Limits
Hard Action Agent runtime limits, CMS-configured organization limits, and current enforcement gaps.
Limits
Action Agent limits come from three different places. A limit is not necessarily a plan setting, and a plan setting is not necessarily enforced by every write path.
| Source | Examples | Change mechanism |
|---|---|---|
| Hard runtime constants | Message validation, chat timeouts, trigger rate limit, Knowledge slice size, generated-artifact size | Application code and a release |
| CMS plan settings | Active-agent allowance, concurrent Agent runs, displayed organization storage limit | The CMS record for the organization's plan |
| Saved Agent configuration | Attached collections, enabled tools, selected MCP tools, trigger scope and schedule | Action Agent Studio |
Messages and model calls
| Surface | Current limit |
|---|---|
| Non-streaming REST message | Trims the message, rejects empty text, and allows at most 100,000 characters |
Hosted MCP send_action_agent_message | Uses the same schema: trimmed, non-empty, at most 100,000 characters |
REST SSE and SDK streamActionAgentChat | Currently bypass the shared message schema; do not rely on the same 100,000-character validation or 400 response |
| Action Agent Studio and channel-trigger ingress | Currently use separate input paths and do not receive the shared 100,000-character REST schema |
Validate streaming, Action Agent Studio, and trigger input in your own integration as well. A provider's context-window limit can still be smaller than any of these application limits.
Named HTTP and builtin HTTP calls use a default 30-second timeout, accept a value from 1 to 300 seconds, and reject a response body larger than 5 MiB. These are HTTP-tool limits, not chat-message limits.
Session and turn lifetime
A durable session is a stored conversation, not a permanently running process.
- Idle runtime: 10 minutes without a message. The chat worker suspends and resumes on a later message or preload.
- Maximum chat-run duration: 1 hour.
- Turn timeout: 10 minutes.
- Cold-start wait: a queued session waits up to 120 seconds for its Trigger chat binding before the send path reports
AGENT_SESSION_NOT_READY.
Suspending or timing out a worker does not delete the transcript. The current public REST, SDK, and hosted MCP Agent API still has no public close, list, or full-transcript operation. See Sessions & chat.
Active agents and concurrent runs
These are organization plan settings, not values stored on one Agent.
Active Agent allowance
product.agentLimit in the CMS limits active, non-template Agents. It is checked when an Agent changes from passive to active.
0: the plan cannot activate Agents.-1: unlimited.- Unset: the code falls back to 3 for Free/Beta/Hobby, 10 for Starter or an unrecognized plan name, 50 for Pro, and unlimited for Business/Enterprise or a plan name containing
business. A missing or invalid organization plan resolves to Free before this fallback.
Creating passive Agents is not limited by this value.
Concurrent Agent chat runs
run.concurrentAgentSessionLimit in the CMS limits in-flight Agent chat runs across the organization. It is not a limit on stored sessions or historical transcripts.
- Unset or
-1: unlimited. 0: no new Agent chat run can be admitted for the organization.- A positive value: a new run can start only while the current in-flight count is below the value.
- With the session queue enabled, excess starts wait in the queue. A
0limit never admits the queued item. Without the queue, a new start can fail withCONCURRENT_AGENT_SESSION_LIMIT.
The counter includes a short dispatch-visibility grace period so several near-simultaneous starts are not admitted past the plan value.
Trigger and API rate limits
All four Action Agent trigger ingress handlers share a distributed 10 requests per 10 seconds sliding-window limit. After the email query-ID check, the trigger limiter runs before signature verification and body parsing.
- Slack, Discord, and Teams requests are keyed by channel and client IP because platform events do not carry Agent query IDs.
- Email requests are keyed by channel,
actionAgentId, and client IP. - Email checks required query IDs before this trigger limiter. A missing
actionAgentIdororganizationIdreturns400without consuming a trigger-window slot.
The trigger router accepts raw request bodies up to 10 MB. A 429 can come from the 10-per-10-second trigger window or the API service's broader per-IP limiter.
Every API service request, including trigger ingress, also passes a shared per-IP limiter of 100 requests per 15 minutes outside the test environment. The test environment raises that IP limit to 50,000.
The authenticated Action Agents REST routes use a separate API limiter with the same 10-per-10-second numeric setting as the trigger limiter, but different keys for list, get, start, message, reconnect, and authenticated Action Agent Studio studio-messages operations. The Action Agent Studio message key includes organization, session, and authenticated user. Trigger ingress does not consume that route-limiter's keys.
Knowledge and tool results
search_knowledgereturns at most 8 hits per call.read_documentreturns at most 4,000 characters per call and returns the document's total extracted length.- A named HTTP tool can read at most a 5 MiB response body.
- There is no additional Agent-level lifetime cap on the number of Knowledge reads or tool calls. Model interaction is still bounded by the selected model mode's maximum step count, the provider context, tool behavior, and the 10-minute turn timeout.
Generated Agent artifacts
Each recognized generated file is limited to 25 MiB. Files over that size, empty payloads, unsupported shapes, unsafe remote URLs, and failed uploads are skipped without failing the chat turn.
The current Agent artifact path has no hard limit on the number of files per turn or the sum of their sizes. It processes each recognized candidate independently.
Storage settings are not write-time enforcement
The CMS also exposes data.storageLimit and data.maxFileSizeLimit. Do not treat them as universal storage enforcement:
data.storageLimitis currently summed with organization Artifact rows and displayed in Storage. The generic upload, Knowledge upload, and generated Agent/Flow artifact write paths do not reject writes when that total is exceeded.data.maxFileSizeLimitcurrently affects a specific ActionFlow file-input UI calculation. It is not enforced by the generic Artifact upload or generated Agent artifact path.- The 25 MiB generated-artifact and 5 MiB HTTP-response checks above are hard code-level checks and are independent of those CMS values.
Organization storage usage is a current visibility limit, not a current write-time quota. Monitor Storage and apply product-level upload controls until server enforcement is added.
Related
Artifacts
Generated Action Agent files, their recognition and size limits, storage paths, failure behavior, and separation from uploads and Flow artifacts.
Troubleshooting
Diagnose Action Agent activation, triggers, capabilities, sessions, streaming, and generated artifacts without exposing credentials.