These limits are enforced by the platform or the SDK. The values are the defaults the platform runs with. Each limit links to the page of the feature it belongs to, which states it too. Budgets you choose for your own workflow (steps per run, payload sizes you assert in tests) are on Best practices.
Webhook triggers
| Limit |
Value |
When you hit it |
What to do |
| Request body |
1 MiB |
413 PAYLOAD_TOO_LARGE, “webhook body too large” |
Send a reference (an object path, a URL, an id) and fetch the content in a step. |
| Body shape |
A JSON object or array |
400. An array is delivered as { "body": [...] }. |
Send an object. |
| Calls per key |
60 per minute, bursts of 10 |
429 RATE_LIMITED with a Retry-After header in seconds |
Honour Retry-After. Give each caller its own key. |
Idempotency-Key header |
255 bytes |
400 “Idempotency-Key is longer than 255 bytes” |
Use a short id (a UUID or your request id). |
| Waiting for the result |
30 s when the endpoint sets no timeout; 120 s at most |
202 with status, runId, and statusUrl; the run carries on |
Poll statusUrl, or respond immediately and read the result later. |
Events and the vault
Schedules
| Limit |
Value |
When you hit it |
What to do |
| Granularity |
1 minute: a 5-field cron, or @hourly / @daily-style descriptors |
An expression with a seconds field is refused |
Use a standard 5-field cron. |
| Late fire |
A fire more than 4 minutes late is skipped |
That tick does not run |
Make each run cover “since the last run”, not “the last minute”. |
Connector actions
| Limit |
Value |
When you hit it |
What to do |
| Time per attempt |
20 s |
The attempt fails and is retried |
Keep actions small. |
| Attempts |
5, with backoff |
The action step fails with connector.action.failed |
Handle the failure path in the graph. |
Workflow runner
| Limit |
Value |
When you hit it |
What to do |
| Input held by a waiting step |
1 MiB (1,048,576 bytes) |
The step fails: “the input carried by step ‘…’ is N bytes, over the 1048576-byte limit a waiting step can hold” |
Shrink the carried item before agent and human steps. |
| Items in flight per region |
8 in a parallel region, 1 in a sequential one |
Further items wait their turn |
Nothing; size your item count for the latency you need. |
Loop bound (loop.max) |
1 to 100 |
The graph is refused at validation |
Bound loops tightly and set exhausted. |
| Run participants |
2 to 64, including the initiator |
The run is refused |
Split large groups. |
| Exchanges in one step (agent asks, person answers) |
12 |
The step fails: “gave up after 12 exchanges without a final answer” |
Ask for everything at once. |
| Model call attempts |
3 (transport failures only, 400 ms then 1600 ms apart) |
The model step fails |
Treat a failed model step as a normal failure path. |
| Human step answer: note, or one value |
20,000 characters each |
The answer is rejected (note_too_long, invalid_field:<name>) |
Ask for less, or collect a document. |
| Human step answer: values |
64 |
The answer is rejected (too_many_values) |
Split the form. |
| Document saved in a step |
2,000,000 characters |
The save is rejected (invalid_field:body) |
Store large documents as objects. |
| SQL in a Cubby step |
No {{ $json.… }} templates |
The step fails: “SQL may not interpolate the run’s data” |
Use ? and args. |
defineWorkflow refuses at build time: duplicate step ids, an unknown step kind, an agent step without use, a model step whose alias is not in models, a graph with no trigger, an edge to an unknown step, and a step nothing is wired into.
Cubbies
| Limit |
Value |
When you hit it |
What to do |
| Size of one cubby |
10 GB |
Writes are refused: 413 QUOTA_EXCEEDED, “storage quota exceeded” |
Delete or archive old rows; keep large content as objects. |
Logs and run history
| Limit |
Value |
When you hit it |
What to do |
| Task log query window |
24 hours |
Older logs come back empty |
Record anything you need later in a cubby row. |
| Finished Jobs and their Tasks |
Kept 7 days |
Older runs are deleted |
Capture runs worth keeping as dataset cases. |
Evaluations
| Limit |
Value |
When you hit it |
What to do |
| Dataset name |
^[a-z0-9][a-z0-9-]{0,62}$ |
Refused |
Lowercase, digits, hyphens. |
| Case id |
[A-Za-z0-9._-], 1 to 80 characters |
Refused |
|
$regex pattern |
256 characters, no nested quantifiers |
The field fails: unsafe $regex refused: … |
Simplify the pattern. |
| Run experiment in ROC |
Repeats 1 to 20, Concurrency 1 to 16, Timeout 10 to 3600 s |
The dialog refuses to start |
Use cef eval run for other values. |