Limits and quotas
Every limit AlphaAgent enforces, where you meet it and the message you see: for Studio users planning agents, knowledge graphs, connectors, environments and workflows, administrators sizing deployments, seats and API keys, and integrators calling the workflow API. Every number is read from the product for Studio 2.0.14 and Organisations 1.0.16; where your own AWS account decides a value (Amazon Bedrock quotas, service quotas), the row says so. Sizes in MiB and GiB are binary units (1 MiB is 1,048,576 bytes); Studio rounds them on screen, for example "50.0 MB" for the 50 MiB PDF cap.
Where to read a limit
Limits are enforced as you work: a field stops accepting input at its length, a disabled Create button carries the reason beside it, and a request over a byte cap is refused with a message that names the count.
- Field lengths: the counter under the field, for example
80 / 80. - Large text bodies: the byte counter under the field, for example
12.4 KB / 8.0 MB; over 8 MiB the block sentence shows both byte counts and Save stays disabled. - Per-user counts: the notice beside a disabled Create button reads "You've reached the limit of 256 agents." (the noun changes with the screen); in a governed deployment the create form shows the service's "Max 256 … per user reached." instead.
- Seats on a deployment: the seat line in Assign a role reads
{used} of {cap} users · room for N. - API keys: open the key in Programmatic Access and read Rate limit, Daily run quota and Concurrent runs; a call over a per-key limit answers 429 with a stable
codeand aRetry-After. - Uploads: a refused upload names the cap it hit; a zip is refused before anything is extracted.
Studio limits
How many things you can create
Each user can hold up to 256 of each resource type. The cap is enforced by the service and pre-checked by the list screens.
| Resource | Cap per user | Service message when refused |
|---|---|---|
| Agents | 256 | "Max 256 agents per user reached." |
| Knowledge graphs | 256 | "Max 256 knowledge bases per user reached." |
| Data connectors | 256 | Create is refused at the cap |
| Execution environments | 256 | "Max 256 environments per user reached." |
| Workflows | 256 | "Max 256 workflows per user reached." |
In a standard deployment the list shows only your own rows, so Studio disables Create in advance and shows the notice beside it. In a governed deployment the list shows everyone's rows, so the pre-check stands down; the cap still counts only what you created yourself, and the service's refusal is the authority.
Names, descriptions and other fields
| Item | Field | Limit |
|---|---|---|
| Agent | Name | 80 characters |
| Agent | Description | 1,000 characters |
| Knowledge graph | Name | 100 characters |
| Knowledge graph | Description | 500 characters |
| Data connector | Name | 80 characters |
| Data connector | Description | 1,000 characters |
| Execution environment | Name | 80 characters |
| Execution environment | Description | 500 characters |
| Workflow | Name | 80 characters |
| Workflow | Description | 1,000 characters |
| Workflow step | Handle | lowercase letters, digits and dashes; unique within the workflow |
| Workflow parameter | Name | ^[a-z][a-z0-9_]{0,63}$ |
| Workflow | Result schema (JSON Schema) | 32 KB |
| Conversation | Title | 200 characters |
| Snowflake connector | Account identifier | 1 to 63 characters: letters, digits, _, . and - |
Large text bodies
Four free-text bodies are capped in UTF-8 bytes, not characters, at 8 MiB: an agent's system prompt, a connector's guide, a pasted OpenAPI specification and a workflow's serialised definition. Studio measures the bytes as you type, disables Save over the cap and shows the block sentence, for example "System prompt is 8,388,609 bytes; the limit is 8,388,608 bytes (8 MiB)." A request that reaches the service over the cap is refused with HTTP 413 and a named error.
Above 50,000 characters a system prompt or connector guide still saves; Studio only shows an advisory that large text costs more per turn ("Large guides cost more per turn.").
Bodies over 350,000 bytes are kept in a bucket in your deployment's AWS account rather than in the table row and read back transparently.
Wiring an agent
| Limit | Value |
|---|---|
| Data connectors on one agent | 8 |
| Knowledge graphs on one agent | 1 (one graph, pinned to one Ready version) |
| Execution environments on one agent | 1 |
| Specialist activation | needs an environment: "An execution environment is required to activate." |
| Supervisor | takes no connector, knowledge graph or environment; works only inside Workflows |
Knowledge graphs
| Limit | Value |
|---|---|
| Source document per build | one PDF; "Only PDF files are supported." |
| Pages per PDF | 32; refused with "This PDF has N pages. Knowledge graphs accept PDFs of 32 pages or fewer." |
| Size per PDF | 50 MiB, shown as "50.0 MB"; refused with "This PDF is (size). Knowledge graphs accept PDFs of 50.0 MB or less." |
| Versions per graph | 50 |
| Builds at a time per graph | 1; a second build is refused with "This graph already has a version building" and asks you to cancel it or wait |
| Versions an agent can pin | Ready only |
The page count is checked in your browser before the upload starts and again by the service; the same sentence is recorded as the version's failure reason if the service is the one that refuses it. The field hint reads "One PDF of up to 32 pages and at most 50.0 MB."
Files and uploads
Files reach an agent through the Files tab of a conversation or run, never as attachments to a message. These caps apply to that tab.
| Limit | Value | Message |
|---|---|---|
| One uploaded file | 100 MB | "…100MB per file." |
| A zip you choose to Expand into this folder | at most 2,000 entries and 500 MB expanded, checked before anything is extracted | "zip has more than 2000 entries" or "zip expands to N MB; the limit is 500MB" |
| A zip you Upload as file | counts as one file (100 MB) | as above |
| Download selection (zip) of a folder or several items | at most 2,000 files and 500 MiB, decided from the listing before the first byte | "That selection has more than 2000 files; download less at a time." |
| Text and code in the inline viewer | first 500 KB shown | "File truncated (exceeds 500 KB preview limit)" |
A zip refusal is all-or-nothing: nothing from it lands. Uploads and new folders always land in the current conversation's folder, even when the explorer scope is All my files. In a governed deployment you can open and download every user's files under Everyone's files, but new files and changes go in your own folder only.
Execution environments
| Setting | Range | Default |
|---|---|---|
| Memory (MB) | 1,769 to 3,008 | 2,048 |
| vCPU | derived: 1 vCPU per 1,769 MB | 1.0 |
| Execution timeout (seconds) | 1 to 900 | 900 (15 minutes) |
| Max workspace storage (MB) | 512 to 3,008 | 512 |
| Custom image | compressed size up to 4 GiB, pushed to this deployment's environment repository | AlphaAgent Python (prebuilt) |
| Provisioning | 15 minutes; after that the environment shows Needs attention with the reason "Provisioning did not finish within 15 minutes" and Provision retries it |
The Memory field clamps to the range when you leave it. Environments carry no variables or secrets; connectors supply credentials.
Data connectors
| Limit | Value |
|---|---|
| Credential rows on a REST API or MCP Server connector | 12 |
| OpenAPI specification | 8 MiB; must pass Validate OpenAPI before Create is enabled |
| Snowflake query timeout | 1 to 60 seconds per statement (default 60); a statement that runs past it is cancelled and reported as "Query exceeded 60 s and was cancelled" |
| Snowflake rows returned per statement | 1,000 |
| Snowflake key-pair token | signed by the platform; each token is valid for 59 minutes |
| AWS connector role session | 900 to 43,200 seconds (default 3,600), capped by the role's own maximum session duration |
Every save of a connector creates a new immutable version; agents and workflows pin to a version, so older versions stay alive until nothing uses them.
Workflows
| Limit | Value | Where you see it |
|---|---|---|
| Steps per workflow | 20 | palette disabled with "This workflow has the maximum of 20 steps."; validation "At most 20 steps; this workflow has N." |
| Step types | Task, Handoff, Conditional, AMPG update (knowledge graph), Redact PII | palette rail |
| Conditional | at least two outgoing branches, each labelled | "A decision needs at least two outgoing branches." |
| Parallelism | 1 to 10 steps at the same time (default 3) | Workflow settings |
| Time limit | Off by default; when on, 0.25 to 168 hours in steps of 0.25 (presets 1 h, 4 h, 24 h, 72 h); counts time spent waiting for your approvals | Workflow settings |
| Workflow definition | 8 MiB | validation bar |
| S3 prefix parameter: max objects | default 500, at most 5,000 | Parameters |
| S3 prefix parameter: max bytes | default 2 GiB, at most 20 GiB | Parameters |
| Result schema | 32 KB | Parameters |
| PII redaction: minimum confidence | 0.5 to 1 in steps of 0.05 (default 0.8) | PII redaction |
| PII redaction: Opus calls per run | 0 to 100,000 (default 200) | PII redaction |
| PII redaction: parquet sample rows | 50,000 | policy default |
| Run data retention | 1 to 3,650 days, default 90; set per deployment by your administrator | Organisations console, deployment Overview |
Every save of a workflow creates a new version; Run Now and schedules use the active version.
Chat
The composer has no message-length cap. A conversation runs one turn at a time: a message you send while a run is live is queued and read at the coordinator's next update, and the pill "N waiting to be read" counts them. Runs are detached: closing the tab does not stop them; Stop does.
Organisations limits
Users and seats
| Limit | Value |
|---|---|
| Users who can sign in to one Studio deployment | 20 by default (ORG_MAX_USERS_PER_DEPLOYMENT) |
| What counts as a seat | a StudioUser grant on that deployment, directly or through a group's members |
| When a grant does not fit | Assign is disabled with "Only N more users fit in this deployment (20 max)" or "No more users fit in this deployment (20 max)"; the server refuses with deployment_user_cap |
| When a group grows after it was assigned | the Identity view shows "a group grew after it was assigned. Remove users to return under the cap." |
Names and fields in the console
| Item | Field | Limit |
|---|---|---|
| Deployment | Deployment name | 200 characters |
| Deployment | Cognito domain prefix | 63 characters (auto-generated) |
| Deployment | Studio app domain | 253 characters |
| AWS account | Alias | 64 characters |
| AWS account | AWS Account ID | exactly 12 digits |
| AWS account | Region | one of the 11 supported regions: us-east-1, us-east-2, us-west-2, eu-west-1, eu-west-2, eu-west-3, eu-central-1, eu-central-2, eu-north-1, eu-south-1, eu-south-2 |
| Library | Name | 100 characters |
| Library | Description | 500 characters |
| Fleet Configuration Template | Name | 100 characters |
| Fleet Configuration Template | Description | 500 characters |
| Update Manager rule | Name | 100 characters |
| Update Manager rule | Day of month (monthly schedule) | 1 to 28 |
Deployment sizing choices
| Setting | Choices | Blank means |
|---|---|---|
| Fargate sizing profile | xs, small, standard, large, xlarge | Automatic (standard) |
| ElastiCache node type | cache.t4g.medium, cache.m7g.large, cache.r7g.large, cache.r7g.xlarge, or any value shaped cache.<family>.<size> | cache.t4g.medium |
| Bedrock inference zone | us, eu; must match the account's region | set from the account you pick |
| Run data retention (days) | 1 to 3,650 | 90 |
API keys
Every value is per key and set by an administrator in Programmatic Access; the defaults apply when the field is left as it is.
| Limit | Default | Maximum |
|---|---|---|
| Rate limit (requests per minute) | 60 | 10,000 |
| Daily run quota | 100 | 100,000 |
| Concurrent runs | 10 | 100 |
| Expiry | 90 days | 365 days (choices 30, 90, 180, 365) |
| Old secret kept working after Rotate | 24 hours | 7 days (choices 1 hour, 24 hours, 3 days, 7 days) |
| Workflows named on one key | 50 | |
| Source IP allow-list entries | 32 CIDRs | |
| Name | 100 characters | |
| Description | 500 characters |
A new key becomes active in its deployment within about a minute; a revoked key stops working within two minutes; a new key external id has no overlap. Per-request usage detail (method, path, status, IP, reason) is kept in the deployment for 90 days.
Audit
| Limit | Value |
|---|---|
| Retention | 400 days |
| One query window | fewer than 90 days |
| Rows per page | 50 shown; the server accepts up to 200 |
API limits
These apply to the workflow API on a governed deployment. Every 429 and 503 carries a Retry-After header; honour it, and poll GET /runs/{run_id} no more than every 5 seconds.
| Limit | Value | Response when exceeded |
|---|---|---|
| Requests per minute, per key | 60 by default | 429 rate_limited, Retry-After = seconds to the next minute |
| Runs per day, per key (resets 00:00 UTC) | 100 by default | 429 quota_exceeded, Retry-After = seconds to the next UTC day |
| Runs in flight, per key | 10 by default | 429 too_many_active_runs, Retry-After: 5; does not consume a daily-quota unit |
Idempotency-Key replay window | 24 hours | 409 idempotency_conflict while the first request is still processing |
limit on list endpoints | 100 for workflows and runs, 500 for events | |
| Request body, every API route | 1 MiB (1,048,576 bytes) | 413 payload_too_large, before the body is read |
| One output's content | 25 MiB | 413 use_bundle |
outputs.zip bundle | 500 MiB and 2,000 objects | 413 bundle_too_large |
result.json | 256 KiB | |
| Not governed, or no key mirrored yet | 503 deployment_updating, Retry-After: 60 |
The defaults are the key's own values; an administrator can raise them up to the maxima in the API keys table above. The full error catalogue is on Limits, errors and codes and Failure codes.
Amazon Bedrock quotas
Model inference runs on Amazon Bedrock inside the AWS account that hosts each Studio deployment, and Bedrock's token quotas are set per AWS account and per region. AlphaAgent cannot raise them, and nothing in the Organisations install or the deployment preflight checks them: the only quota check the install runs is the advisory quota-headroom preflight for Elastic IPs, VPCs and NAT gateways. Raise Bedrock quotas with AWS for the account and region of each deployment. For why every deployment gets its own account, read the admonition at the top of Before you start.
When Bedrock throttles a run, Studio shows one banner with three states: Slowed, Refused and Daily quota exhausted. What each state says, what happened to the run and what to do are on Banners you may see and Troubleshooting. The models a deployment uses by role are listed on Supported models.
Notes
- What to do when you hit a limit (the 256 cap, a refused PDF or upload, the seat cap, an API 429, a throttle banner) is answered on FAQ; every row in a list has Delete, and an administrator raises a key's limits with Edit on the key.
- The seat cap is
ORG_MAX_USERS_PER_DEPLOYMENT, set when the Organisation is configured; ask for a higher value there. - Every number on this page is read from Studio 2.0.14 and Organisations 1.0.16; sizes in MiB and GiB are binary units (1 MiB is 1,048,576 bytes), which Studio rounds on screen, for example 50.0 MB for the 50 MiB PDF cap.
Related
- Banners you may see
- Knowledge graphs: build a version
- Chat: files, previews and approvals
- Execution environments
- Workflows: build
- Working in a governed deployment
- Users, groups and roles
- Programmatic access
- Limits, errors and codes
- Infrastructure sizing and costs
- Failure codes
- FAQ
- Troubleshooting
- Glossary