DocsGuide

Limits

What bounds a call, a stream, a socket and a key, and how a refusal looks.

Every bound is enforced and every refusal is labelled. The numbers here are the platform's today; a change is announced in the changelog.

WhatBoundRefusal
requests per key1000 per second at the gateway, bursts to 2000429 rate_limited
token requests20 per 10 seconds per client address429 at the identity provider
request body2 MiB413 payload_too_large
answer4 MiB500 internal (a product that can exceed it pages instead)
calls in flight on one socket64rate_limited on the 65th
socket frame from the client256 KiBthe frame is refused, the socket stays open
a stream or a socketno timeoutnone

Daily allowances

A product may bound what a key does per day (tokens, runs, pages) and says so in its own section; the answer carries what is left (…_left_today) and the day resets at 00:00 UTC. A key over its allowance gets 429 rate_limited with a retry detail. Allowances belong to the account, so several keys of one account share them.

Fairness

The per-key rate limit is abuse protection, not a plan. A plan's number is its monthly allowance in units (Usage and units); the console shows an account's usage against it.