# Limits

> Every ZeroCaptcha limit in one place: request sizes and timeouts, field lengths, task deadlines, token lifetimes, budgets, keys, callbacks and retention.

Source: https://zerocaptcha.io/docs/reference/limits

Every limit the API applies, in one place. Values marked "by default" are the service's settings,
which can change: the `RateLimit-Policy` header and each task's own fields (`deadline`,
`maxAttempts`, `tokenExpiresAt`) always say what applies to you.

## Requests

| Limit | Value |
| --- | --- |
| Request body | 64 KiB by default; larger is [`payload_too_large`](https://zerocaptcha.io/docs/reference/errors#payload_too_large) (413) |
| Server time per request | 10 seconds by default; longer is [`request_timeout`](https://zerocaptcha.io/docs/reference/errors#request_timeout) (504) |
| `Idempotency-Key` | 1 to 255 visible ASCII characters; kept for 24 hours |
| Tasks per list page | 1 to 100; 50 by default |

## Task fields

| Field | Limit |
| --- | --- |
| `websiteURL` | `http` or `https`, at most 2,048 characters, no credentials, the scheme's default port, a public domain name |
| `websiteKey` | 1 to 100 letters, digits, `_` and `-` |
| `action` | Up to 32 letters, digits, `_` and `-` |
| `cdata` | Up to 255 letters, digits, `_` and `-` |
| `proxy` | `http` or `https` with a port; a public host; not a port another protocol reserves; login and password at most 255 bytes each; host name at most 253 characters |
| `callbackUrl` | `http` or `https`, at most 2,048 characters, no credentials, a public domain or IP address, not a port another protocol reserves |

## Tasks

| Limit | Value |
| --- | --- |
| Deadline | 150 seconds after creation by default (the task's `deadline`) |
| Solve attempts | 3 by default (the task's `maxAttempts`); none started with under 5 seconds left |
| Tasks queued or running per account | 50 by default, beyond which `queue_full` (429, `Retry-After: 2`) |
| Tasks queued across the service | 5,000, beyond which `queue_full` |
| Creation rate | No budget by default: your balance and queue share bound it |
| Turnstile token | Valid once, for 300 seconds from `tokenIssuedAt` |
| Challenge clearance | Served for 30 minutes from `tokenIssuedAt`; the site's own setting decides how long it accepts it |
| Tokens and clearances deleted | 10 minutes after they expire |
| Proxy credentials deleted | When the task finishes |
| Task records kept | About 90 days: deleted a month at a time, once their month ended more than 90 days ago |

## Reads

| Budget | Value |
| --- | --- |
| Reads per key | 200 every 2 seconds by default |
| Reads per account | 200 every 2 seconds by default, all keys together |
| Live-update streams per account | 10 at once by default |
| `GET /v1/prices` and `GET /v1/status` | 60 a minute per client address by default |

Over a budget: [`rate_limited`](https://zerocaptcha.io/docs/reference/errors#rate_limited) (429) with `Retry-After`;
`ERROR_RATE_LIMIT` in the createTask format; `ERROR: 1005` in 2Captcha's.

## Keys and accounts

| Limit | Value |
| --- | --- |
| Active API keys per account | 20; a key being replaced by a rotation, and a revoked key, do not count |
| Allowed addresses per key | 100 IP addresses or CIDR networks |
| Rotation overlap | 1 hour, 24 hours or 7 days |
| Daily spend cap | Any amount in whole cents, per key, per UTC day; none by default |
| Open team invitations | 20 per account; each link works once, for 7 days |
| Passkeys | 20 per person |
| Recovery codes | 10, each once |
| Dashboard session | 24 hours idle, 30 days at most |
| Recent sign-in, for sensitive changes | 10 minutes |
| Password | At least 8 characters |

## Money

| Limit | Value |
| --- | --- |
| Smallest top-up | $10 |
| Largest top-up | No maximum |
| Amounts | US dollars; top-ups in whole cents, balances and prices to six decimals |
| Refunds | None: top-ups are final |

## Callbacks

| Limit | Value |
| --- | --- |
| Time to answer | 10 seconds per attempt |
| Attempts | 8, from 30 seconds apart doubling to 32 minutes apart, each wait lengthened by up to half at random |
| Signature tolerance | 5 minutes between `t` and your clock |
