Concepts
Limits
What bounds a call, a stream, a socket, a key and a webhook, and how a refusal looks.
Every bound is enforced and every refusal is labelled. The numbers here are the platform's today; a change is announced in the changelog.
| What | Bound | Refusal |
|---|---|---|
| requests per key | 1000 per second at the gateway, bursts to 2000 | 429 rate_limited; every answer carries X-RateLimit-* |
| token requests | 20 per 10 seconds per client address | 429 at the identity provider |
| request body | 2 MiB | 413 payload_too_large |
| answer | 4 MiB | 500 internal (a product that can exceed it pages instead) |
| calls in flight on one socket | 64 | rate_limited on the 65th |
| socket frame from the client | 256 KiB | the frame is refused, the socket stays open |
| open streams per key or person | 32 event streams, sockets and MQTT connections together | 429 rate_limited with Retry-After: 1; MQTT CONNACK 0x97 |
| open streams per account | 128 | the same |
| the account's event streams | 10 open at once, all its keys together (the events service's own bound) | 429 rate_limited |
| a stream's or a socket's life | 24 hours | the stream ends with unavailable; MQTT DISCONNECT 0xA0 |
| an idle socket | 5 minutes with no call in flight and no frame | closed with code 1000, reason idle |
| a revoked key's open streams | end within seconds | unauthenticated; MQTT DISCONNECT 0x87 |
| webhook endpoints | 10 per account | the 11th is refused |
| webhook deliveries in flight | 4 per endpoint | the next waits its turn; nothing is dropped |
| webhook payload | 64 KiB | none: events carry ids and stay far below it |
| test inbox | 1 per account, for 24 hours | a second create answers the inbox you have |
| test inbox requests kept | the last 50 | the oldest is dropped |
| test inbox request body | 64 KiB | 413 payload_too_large |
| test inbox requests | 60 per minute per inbox | 429 rate_limited |
| MQTT packet | 256 KiB | reason code 0x95, the connection closes |
| MQTT QoS 1 messages in flight | 16 (Receive Maximum) | reason code 0x93, the connection closes |
| MQTT subscriptions | 32 per connection | reason code 0x97 for the 33rd |
| MQTT keep-alive | up to 300 seconds | a longer one is lowered to 300 in CONNACK |
Daily allowances
The budget is the account's monthly units (Usage and units). Beside
it, a product bounds what one caller does per day (tokens, sandbox runs, pages), well
above any plan, against abuse, and says so in its own section; the answer carries what
is left (…_left_today) where the product reports it, and the day resets at 00:00 UTC.
A caller over a daily bound gets 429 rate_limited with a retry detail.
Fairness
The per-key rate limit is abuse protection, not a plan. A plan's number is its monthly allowance in units (Usage and units); the console shows an account's usage against it.