ArtieHelp center
Developers · 3 min read

Security, usage and billing

Protect credentials, isolate workspace access and understand usage and rate limits.

OAuth credentials identify the member, client and environment; Artie derives workspace authority on the server. Keep credentials out of logs and use observed usage and throttle responses to manage your integration.

On this page

Overview

artie usage --json

Usage exposes role-authorized cached member billing availability. It is not a live provider quota, an operational supplier-cost ledger, a final invoice, or evidence that the next provider call will succeed. Production paid work follows the current billing policy. Stop/pause/cancel, usage and export do not depend on a wallet balance.

Every surface retains tenant, member, object and audience permissions. Knowing an object UUID is not authorization. Artifact reads bind the artifact to the named permitted task; an unrelated readable task does not unlock the artifact. A revoked grant or ended membership is rechecked. Private context is not made public by connecting an assistant host.

System/provider secrets, authentication tokens, cookies and hidden model reasoning must stay out of logs, receipts, examples and support messages. Keep credential values out of diagnostic errors and logs. Use source revision, request ID, stage, error code and bounded nonprivate facts for diagnostics. Your own information that you deliberately choose to save or send may remain in its canonical saved work and save receipts, even if it looks like a password or key; your authority and chosen audience still apply. Someone else's private data remains with its owner.

Request and response limits

ContractLimit or behavior
JSON request body≤1,048,576 bytes, application/json, ≤30-second body read; one MCP request per HTTP body
Ordinary mutation keys8–128 characters
Message/task instructions/answer/refine≤100,000 characters, trimmed nonempty
Task title / acceptancetitle ≤240; ≤20 acceptance items, each ≤1,000
Selected refs≤20 uploads/files, ≤8 sources, ≤28 total, no duplicate identity
Task source resolved filesUp to 30 returned file facts; describes current instruction revision/message, not historical inputs
Artisans / tasksdefault 25, max 50 rows per page
Search1–6 selected kinds; default/max 20 results; previews, coverage, hasMore, partial; no cursor field
Run historydefault 5, max 25
Result collectionseach default/max 20; text default 12k / max 24k chars; independent text/file/artifact/effect/email cursors
Task detail children/resultsresultRuns and relatedTasks each ≤25 with independent cursors
Files list / memory linesfiles ≤25, no limit input; memory ≤50, no limit input
Versioned contentoffset default 0; maxChars default 12k, max 24k; sourceVersion 64 lowercase hex
Email bodymaxChars ≤24k; nextOffset, totalChars, optional sourceVersion ≤256; associated archived email only
Inline uploaddecoded bytes ≤262,144; encoded content schema max 349,528 chars; UTF-8/base64 explicit
Raw staged upload≤10 MiB, key 8–128, metadata header ≤4,096 chars, 30-second read
Stored-file content / CLI downloadstored files ≤100 MiB; CLI download cap 100 MiB; published or supplied digest verified
Artifact inline text≤10 MiB original; use original authenticated download above bound
Image display1–4 normalized PNG/JPEG parts; each dimension ≤2,000 px; each part ≤3,750,000 bytes; separate original/part digests
CLI local text input≤1 MiB bytes before schema character limits
CLI JSON responsedefault cap 4 MiB; separate original-byte downloads
CLI result --all≤100 pages / ≤2.4 million text chars, can remain incomplete
Watch0–86,400 seconds; polling starts ~1 second, grows to 10 seconds plus jitter; retries read 429/503 within deadline

Read and control buckets each allow 600 requests per workspace per minute and 240 per grant. Write buckets allow 120 per workspace and 60 per grant per minute. These are separate buckets. Honor HTTP 429 Retry-After; do not load-test shared production limits.

Need help with your workspace?

Contact support