Rate limits and quotas

Rate limits and quotas

Request budgets per minute, sign-in limits, account limits on Kisten, disk and running Kisten, and every per-feature limit.

Rate limits

Requests to kiste.run are counted per minute. A request over a budget gets 429 Too Many Requests with a Retry-After header and error L01 (or A03 for sign-in). The CLI waits and tells you how long.

BudgetCounted perLimit
All API requestsnetwork address (IPv6: per /64)600 per minute
All requests of an accountaccount600 per minute
Changes of an account (POST, PUT, PATCH, DELETE)account120 per minute
Sign-in, OAuth and token endpointsnetwork address30 per minute, and at most 20 within 10 seconds
Password sign-innetwork address and e-mail address10 per 15 minutes
Password sign-in, any e-mail addressnetwork address30 per 15 minutes
CLI token exchangenetwork address10 per 15 minutes
Billing actions that reach the payment provideraccount20 per minute
Desktop sessionsaccount120 per 15 minutes
Live usage samples (status --usage, metrics)account40 per minute
Webhook changes and test deliveriesaccount20 per minute
Each published port on Kiste Streamport, all visitors together1,200 per minute

Downloads of the CLI and the installers are not limited beyond Cloudflare's protection against attacks. Long-running requests such as kiste exec have no deadline of their own beyond your client's.

Account limits

Every account has limits on what it can hold and run. kiste limits shows yours and what is in use:

kiste limits
LimitError when reached
Number of KistenL02
Disk of all Kisten and snapshots togetherL04
Kisten, vCPUs and memory running at onceL03
Size of one Kiste (vCPU, memory, disk), smallest and largestL05
Number of custom imagesL06
Number of environmentsL15
Commands running at onceL16

Creating, forking, restoring, starting and resuming all count. A stopped Kiste counts toward the number of Kisten and the disk, not toward what is running.

When the platform itself has no free capacity for a Kiste of the requested size at the moment, the answer is 503 with L13 and Retry-After: 60; your limits are not the cause.

Per-feature limits

FeatureLimit
API keys10 active per account; lifetime 5 minutes to 1 year
Device keys (signed-in computers)50 per account
SSH connections32 open per account; closed after 1 hour without traffic
Desktop viewers4 per Kiste, 8 per account
Desktop linkslifetime 1 minute to 7 days, 1 hour by default
Published ports32 per Kiste; 64 open requests per port; WebSocket messages up to 16 MiB
Webhook endpoints10 per account, 32 event types each
Kiste lifetime (--ttl)60 seconds to 30 days
Checkpoint interval60 seconds to 1 day, 5 minutes by default
Console loglast 2,000 lines
Environments32 repositories, 256 variables, 64 secret files, 256 KiB setup script, 512 KiB manifest
Clipboard1 MiB of text per copy or paste

Request sizes

RequestLargest body
/v1 API requests64 KiB
Sign-in, OAuth, device keys, desktop sessions8 KiB

A larger body answers 413 with P03.

On this page