Limits and rate limits
Request rate limits, body and document sizes, search pages, webhook limits and token lifetimes.
| Limit | Value | Notes |
|---|---|---|
| Requests per credential | 600 / minute (per key; configurable per key) | shared across all instances; Retry-After on 429 |
| Requests per IP | 600 / minute | per instance |
| JSON body | 2 MiB | refused from Content-Length before reading |
| Document upload | 25 MiB | direct-to-storage or through the platform |
| Resource nesting | 64 levels | |
| Text field length | 10 000 characters | |
| Search page | _count ≤ 200 |
_revinclude returns at most 1 000 |
| Webhook endpoints | 10 per project and environment | |
| Webhook attempts | 10 with exponential backoff (30 s → 1 h) | endpoint auto-disabled after 10 consecutive failures |
| Idempotency keys | 128 characters, kept 24 h | |
| Access token / refresh token / auth code | 30 min / 30 days / 10 min | |
| Consent duration | 30, 90, 180 or 365 days |
Sandbox (self-service)
| Limit | Value | Notes |
|---|---|---|
| Resource writes | 10 000 per project per day (UTC) | every created, updated or deleted resource counts (a bundle of 200 entries is 200); 429 with Retry-After until midnight UTC; the synthetic patients and their reset do not count |
| Patients | 500 per project, besides its 30 synthetic patients | |
| Documents | 250 MB per project | |
| Organisations | 3 created per account | |
| Sandbox projects | 5 per organisation | |
| API keys | 20 active per project |
Production projects have none of the sandbox limits; they are open to verified organisations with a signed data processing agreement, and their allowances come from the plan: see Pricing. The sandbox is free, and the first month of production is free.