Skip to content

Limits ​

The API applies a small number of fixed bounds. They are chosen to stop a looping script, not to constrain a legitimate integration. When a bound is reached, the response says so with a status and a code (Errors).

Requests ​

BoundValueWhen exceeded
Requests per API key600 per sliding minute429 api_key.rate_limited, Retry-After in seconds
Sign-in attemptsPer IP address429 auth.too_many_attempts, Retry-After
Request body5 MB413, code request.payload_too_large, details.reason: "FST_ERR_CTP_BODY_TOO_LARGE"
Webhook trigger body (POST /hooks/wf/{token})256 KB of JSON413, code request.payload_too_large
triggerData of a test run256 KB, like the real webhook400

The rate limit is per key: give each integration its own key and none of them will throttle the others. Attachments are not JSON bodies: they are uploaded as multipart/form-data through POST /api/v1/messages/attachments, one file per request, 25 MB at most (413 above; executables and scripts are refused with 400).

Idempotency ​

BoundValue
Idempotency-Key length1 to 200 characters (400 idempotency.invalid_key otherwise)
Memory of a key24 hours
Stored response64 KB; above, the response is served but not memorised (Idempotency-Replayed: unsupported)

See Idempotency.

Lists ​

Listlimit defaultlimit maximum
Executions, waiting executions, incidents, messages, threads, contacts, journals, audit log, evaluation cases50200
Approvals50100
Morning review25100
Notifications30100
Tables rows (offset pagination)100500

A limit above the maximum is a 400 request.bad_request, not a silent clamp. The exact bounds of each route are in the reference.

Tables ​

BoundValueWhen exceeded
offset of GET /api/v1/tables/{id}/rows100 000400; a page beyond the filtered rows is tables.page_out_of_range
Filters per request (filter)20 conditions400
Rows, columns, tables per instanceSet by the instance; read them with GET /api/v1/tables/limits409 tables.limit_reached, details.limit names the bound

Bulk operations ​

OperationBound
POST /api/v1/executions/cancel200 execution ids per call
POST /api/v1/workflows/{id}/executions/cancel and …/retry-failedlimit 1 to 200 per call, default 50; hasMore says whether to call again
…/retry-failed since30 days at most, 24 hours by default
PUT /api/v1/workflows/{id}/test-messages20 pinned messages

API keys ​

BoundValue
Name1 to 120 characters
Scopes per key1 to 20
Expiry (expiresInDays)1 to 730 days, or none
lastUsedAt precisionOne minute

Workflows and executions ​

The execution engine has bounds of its own: how many runs of a workflow may be in flight at once (maxConcurrency), how long a run may stay active (executionTimeoutMs), how long a wait may last. Each workflow reports the effective values and the ceilings of the instance in executionLimits, returned by GET /api/v1/workflows/{id}; asking for more than the ceiling through PATCH /api/v1/workflows/{id} is 409 workflow.execution_limit_invalid. See Executions and Configuration.