Pay per successful handoff
Pointely SDKs are open source. You only pay for the hosted bridge, and only when a user actually approves. Every plan includes BankID, MitID, FTN, and NemID; failed and abandoned attempts are on us.
Sandbox
Build, test, and demo against every Nordic provider.
- BankID, MitID, FTN, NemID test environments
- All SDKs (open source, Apache-2.0)
- Signed webhooks & replay protection
- Audit log (7-day retention)
- 1 team member
Production
Live traffic for indie builders and growing teams.
- All Nordic providers in production
- 500 successful handoffs / month
- Signed webhooks with auto-retry
- Audit log (90-day retention)
- Pause / resume controls
- Up to 5 team members
Scale
Volume pricing and SLAs for product-led teams.
- Everything in Production
- 5,000 successful handoffs / month
- Audit log (12-month retention)
- Dead-letter alerting (Slack / Sentry)
- Datadog metrics export
- Priority email support
Need higher volume, on-prem, or a Data Processing Agreement? Talk to us about Enterprise: custom rates, dedicated support, and a signed DPA.
Frequently asked questions
One handoff equals one successful, signed step-up round-trip: your code paused with one SDK call, the user approved with BankID / MitID / FTN / NemID (or any registered provider), and an Ed25519-signed record was returned. We do not bill failed, expired, or user-cancelled attempts.
Yes. @pointely/sdk and every framework SDK (Next.js, React, Express, Fastify, Vercel AI, LangChain) are Apache-2.0. You can self-host the bridge from apps/handoff-cloud, or use our hosted tenants on the plans below.
Yes. Every paid plan ships with BankID (Sweden), MitID (Denmark), FTN (Finland), and NemID (legacy Denmark). You do not pay separately per provider, and you can route the same user to the right provider based on country.
On Production we charge €0.20 per extra handoff; on Scale it drops to €0.12. You will never get rate-limited mid-flow. Every handoff completes, and overage is billed at the end of the cycle.
Pointely is built to eIDAS High where the underlying Nordic provider supports it, and supports PSD2 SCA flows (qualified, dynamic linking, signed transaction data). You stay the data controller; we are a processor with a signed DPA on Scale and Enterprise.
Every pause, push, authentication, and resume is appended to a tamper-evident log scoped to your tenant. Sandbox keeps 7 days; Production 90 days; Scale 12 months. Enterprise can stream the log to your own warehouse or SIEM.
The hosted Pointely bridge runs in EU regions only. Personal data and signed records are encrypted at rest with per-tenant keys; webhooks are signed with HMAC-SHA256 and protected against replay via unique delivery IDs.
Yes. Annual contracts include a 15% discount on Production and Scale, and unlock Enterprise terms (DPA, SLAs, custom retention). Talk to us for a quote.