English
Limits
The API applies a small number of fixed bounds. They are chosen to stop a looping script, not to constrain a legitimate integration. When a bound is reached, the response says so with a status and a code (Errors).
Requests
| Bound | Value | When exceeded |
|---|---|---|
| Requests per API key | 600 per sliding minute | 429 api_key.rate_limited, Retry-After in seconds |
| Sign-in attempts | Per IP address | 429 auth.too_many_attempts, Retry-After |
| Request body | 5 MB | 413, code request.payload_too_large, details.reason: "FST_ERR_CTP_BODY_TOO_LARGE" |
Webhook trigger body (POST /hooks/wf/{token}) | 256 KB of JSON | 413, code request.payload_too_large |
triggerData of a test run | 256 KB, like the real webhook | 400 |
The rate limit is per key: give each integration its own key and none of them will throttle the others. Attachments are not JSON bodies: they are uploaded as multipart/form-data through POST /api/v1/messages/attachments, one file per request, 25 MB at most (413 above; executables and scripts are refused with 400).
Idempotency
| Bound | Value |
|---|---|
Idempotency-Key length | 1 to 200 characters (400 idempotency.invalid_key otherwise) |
| Memory of a key | 24 hours |
| Stored response | 64 KB; above, the response is served but not memorised (Idempotency-Replayed: unsupported) |
See Idempotency.
Lists
| List | limit default | limit maximum |
|---|---|---|
| Executions, waiting executions, incidents, messages, threads, contacts, journals, audit log, evaluation cases | 50 | 200 |
| Approvals | 50 | 100 |
| Morning review | 25 | 100 |
| Notifications | 30 | 100 |
Tables rows (offset pagination) | 100 | 500 |
A limit above the maximum is a 400 request.bad_request, not a silent clamp. The exact bounds of each route are in the reference.
Tables
| Bound | Value | When exceeded |
|---|---|---|
offset of GET /api/v1/tables/{id}/rows | 100 000 | 400; a page beyond the filtered rows is tables.page_out_of_range |
Filters per request (filter) | 20 conditions | 400 |
| Rows, columns, tables per instance | Set by the instance; read them with GET /api/v1/tables/limits | 409 tables.limit_reached, details.limit names the bound |
Bulk operations
| Operation | Bound |
|---|---|
POST /api/v1/executions/cancel | 200 execution ids per call |
POST /api/v1/workflows/{id}/executions/cancel and …/retry-failed | limit 1 to 200 per call, default 50; hasMore says whether to call again |
…/retry-failed since | 30 days at most, 24 hours by default |
PUT /api/v1/workflows/{id}/test-messages | 20 pinned messages |
API keys
| Bound | Value |
|---|---|
| Name | 1 to 120 characters |
| Scopes per key | 1 to 20 |
Expiry (expiresInDays) | 1 to 730 days, or none |
lastUsedAt precision | One minute |
Workflows and executions
The execution engine has bounds of its own: how many runs of a workflow may be in flight at once (maxConcurrency), how long a run may stay active (executionTimeoutMs), how long a wait may last. Each workflow reports the effective values and the ceilings of the instance in executionLimits, returned by GET /api/v1/workflows/{id}; asking for more than the ceiling through PATCH /api/v1/workflows/{id} is 409 workflow.execution_limit_invalid. See Executions and Configuration.