
| Hosted service production, 32 cores | Hosting | 32 x 0.5 = 16 | $760,000 | $167,200 |
| Staging and test for the service, 8 cores | Hosting, non production | 8 x 0.5 = 4 | $190,000 | $41,800 |
| Internal finance and HR, 8 cores | Full use | 8 x 0.5 = 4 | $190,000 | $41,800 |
| Total | 24 | $1,140,000 | $250,800 |
Two rows surprise first time buyers. Staging and test need licenses, because Oracle's free developer license excludes any production or commercial use. And the internal database cannot ride on the hosting grant.
Why does the grant decide the support bill?
Support runs at 22 percent annually whichever grant you hold, so the grant decides the base it is charged against. A hosting grant bought for a workload that only needed full use carries the higher base every year. The reverse leaves a compliance gap that only a later purchase closes.
Buying the wrong grant costs money every year in license and support. Holding the wrong grant costs you your compliance position in the next audit.
What does fixing a wrong grant cost?
It costs a hosting grant for every processor the service runs on, priced by Oracle once it holds the finding. In the example, that is 16 Processor licenses bought again. Retiring the old ones saves less than expected, because Oracle's support policies reprice what remains on an order when part of it is terminated.
What have we seen in recent Oracle hosting reviews?
Across roughly 20 to 30 Oracle engagements involving hosted or embedded delivery that I reviewed in 2024 and 2025, the grant type was wrong more often than the quantity. The same four patterns kept appearing, and all of them were settled on paper before anyone discussed a processor count.
- A commercial service on internal use licenses. Companies delivered a paid service on full use licenses bought for internal business operations, with no hosting rights anywhere in the contract set.
- A description that had aged out. Hosting grants were held against an application description written years earlier that no longer matched the product being sold.
- Hosting bought for the wrong workload. Teams paid for the hosting grant where the workload was their own business, and full use would have been correct and cheaper.
- Late exclusions at certification. Hosted deployments were excluded late in an unlimited agreement certification, after they had already been counted in the business case.
A wrong grant is not fixable with a discount. It is fixable only by buying the right thing.
Why we settle the grant before anyone negotiates quantity
The usual advice is to negotiate the quantity hard and leave the grant type to legal as paperwork. We think that order is backward, because no discount changes which rights you hold. Establish the grant first, register the product accurately and keep the description current, then negotiate the number.
How do hosted deployments fare in a ULA certification?
Hosted deployments are the ones most often excluded late. An unlimited agreement usually grants use for your own operations, so servers serving your customers may not count at certification. The mechanics are in the unlimited agreement reference, the timing question in the ULA exit decision guide, and the certification steps in our certification guide.
How do you check which grant you actually hold?
Start with the paper, then compare it with what runs.
- Ordering documents. Read every order for hosting language and for any restriction to a named application.
- The registration form. Find the approved version and compare its product name, programs and customer description with what you sell today.
- Support records. In My Oracle Support, list the Customer Support Identifiers and the licenses each one covers, so you know which grant each server relies on.
- Your customer contracts. Check where your agreements promise dedicated environments or installation on customer premises.
- The deployment inventory. Map each database server to a product, an environment and a grant.
Our guide to reconciling contracts to deployments covers the inventory step, and the rules for third party data centers apply when your service runs in someone else's facility.
Which mistakes cost hosting providers the most?
- Launching a service on existing licenses. A product team spins up a paid service on the company's full use licenses, and the gap stays open until an audit finds it.
- Buying a company and assuming its service is covered. An acquired platform needs its own registration, and its own licenses may carry assignment limits covered in our note on assignment clauses.
What should you say to Oracle, and what should the contract say?
Keep the conversation on rights before price. The account team usually opens with quantity and discount.
| What you may hear | How to reply |
|---|---|
| Your full use licenses are fine because customers never touch the database. | Ask Oracle to confirm that in writing against the internal business operations clause. If Oracle declines, you know where the gap is. |
| The hosting grant covers everything you run in that data center. | Point to the registration form. The grant covers the registered application, and internal systems stay on full use. |
| We can sort out the registration after the order is signed. | Ask for the approved form to be attached to the order, so scope and price are agreed together. |
| Your unlimited agreement covers the hosted service. | Ask where the order grants hosting rights. If it does not, plan the certification without those servers. |
Which contract terms should you ask for?
- Hosting language on the ordering document. It is the grant itself, and without it the licenses default to internal use.
- A product level application description. It should cover successor versions and renamed modules, so ordinary releases stay in scope.
- A written process to amend the registration. Adding a product line or an acquired platform should be a documented update with an agreed turnaround.
- Stated treatment of single tenant deployments. If you sell dedicated environments, the order should say whether they are covered.
- Credit for full use licenses moved to the hosting grant. If you are correcting a wrong grant, negotiate the migration before Oracle has an audit finding to price.
Before signing, ask in writing which grant the order carries and which document defines the registered application. The clause negotiation guide covers the wording.
What to do next
- Establish the grant first. Confirm which grant type your contract set actually holds before anyone discusses quantity.
- Find the registration form. Read it as a scoping document, and compare it line by line with the product you sell today.
- Rewrite the description at product level. Describe the product rather than the release, so it survives the next roadmap change.
- Check your own workloads. Make sure you are not paying for hosting on internal systems where full use would be correct and cheaper.
- Raise hosted deployments early in any certification. Settle their treatment before the certification count, while the business case can still change.
- Get the grant position reviewed. Our Oracle practice establishes the grant position before the quantity conversation opens.
Want a second opinion on your Oracle position? Our Oracle licensing consultants are former Oracle insiders who now work only for buyers.
Frequently asked questions
What does the Oracle PAH license permit?
Running your own proprietary application on Oracle programs, from your own environment, and selling remote access to it as a service to third party users. Your internal systems and other companies' applications need a different grant.
What conditions must a PAH deployment meet?
All four at once: you own the application, it runs in your data center, colocation space or cloud tenancy, users gain no rights to the programs, and the service is offered to a market. Failing one takes that deployment outside the grant.
Can PAH licensed software be installed at the customer site?
No. Once Oracle software sits on customer infrastructure you are distributing rather than hosting, which needs an application specific full use or embedded arrangement sold on different terms.
Does the PAH license cover my internal systems?
No. It covers the hosted service only. Finance, people and reporting systems need full use licenses, including internal reporting run directly against the service's production database.
Are all of my products covered by one PAH registration?
Only the registered application. A second product line, a spin out or an acquired platform needs its own registration, so build that step into product launches and acquisitions.
What does the PAH registration form do?
It fixes the grant to a written description of your product: the application name, the architecture, the programs used and the intended end customers. Keep the approved copy with your orders, because auditors ask for it early.
What is the most common PAH audit finding?
A mismatch between the registered description and the service actually delivered, usually because the form was written years earlier and never updated through rebrands, new modules or a move to another hosting location.
Can a single tenant environment use a PAH license?
Only uncomfortably. A dedicated environment for one named customer is the first deployment an auditor questions under a grant written for a commercially available service. If you sell private editions, settle their treatment in the order before signing.
Does the grant type change the Oracle support rate?
No. Support runs at 22 percent annually under every grant. The grant changes the license fee that percentage is charged against, not the rate itself.
What should be settled first in a PAH negotiation?
The grant type. Confirm the hosting rights on the order and the scope of the registration before discussing processor counts, because a discount on the wrong grant still leaves the deployment unlicensed.