Polly
Polly is the de-facto resilience and transient-fault-handling library for .NET. It lets you express strategies such as Retry, Circuit Breaker, Timeout, Rate Limiter, Fallback, and Hedging in a fluent, thread-safe way, and it is the engine behind Microsoft's Microsoft.Extensions.Resilience and Microsoft.Extensions.Http.Resilience packages. Polly is a .NET Foundation member project and its source is licensed under the New BSD License (BSD-3-Clause).
On 14 July 2026 the Polly team announced that Polly is adopting the Open Source Maintenance Fee (OSMF) model, effective 16 November 2026 — a four-month notice period before enforcement.
What Changed
The source license does not change. In the words of Joel Hulen, Lead Polly Project Owner:
"The source code remains free and open. Polly stays under its existing open source license. Nothing about your right to read, fork, build from, and contribute to the source changes."
What changes is the NuGet package license on releases published from 16 November 2026 onward: those binaries carry an OSMF clause requiring revenue-generating organizations to pay a monthly maintenance fee. Because a package's license is immutable once shipped, the change is not retroactive — every version released on or before that date keeps its current terms.
Unlike Verify, the Polly team has not announced any build-time sponsorship check or EULA-style enforcement tooling. The obligation is contractual, tied to the package license.
Who Pays and How Much
- Fee: $20/month, paid via GitHub Sponsors. The exact sponsorship tier and instructions are to be published before November 2026.
- Threshold: organizations that earn at least US $20,000 from products or projects that use Polly.
- Per organization, not per project — one fee covers all of a company's usage.
- Exempt: individuals, hobbyists, students, and nonprofits that do not generate Polly-derived revenue; anyone using Polly for free (non-revenue) purposes.
- Direct dependencies only. If Polly reaches your app transitively — for example through
Microsoft.Extensions.Http.Resilience— the fee does not apply. It applies when you referencePolly(orPolly.Core) directly.
The fee is not a support contract or an SLA.
What This Means For You
- Using Polly only transitively (via
Microsoft.Extensions.*.Resilience): nothing to do. - Using Polly directly, as an individual / non-revenue / under $20k: still free.
- Using Polly directly in a revenue-generating organization above the threshold: budget $20/month from November 2026, or pin to a version released before then.
- Want to avoid the obligation entirely: pin to a pre-OSMF release, consume Polly only through the Microsoft resilience packages, or move to the BSD-3-Clause community fork Fences.
Alternatives
Polly is deep and well-integrated; there is no drop-in replacement with the same breadth. The realistic options are:
-
Pin to a pre-OSMF version of Polly:
- Any release published on or before 16 November 2026 keeps its current BSD-only NuGet license.
- Pros: zero code change, full feature set, free.
- Cons: no future updates, security fixes, or new .NET target support on that pinned line.
-
Consume Polly through
Microsoft.Extensions.Http.Resilience/Microsoft.Extensions.Resilience:- Microsoft's first-party resilience packages are built on Polly but reference it transitively, so the maintenance fee does not apply.
- Pros: MIT-licensed, first-party, covers the common HTTP retry / circuit-breaker / timeout scenarios with standard handlers.
- Cons: opinionated pipeline shape; less direct control than using the Polly API yourself; you are still relying on Polly underneath.
-
Fences — the community fork:
- After opening a "Forking Polly" discussion on 18 August 2026, Ian Cooper and the Brighter Command team forked Polly 8.7.0 as Fences, published on NuGet under the
Paramore.Fences.*prefix (9.0.0 stable on 29 August 2026). BSD-3-Clause, no maintenance-fee EULA; the v8-era API mirrors Polly's exactly. - Pros: drop-in for the Polly 8 API, free binaries, no procurement conversation.
- Cons: young project, small maintainer pool, not affiliated with or endorsed by App vNext, and future major versions may diverge from Polly.
- Rolling your own fork is equally legitimate — BSD-3-Clause permits redistribution and modification, and a self-built binary carries only the BSD terms — but then you own maintenance, security patching, and CI.
- After opening a "Forking Polly" discussion on 18 August 2026, Ian Cooper and the Brighter Command team forked Polly 8.7.0 as Fences, published on NuGet under the
-
Hand-rolled resilience:
- For simple cases,
HttpClientwith a customDelegatingHandler,PeriodicTimer-based retry loops, orSystem.Threading.RateLimiter(built into .NET 7+) can cover retry, timeout, and rate limiting without a dependency. - Cons: circuit breaker, hedging, and bulkhead isolation are non-trivial to implement correctly; easy to get backoff/jitter wrong.
- For simple cases,
Conclusion
Polly's source stays open under BSD-3-Clause, but packages released from 16 November 2026 add an Open Source Maintenance Fee: $20/month for organizations earning $20k+ that depend on Polly directly. Transitive use via Microsoft's resilience packages is unaffected, individuals and non-revenue users pay nothing, and teams that want to opt out can pin to a pre-OSMF release or move to the BSD-3-Clause community fork Fences.
Links and References
- The Polly Project: Introducing the Open Source Maintenance Fee for Polly
- GitHub Discussion: OSMF adoption (App-vNext/Polly#3183)
- GitHub: App-vNext/Polly
- GitHub Sponsors: App-vNext
- Open Source Maintenance Fee: Home · For Consumers · FAQ
- Fork: BrighterCommand/Fences · Forking Polly (App-vNext/Polly#3202)
- Context: .NET Foundation statement on Open Source Maintenance Fees
- Microsoft Docs: Build resilient HTTP apps
- Similar model: Verify · NPOI · WiX Toolset
Related News
- 2026-08-29
Fences: a BSD-3-Clause community fork of Polly ships to NuGet
After opening a "Forking Polly" discussion on 18 August 2026, Ian Cooper and the Brighter Command team published Fences — a fork of Polly 8.7.0 that keeps the BSD-3-Clause terms and carries no maintenance-fee EULA. Packages ship under the Paramore.Fences.* prefix (9.0.0 stable on 29 August 2026) and the v8-era API mirrors Polly's exactly. It is not affiliated with or endorsed by App vNext.
- 2026-08-29
Coding Bolt: The Polly Drama Explained
A walkthrough of the reaction to Polly's Open Source Maintenance Fee. The argument made is that the $20/month is not the real cost — the friction is legal review, procurement and dependency-policy overhead once commercial terms enter the dependency tree. Covers the Fences fork and the .NET Foundation's clarification that consumers must review terms beyond the source license.
- 2026-08-29
Renato Golia: Free software never promised free labour
Golia argues an open source license is a backward-looking promise about code already published, not a commitment to perpetual free maintenance — which is why fee models that leave existing releases untouched sit differently from retroactive relicensing. Draws parallels with Elasticsearch/OpenSearch and Redis/Valkey alongside the AutoMapper, MediatR and Polly changes.
- 2026-08-21
Aaron Stannard: The .NET OSS Relicensing Panic Is an Incentives Problem
Aaron Stannard argues the wave of .NET relicensing is a predictable market outcome of misaligned incentives rather than a crisis: maintainers carry enterprise-grade expectations on volunteer funding. His advice to commercial users is to sponsor critical dependencies proactively and become customers rather than free consumers, citing Polly and Verify as the current flashpoints and IdentityServer as a relicensing that worked out commercially.
- 2026-08-19
.NET Foundation Statement on Open Source Maintenance Fees
The .NET Foundation published a statement and FAQ on maintenance-fee models, declining to take a position for or against them. Foundation projects may adopt OSMF-style funding provided the source stays freely available under a permissive license, anyone can build equivalent artifacts themselves, and mandatory dependencies remain permissively licensed. Consumers are urged to read the terms attached to packages, not just the source license.
- 2026-07-14
Introducing the Open Source Maintenance Fee for Polly
The Polly team announced that Polly is adopting the Open Source Maintenance Fee model, effective 16 November 2026. The BSD-3-Clause source license is unchanged, but NuGet packages released from that date add an OSMF clause: organizations earning at least $20,000 from products that depend on Polly directly are expected to pay $20/month via GitHub Sponsors. Transitive use via Microsoft.Extensions.*.Resilience is exempt.