Skip to main content

Limits

Hard Action Agent runtime limits, CMS-configured organization limits, and current enforcement gaps.

Limits

Action Agent limits come from three different places. A limit is not necessarily a plan setting, and a plan setting is not necessarily enforced by every write path.

SourceExamplesChange mechanism
Hard runtime constantsMessage validation, chat timeouts, trigger rate limit, Knowledge slice size, generated-artifact sizeApplication code and a release
CMS plan settingsActive-agent allowance, concurrent Agent runs, displayed organization storage limitThe CMS record for the organization's plan
Saved Agent configurationAttached collections, enabled tools, selected MCP tools, trigger scope and scheduleAction Agent Studio

Messages and model calls

SurfaceCurrent limit
Non-streaming REST messageTrims the message, rejects empty text, and allows at most 100,000 characters
Hosted MCP send_action_agent_messageUses the same schema: trimmed, non-empty, at most 100,000 characters
REST SSE and SDK streamActionAgentChatCurrently bypass the shared message schema; do not rely on the same 100,000-character validation or 400 response
Action Agent Studio and channel-trigger ingressCurrently use separate input paths and do not receive the shared 100,000-character REST schema

Validate streaming, Action Agent Studio, and trigger input in your own integration as well. A provider's context-window limit can still be smaller than any of these application limits.

Named HTTP and builtin HTTP calls use a default 30-second timeout, accept a value from 1 to 300 seconds, and reject a response body larger than 5 MiB. These are HTTP-tool limits, not chat-message limits.

Session and turn lifetime

A durable session is a stored conversation, not a permanently running process.

  • Idle runtime: 10 minutes without a message. The chat worker suspends and resumes on a later message or preload.
  • Maximum chat-run duration: 1 hour.
  • Turn timeout: 10 minutes.
  • Cold-start wait: a queued session waits up to 120 seconds for its Trigger chat binding before the send path reports AGENT_SESSION_NOT_READY.

Suspending or timing out a worker does not delete the transcript. The current public REST, SDK, and hosted MCP Agent API still has no public close, list, or full-transcript operation. See Sessions & chat.

Active agents and concurrent runs

These are organization plan settings, not values stored on one Agent.

Active Agent allowance

product.agentLimit in the CMS limits active, non-template Agents. It is checked when an Agent changes from passive to active.

  • 0: the plan cannot activate Agents.
  • -1: unlimited.
  • Unset: the code falls back to 3 for Free/Beta/Hobby, 10 for Starter or an unrecognized plan name, 50 for Pro, and unlimited for Business/Enterprise or a plan name containing business. A missing or invalid organization plan resolves to Free before this fallback.

Creating passive Agents is not limited by this value.

Concurrent Agent chat runs

run.concurrentAgentSessionLimit in the CMS limits in-flight Agent chat runs across the organization. It is not a limit on stored sessions or historical transcripts.

  • Unset or -1: unlimited.
  • 0: no new Agent chat run can be admitted for the organization.
  • A positive value: a new run can start only while the current in-flight count is below the value.
  • With the session queue enabled, excess starts wait in the queue. A 0 limit never admits the queued item. Without the queue, a new start can fail with CONCURRENT_AGENT_SESSION_LIMIT.

The counter includes a short dispatch-visibility grace period so several near-simultaneous starts are not admitted past the plan value.

Trigger and API rate limits

All four Action Agent trigger ingress handlers share a distributed 10 requests per 10 seconds sliding-window limit. After the email query-ID check, the trigger limiter runs before signature verification and body parsing.

  • Slack, Discord, and Teams requests are keyed by channel and client IP because platform events do not carry Agent query IDs.
  • Email requests are keyed by channel, actionAgentId, and client IP.
  • Email checks required query IDs before this trigger limiter. A missing actionAgentId or organizationId returns 400 without consuming a trigger-window slot.

The trigger router accepts raw request bodies up to 10 MB. A 429 can come from the 10-per-10-second trigger window or the API service's broader per-IP limiter.

Every API service request, including trigger ingress, also passes a shared per-IP limiter of 100 requests per 15 minutes outside the test environment. The test environment raises that IP limit to 50,000.

The authenticated Action Agents REST routes use a separate API limiter with the same 10-per-10-second numeric setting as the trigger limiter, but different keys for list, get, start, message, reconnect, and authenticated Action Agent Studio studio-messages operations. The Action Agent Studio message key includes organization, session, and authenticated user. Trigger ingress does not consume that route-limiter's keys.

Knowledge and tool results

  • search_knowledge returns at most 8 hits per call.
  • read_document returns at most 4,000 characters per call and returns the document's total extracted length.
  • A named HTTP tool can read at most a 5 MiB response body.
  • There is no additional Agent-level lifetime cap on the number of Knowledge reads or tool calls. Model interaction is still bounded by the selected model mode's maximum step count, the provider context, tool behavior, and the 10-minute turn timeout.

Generated Agent artifacts

Each recognized generated file is limited to 25 MiB. Files over that size, empty payloads, unsupported shapes, unsafe remote URLs, and failed uploads are skipped without failing the chat turn.

The current Agent artifact path has no hard limit on the number of files per turn or the sum of their sizes. It processes each recognized candidate independently.

Storage settings are not write-time enforcement

The CMS also exposes data.storageLimit and data.maxFileSizeLimit. Do not treat them as universal storage enforcement:

  • data.storageLimit is currently summed with organization Artifact rows and displayed in Storage. The generic upload, Knowledge upload, and generated Agent/Flow artifact write paths do not reject writes when that total is exceeded.
  • data.maxFileSizeLimit currently affects a specific ActionFlow file-input UI calculation. It is not enforced by the generic Artifact upload or generated Agent artifact path.
  • The 25 MiB generated-artifact and 5 MiB HTTP-response checks above are hard code-level checks and are independent of those CMS values.

Organization storage usage is a current visibility limit, not a current write-time quota. Monitor Storage and apply product-level upload controls until server enforcement is added.

On this page