Prisma AIRS Licenses
Focus
Focus
Prisma AIRS

Prisma AIRS Licenses

Table of Contents

Prisma AIRS Licenses

Learn what is required to activate and onboard your Prisma AIRS license.
Where Can I Use This?What Do I Need?
  • Prisma AIRS
  • Software NGFW Credits
Prisma AIRS uses a bring-your-own license (BYOL) model. This means you must retrieve an authcode from the Palo Alto Networks Customer Support Portal and then apply that authcode when deploying your Prisma AIRS: Network intercept managed by Strata Cloud Manager or Panorama, and Prisma AIRS AI Runtime API
The Prisma AIRS license is funded using Software NGFW credits. To use Software NGFW credits, you must fund a credit pool. You then create a deployment profile to configure one or more Prisma AIRS AI Runtime intercepts based on the number of vCPUs per instance and the total number of instances supported by the deployment profile. All the Prisma AIRS AI Runtime Firewall and API created with a deployment profile share the same authcode.
For Prisma AIRS AI Runtime API, credit usage is calculated in monthly tokens (billions) where each token is equal to four characters. At the end of each calendar month, your token quota resets.

License for Prisma AIRS AI Runtime Firewall

The Prisma AIRS AI Runtime: Network intercept license includes the following AI security services.
  • AI App Protection
  • AI Model Protection
  • AI Data Protection
Additionally, the Prisma AIRS AI Runtime Security (Instance) includes the following cloud-delivered security services.

License for Prisma AIRS AI Runtime API

The Prisma AIRS AI Runtime Security (API) license includes the following Prisma AIRS AI Runtime services:
  • Pro (Cloud Management, Strata Cloud Manager, and ADEM)
  • Enterprise DLP
  • Strata Logging Service
Activating the Prisma AIRS AI Runtime: API intercept deployment in the Customer Support Portal enables the above services on the Hub. The Hub creates instances for the Strata Cloud Manager instance including, the Prisma AIRS AI Runtime API feature.

AI Gateway Metering and Licensing

The Prisma AIRS AI Gateway employs a consumption-based metering model. All AI traffic, including MCP, LLM, and A2A payloads routed through the Gateway is measured in Tokens.
Token consumption calculation:
  1. Prompts (Request/Responses) - Token values returned by the LLM.
  2. MCP Tool calls - Industry-standard conversion rate of 1 Token per 4 plaintext (UTF-8) characters.
  3. A2A requests - Industry-standard conversion rate of 1 Token per 4 plaintext (UTF-8) characters.
This standard applies consistently across both SaaS and Hybrid deployment environments.

Licensing Structure

In alignment with the broader Prisma AIRS portfolio (including AI Runtime, Model Scanning, and Red Teaming), the AI Gateway utilizes Software NGFW credits for licensing. Total credit requirements are estimated based on your organization’s anticipated token usage.
This model includes built-in tiered volume discounts, so as you reach higher usage tiers, the cost per billion tokens decreases. The more you scale, the fewer Flex Credits you'll spend on usage in those higher tiers.
Self-Service Tool: Palo Alto Networks is building an interactive Flex Credit Calculator to convert your projected token usage into required credits instantly.
Need an Estimate Today? Contact your Palo Alto Networks sales representative with your expected token consumption, and your account team will calculate the exact credits needed for your deployment.