Methodology
How we decide whether a Java install is free or needs a paid license
Every rule the report applies, the Oracle page it comes from, and the date we last read that page. Nothing here is behind the paywall — if you disagree with a classification, this is the page to argue with.
The license is set by the build you downloaded
Oracle's FAQ says you "may continue to use releases you have downloaded under the terms of the license under which you downloaded them." An installed no-fee build never becomes paid later. Exposure comes from two places only: Oracle builds that are already under OTN, and updating or pulling a newer Oracle build that is OTN. Oracle JDK licensing FAQ, checked 2026-09-11.
This page is not legal advice, and RuntimeClear is not affiliated with Oracle. It tells you what we classified and why, so that you — or your counsel — can check it.
What each status means
| Status | Meaning |
|---|---|
| free | A non-Oracle OpenJDK build, an Oracle OpenJDK build under GPLv2+CPE, or an Oracle JDK build under NFTC or BCL. |
| at risk | Free today under NFTC, but the next Oracle update, image pull or auto-update brings an OTN build. Oracle JDK 21 is the main case. |
| paid license | An Oracle JDK build under OTN. Commercial production use needs a Java SE subscription unless an OTN exception applies. |
| needs review | Signals conflict, the vendor or version is unknown, it is Oracle GraalVM, the version had not been released as of the check date, or the line is vendor-neutral. The engine marks these rather than guessing. |
1 · Oracle JDK and JRE, by version
Applies once an install has been identified as an Oracle JDK — see section 5 for how that identification is made.
| Product line | Version range | License | Status | Free for commercial production? | Primary source |
|---|---|---|---|---|---|
| Oracle JDK/JRE 6 | 6 – 6u45 (last public, archive) | BCL | free | Yes, for general-purpose desktops and servers. "Commercial Features" and embedded use are excluded. | Java 6 archive · BCL text |
| Oracle JDK/JRE 7 | 7 – 7u80 (last public, archive) | BCL | free | Yes, same BCL caveats. | Java 7 archive |
| Oracle JDK/JRE 8 | 8 – 8u202 (1.8.0_202-b08, 15 Jan 2019) | BCL | free | Yes. BCL caveats: Commercial Features such as JFR behind -XX:+UnlockCommercialFeatures, and embedded use, need a separate license. No longer patched. |
8u202 release notes · Java 8 archive, 8u202 and earlier · FAQ |
| Oracle JDK/JRE 8 | 8u203 – 8u210 | — | needs review | No public release uses these numbers. | same archive pages |
| Oracle JDK/JRE 8 | 8u211+ (1.8.0_211-b12, 16 Apr 2019) and later, through 8u501 / 8u503 | OTN | paid license | No. Free only for personal use, development/testing/prototyping/demo, Oracle-approved products, and Oracle Cloud Infrastructure. | 8u211 release notes · Java 8 archive, 8u211 and later · java.com license notice |
| Oracle JDK 9 | 9, 9.0.1, 9.0.4 | BCL | free | Yes, BCL caveats. EOL. | Java 9 archive |
| Oracle JDK 10 | 10, 10.0.1, 10.0.2 | BCL | free | Yes, BCL caveats. EOL. | Java 10 archive |
| Oracle JDK 11 | every release from GA (11.0.0, Sep 2018) onward | OTN | paid license | No. This is the version people most often assume is free and it never was. | JDK 11 release notes · FAQ table: Java 11, all releases |
| Oracle JDK 12–16 | all releases | OTN | paid license | No. Verified individually for 12, 13, 14, 15 and 16. | Release notes for 12, 13, 14, 15, 16 |
| Oracle JDK 17 | 17 – 17.0.12 (Jul 2024; releases through Sep 2024) | NFTC | free | Yes. No longer patched under NFTC. | FAQ table · support roadmap |
| Oracle JDK 17 | 17.0.13+ (17.0.13+10, released 15 Oct 2024), currently to 17.0.20.1 | OTN | paid license | No. This is the boundary most inventories miss: 17.0.12 and 17.0.13 look identical in a version string. | 17.0.13 release notes · roadmap · Oracle blog, 16 Apr 2024 |
| Oracle JDK 18, 19, 20, 22, 23, 24 | all releases | NFTC | free | Yes. EOL, no updates. | FAQ: six-month non-LTS releases |
| Oracle JDK 21 | 21 – 21.0.12 (21.0.12+7, 21 Jul 2026) and 21.0.12.1 (21.0.12.1+1, 18 Aug 2026) — the latest release so far | NFTC | at risk | Yes, for that build. The next update is OTN. | 21.0.12 release notes · 21.0.12.1 release notes · Oracle blog, 14 Aug 2026 |
| Oracle JDK 21 | 21.0.12.2 and higher 21.0.12.x | — | needs review | Not released as of 2026-09-11. NFTC if Oracle ships it in September 2026, OTN if it ships later. The engine will not guess. | same |
| Oracle JDK 21 | 21.0.13+, the October 2026 CPU (20 Oct 2026) onward. Planned, not yet released. | OTN (planned) | paid license | No, once it ships. | roadmap: updates released after September 2026 · blog · CPU dates |
| Oracle JDK 25 | 25 – 25.0.12, currently 25.0.4.1 | NFTC | free | Yes. NFTC planned "until September of 2028". | FAQ · roadmap |
| Oracle JDK 25 | 25.0.13 and later (October 2028 or later) | — | needs review | Unknown. OTN is planned but not published. | same |
| Oracle JDK 26 | all, currently 26.0.2.1 | NFTC | free | Yes, for its entire planned six-month support life. | FAQ: non-LTS releases |
| Oracle JDK 27+ | any | — | needs review | Not released as of the check date. | — |
One inference, stated plainly
That the October 2026 CPU is update 21.0.13 is our inference, not Oracle's words. Oracle names the date. We infer the version from its numbering, where every CPU raises the update number by one — 21.0.12 was the July 2026 CPU, and 17.0.13 was the October 2024 CPU. If Oracle numbers it differently, this row is wrong and we will correct it. See section 8 for the full list of things in this class.
2 · What OTN and NFTC actually allow
OTN permits free use only for: personal use ("solely on a desktop or laptop computer under such Individual's control only to run Personal Applications"); development use ("to develop, test, prototype and demonstrate Your Applications"); running Oracle-approved products listed in its schedules; and use on Oracle Cloud Infrastructure. The license adds that if "You want to use the Programs for any purpose other than as expressly permitted … You must obtain … a valid Program license." Oracle's FAQ is blunt about where the personal-use line falls: "If you are using Java on a desktop or laptop computer as part of any business operations, that is not personal use." OTN license text (updated 10 Apr 2019), FAQ, checked 2026-09-11.
The report always shows these exceptions as a note. It never uses one to mark something free, because whether an exception applies depends on facts about your deployment that a scanner cannot see.
NFTC grants free use "including in commercial and production use", and permits redistribution as long as it is not for a fee. NFTC text, FAQ, checked 2026-09-11.
3 · OpenJDK and non-Oracle builds
| Product | License | Status | Source |
|---|---|---|---|
| Oracle OpenJDK (jdk.java.net) | GPLv2+CPE | free | FAQ table · jdk.java.net — free, but Oracle updates each release for only about six months, so the report adds an action to move to a maintained build |
| Oracle GraalVM | GFTC or GraalVM OTN | needs review | GFTC text · blog · graalvm.org — for JDK 17 the GraalVM OTN license applies after Sep 2024; for JDK 21 GraalVM OTN is planned from the Oct 2026 CPU |
| GraalVM Community Edition | GPLv2+CPE | free | setup-java license table · OpenJDK GPLv2+CE |
| Eclipse Temurin (Adoptium) | GPLv2+CPE | free | adoptium.net — "no licensing fees" |
| Amazon Corretto | GPLv2+CPE | free | Corretto FAQ — "at no cost" |
| Azul Zulu community builds | GPLv2+CE | free | Azul Core — "zero licensing fees". Zulu SA subscriber builds are paid support, not a paid license to run |
| BellSoft Liberica JDK | Vendor | free | Liberica JDK — "completely free to use in production" |
| Microsoft Build of OpenJDK | Vendor | free | Microsoft Learn — "free for anyone to deploy anywhere" |
| Red Hat build of OpenJDK | GPL | free | Red Hat Developer — no-cost; support comes with a subscription |
| SAP SapMachine | Vendor | free | sapmachine.io — "completely free to use in development and production" |
| IBM Semeru Runtimes | GPLv2+CE / IBM | free | Semeru downloads — Open Edition is GPLv2+CE; Certified Edition is a no-cost IBM license |
Unrecognised vendor reporting OpenJDK Runtime Environment, with no Oracle commercial marker | GPLv2+CPE | free | OpenJDK branding defaults |
| IBM SDK (non-Semeru), ISV-bundled JDKs, anything else | Unknown | needs review | — |
Vendor support contracts are a separate thing from the license to run the binaries. None of the vendors above requires a paid subscription to run their builds in production.
4 · Dockerfiles, CI and build tools
A reference is a place where Oracle Java would be pulled, not where it is installed today: a Dockerfile, a CI workflow, an SDK manager file, a build-tool toolchain. These are the installs-in-waiting that agent-based inventory tools structurally cannot see, because nothing has been installed yet.
| Reference | What it pulls | Status | Source |
|---|---|---|---|
actions/setup-java with distribution: oracle, java-version: 21 | The major version only, from Oracle's script-friendly URLs. Oracle says the JDK 21 latest URLs "will cease to work on October of 2026". | at risk | setup-java Oracle installer · Oracle script-friendly URLs |
setup-java oracle with 25, 26 or latest | NFTC builds. | free | setup-java README |
setup-java oracle with 17 | The JDK 17 latest URLs stopped working in October 2024; archive URLs for 17.0.12 and earlier were promised "at least until October of 2025". | needs review | script-friendly URLs |
setup-java oracle-openjdk | jdk.java.net GPL builds. | free | setup-java README |
container-registry.oracle.com/java/jdk:<tag> | Oracle's registry has images for every JDK release. A floating tag follows the newest update of that line. | Floating 8/11/17 → paid license; floating 21 → at risk; 25/26 → free; pinned tags → section 1; no tag → needs review | oracle/docker-images OracleJava README |
container-registry.oracle.com/java/jdk-no-fee-term:<tag> | Images covered by NFTC; no login required. | 21 → at risk (no further 21 patches after Sep 2026; getting them from Oracle means OTN); 17 → free but unpatched; 25/26 → free | same |
Docker Hub openjdk:<tag> | GPL builds. Officially deprecated; only EA tags updated since July 2022. | free, with an action to move to eclipse-temurin | deprecation notice |
eclipse-temurin, amazoncorretto, azul/zulu-openjdk, bellsoft/liberica-*, mcr.microsoft.com/openjdk/jdk, Red Hat UBI OpenJDK, sapmachine, ibm-semeru-runtimes | Vendor OpenJDK. | free | Vendor pages, section 3 |
SDKMAN identifiers ending -oracle | Oracle JDK, classified by version per section 1. -graal → review; -graalce, -open, -tem, -amzn and similar → free. | Per version | sdkman.io/jdks |
Gradle vendor = JvmVendorSpec.ORACLE | Matches any JDK whose vendor is Oracle — Oracle JDK or Oracle OpenJDK. Ambiguous by design. | needs review | Gradle toolchains |
Maven <vendor>oracle</vendor> | A free-text match against each machine's own toolchains.xml. | needs review | Maven toolchains |
CI build and test jobs count as "develop, test, prototype and demonstrate", which OTN allows. The exposure is OTN builds that end up in production images or on servers — so every OTN reference carries that note rather than an accusation.
5 · How an install is identified as Oracle
The scanner reads the plain-text release file in each Java home, and only runs java -version when there isn't one. These are the signals it weighs, and how much weight each one carries.
| Signal | Meaning | Confidence |
|---|---|---|
Bundled license text (legal/java.base/LICENSE, LICENSE, COPYRIGHT) naming OTN, NFTC, BCL or GPL | The license the build actually shipped with. | Strongest signal available. If it disagrees with the version rules, the result is needs review rather than a guess. |
Runtime name Java(TM) SE Runtime Environment | Oracle JDK or JRE. Oracle GraalVM prints it too, so GraalVM is checked first. | Documented: JDK 11 release notes — "Oracle JDK will say java and include LTS. OpenJDK (when produced by Oracle) will say OpenJDK". |
BUILD_TYPE="commercial" in the release file | An Oracle JDK commercial build. | Not documented by Oracle. The open-source build never writes this key (openjdk/jdk21u), so it comes from Oracle's closed build. Confirmed on a real Oracle JDK 11.0.24 macOS install on 2026-09-11, where Oracle OpenJDK 20.0.x on the same machine had no BUILD_TYPE. Treated as strong, never as sufficient alone. |
IMPLEMENTOR="Oracle Corporation" | Oracle JDK or Oracle OpenJDK. | Not enough on its own. The engine returns needs review when this is the only signal. |
OpenJDK Runtime Environment | An OpenJDK (GPL) build. | OpenJDK default branding. |
| rpm or dpkg vendor field saying "Oracle" | — | Deliberately ignored. Oracle Linux ships GPL OpenJDK packages too, so this would produce false positives. |
| An Oracle signal and an OpenJDK signal on the same install | Conflict. | needs review |
javaVersion and rawVersion disagreeing | Conflict. | needs review |
6 · Auto-update
An enabled Oracle Java updater on a business machine is flagged at risk, because every Oracle Java 8 release since 8u211 (16 Apr 2019) is OTN — so accepting an update installs an OTN build. Java Update "periodically checks for new versions" and asks permission to upgrade. What is Java Update?, java.com license notice, checked 2026-09-11. A disabled updater is reported for information only.
Noted but not auto-classified: winget's Oracle.JavaRuntimeEnvironment manifests are 8u251 and later, which are OTN — so winget upgrade --all on a machine with an Oracle JRE installs an OTN build. microsoft/winget-pkgs, checked 2026-09-11.
7 · The subscription list price
Used only to produce an estimate of what Oracle's list price would be. It is not a quote, and the report labels it as an estimate everywhere it appears.
| Total employees | USD per employee per month |
|---|---|
| 1 – 999 | $15.00 |
| 1,000 – 2,999 | $12.00 |
| 3,000 – 9,999 | $10.50 |
| 10,000 – 19,999 | $8.25 |
| 20,000 – 29,999 | $6.75 |
| 30,000 – 39,999 | $5.70 |
| 40,000 – 49,999 | $5.25 |
| 50,000+ | Contact Oracle |
The whole employee count is priced at its tier's rate; the annual cost is the monthly figure times twelve. "Employee" is defined by the price list as "(i) all of Your full-time, part-time, temporary employees, and (ii) all of the full-time employees, part-time employees and temporary employees of Your agents, contractors, outsourcers, and consultants" who support your internal business operations. That counts every employee, not only the ones who touch Java.
Source: Oracle's Java SE Universal Subscription global price list. The tiers were read from the 1 March 2023 edition, via a university mirror, because oracle.com's robots.txt blocks automated fetching. Oracle's subscription FAQ confirms the endpoints: "Pricing starts at $15/employee per month. Published tier pricing is as low as $5.25 per month." Checked 2026-09-11. See section 8, item 4.
8 · What we could not verify from an official source
Seven things. Each is used in a way that limits the damage if it turns out to be wrong, and we would rather you read this list than discover it yourself.
BUILD_TYPE="commercial"as an Oracle JDK marker. Oracle does not document it. Observed on a real Oracle JDK 11.0.24 install on 2026-09-11. The engine still requires that no OpenJDK signal contradicts it.- That jdk.java.net Oracle OpenJDK builds set
IMPLEMENTOR="Oracle Corporation". The engine returns needs review whenever implementor is the only signal, so this cannot by itself cause a paid classification. - That Oracle JDK 21.0.13 is the first OTN build. Inferred from CPU numbering. Oracle only says "October 2026 CPU", and the build is not released yet.
- The middle price tiers, $12.00 down to $5.70. From the March 2023 edition of the price list. The current PDF on oracle.com could not be fetched. The report labels every cost figure a list-price estimate.
- The license terms of pinned-version
container-registry.oracle.com/java/jdkimages beyond the JDK's own license — registry access is under Oracle's standard terms. Pinned NFTC-version tags are classified by JDK version, with a note. - SDKMAN suffixes other than
tem,oracle,graalandamzn— for examplezulu,librca,ms,sapmchn,sem,graalce,open. These come from SDKMAN's current listing conventions rather than a fetched page. - Temurin deb and rpm packages for non-LTS 26 (
temurin-26-jdk). The engine adds a note to check the repository tree.
9 · How often this is rechecked
Every rule above carries the date we last read its source. The whole file is reviewed:
- On every Oracle Critical Patch Update date — January, April, July and October (Oracle's CPU schedule).
- Whenever Oracle publishes a licensing change or a new support roadmap.
- Whenever someone reports a misclassification.
Each review updates the check date on every row, whether or not the row changed — so a stale date means we have not looked, not that nothing happened. The rules file is fetched by the report at run time, so a correction reaches everyone's next report without anyone reinstalling anything.
10 · Where the migration commands come from
The report's runbook does not invent commands. Each one comes from the vendor's own installation documentation, read on 2026-09-11:
- Temurin on Debian and RPM distributions — adoptium.net/installation/linux. The RPM form uses
sudo teerather than the docs'sudo cat <<EOF >, which does not write as root. - Corretto on Linux — AWS Corretto install guide.
- Removing an Oracle JDK — Oracle's own Linux and macOS installation guides, and java.com's JRE uninstall page.
- macOS —
brew install --cask temurin@21, from the Adoptium source in Homebrew Cask. - Windows —
winget install EclipseAdoptium.Temurin.21.JDK, from the Adoptium source in winget-pkgs. - Docker —
FROM eclipse-temurin:21-jdk, docker-library official images. - GitHub Actions —
actions/setup-java@v6withdistribution: 'temurin'(setup-java README). - SDKMAN — sdkman.io/usage.
- Gradle —
vendor = JvmVendorSpec.ADOPTIUMwith the foojay resolver (Gradle toolchains). - Maven —
toolchains.xmlwith maven-toolchains-plugin 3.3.0.
11 · Corrections
If a classification is wrong, we want to know, and the fix is public. Open a misclassification report or email support@runtimeclear.com with the install's release file contents and the Oracle page you think applies.
Corrections are recorded in the changelog with the date and the source that settled it.