> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Rate limits and quotas

> Request budgets per minute, sign-in limits, account limits on Kisten, disk and running Kisten, and every per-feature limit.

## Rate limits

Requests to kiste.run are counted per minute. A request over a budget gets
`429 Too Many Requests` with a `Retry-After` header and error
[L01](https://docs.kiste.run/errors/l.md#l01) (or [A03](https://docs.kiste.run/errors/a.md#a03) for sign-in). The CLI waits and
tells you how long.

| Budget | Counted per | Limit |
| --- | --- | --- |
| All API requests | network address (IPv6: per /64) | 600 per minute |
| All requests of an account | account | 600 per minute |
| Changes of an account (POST, PUT, PATCH, DELETE) | account | 120 per minute |
| Sign-in, OAuth and token endpoints | network address | 30 per minute, and at most 20 within 10 seconds |
| Password sign-in | network address and e-mail address | 10 per 15 minutes |
| Password sign-in, any e-mail address | network address | 30 per 15 minutes |
| CLI token exchange | network address | 10 per 15 minutes |
| Billing actions that reach the payment provider | account | 20 per minute |
| Desktop sessions | account | 120 per 15 minutes |
| Live usage samples (`status --usage`, metrics) | account | 40 per minute |
| Webhook changes and test deliveries | account | 20 per minute |
| Each published port on Kiste Stream | port, all visitors together | 1,200 per minute |

Downloads of the CLI and the installers are not limited beyond Cloudflare's
protection against attacks. Long-running requests such as
`kiste exec` have no deadline of their own beyond your client's.

## Account limits

Every account has limits on what it can hold and run. `kiste limits` shows yours
and what is in use:

```bash
kiste limits
```

| Limit | Error when reached |
| --- | --- |
| Number of Kisten | [L02](https://docs.kiste.run/errors/l.md#l02) |
| Disk of all Kisten and snapshots together | [L04](https://docs.kiste.run/errors/l.md#l04) |
| Kisten, vCPUs and memory running at once | [L03](https://docs.kiste.run/errors/l.md#l03) |
| Size of one Kiste (vCPU, memory, disk), smallest and largest | [L05](https://docs.kiste.run/errors/l.md#l05) |
| Number of custom images | [L06](https://docs.kiste.run/errors/l.md#l06) |
| Number of environments | [L15](https://docs.kiste.run/errors/l.md#l15) |
| Commands running at once | [L16](https://docs.kiste.run/errors/l.md#l16) |

Creating, forking, restoring, starting and resuming all count. A stopped Kiste
counts toward the number of Kisten and the disk, not toward what is running.

When the platform itself has no free capacity for a Kiste of the requested size
at the moment, the answer is `503` with [L13](https://docs.kiste.run/errors/l.md#l13) and
`Retry-After: 60`; your limits are not the cause.

## Per-feature limits

| Feature | Limit |
| --- | --- |
| API keys | 10 active per account; lifetime 5 minutes to 1 year |
| Device keys (signed-in computers) | 50 per account |
| SSH connections | 32 open per account; closed after 1 hour without traffic |
| Desktop viewers | 4 per Kiste, 8 per account |
| Desktop links | lifetime 1 minute to 7 days, 1 hour by default |
| Published ports | 32 per Kiste; 64 open requests per port; WebSocket messages up to 16 MiB |
| Webhook endpoints | 10 per account, 32 event types each |
| Kiste lifetime (`--ttl`) | 60 seconds to 30 days |
| Checkpoint interval | 60 seconds to 1 day, 5 minutes by default |
| Console log | last 2,000 lines |
| Environments | 32 repositories, 256 variables, 64 secret files, 256 KiB setup script, 512 KiB manifest |
| Clipboard | 1 MiB of text per copy or paste |

## Request sizes

| Request | Largest body |
| --- | --- |
| `/v1` API requests | 64 KiB |
| Sign-in, OAuth, device keys, desktop sessions | 8 KiB |

A larger body answers `413` with [P03](https://docs.kiste.run/errors/p.md#p03).

## Related topics

- Previous: [P: Platform](https://docs.kiste.run/errors/p.md)
- Next: [Security and trust](https://docs.kiste.run/security.md)
