Rate limits and quotas
Request budgets per minute, sign-in limits, account limits on Kisten, disk and running Kisten, and every per-feature limit.
Rate limits
Requests to kiste.run are counted per minute. A request over a budget gets
429 Too Many Requests with a Retry-After header and error
L01 (or A03 for sign-in). The CLI waits and
tells you how long.
| Budget | Counted per | Limit |
|---|---|---|
| All API requests | network address (IPv6: per /64) | 600 per minute |
| All requests of an account | account | 600 per minute |
| Changes of an account (POST, PUT, PATCH, DELETE) | account | 120 per minute |
| Sign-in, OAuth and token endpoints | network address | 30 per minute, and at most 20 within 10 seconds |
| Password sign-in | network address and e-mail address | 10 per 15 minutes |
| Password sign-in, any e-mail address | network address | 30 per 15 minutes |
| CLI token exchange | network address | 10 per 15 minutes |
| Billing actions that reach the payment provider | account | 20 per minute |
| Desktop sessions | account | 120 per 15 minutes |
Live usage samples (status --usage, metrics) | account | 40 per minute |
| Webhook changes and test deliveries | account | 20 per minute |
| Each published port on Kiste Stream | port, all visitors together | 1,200 per minute |
Downloads of the CLI and the installers are not limited beyond Cloudflare's
protection against attacks. Long-running requests such as
kiste exec have no deadline of their own beyond your client's.
Account limits
Every account has limits on what it can hold and run. kiste limits shows yours
and what is in use:
| Limit | Error when reached |
|---|---|
| Number of Kisten | L02 |
| Disk of all Kisten and snapshots together | L04 |
| Kisten, vCPUs and memory running at once | L03 |
| Size of one Kiste (vCPU, memory, disk), smallest and largest | L05 |
| Number of custom images | L06 |
| Number of environments | L15 |
| Commands running at once | L16 |
Creating, forking, restoring, starting and resuming all count. A stopped Kiste counts toward the number of Kisten and the disk, not toward what is running.
When the platform itself has no free capacity for a Kiste of the requested size
at the moment, the answer is 503 with L13 and
Retry-After: 60; your limits are not the cause.
Per-feature limits
| Feature | Limit |
|---|---|
| API keys | 10 active per account; lifetime 5 minutes to 1 year |
| Device keys (signed-in computers) | 50 per account |
| SSH connections | 32 open per account; closed after 1 hour without traffic |
| Desktop viewers | 4 per Kiste, 8 per account |
| Desktop links | lifetime 1 minute to 7 days, 1 hour by default |
| Published ports | 32 per Kiste; 64 open requests per port; WebSocket messages up to 16 MiB |
| Webhook endpoints | 10 per account, 32 event types each |
Kiste lifetime (--ttl) | 60 seconds to 30 days |
| Checkpoint interval | 60 seconds to 1 day, 5 minutes by default |
| Console log | last 2,000 lines |
| Environments | 32 repositories, 256 variables, 64 secret files, 256 KiB setup script, 512 KiB manifest |
| Clipboard | 1 MiB of text per copy or paste |
Request sizes
| Request | Largest body |
|---|---|
/v1 API requests | 64 KiB |
| Sign-in, OAuth, device keys, desktop sessions | 8 KiB |
A larger body answers 413 with P03.