Skip to content
pols.so docs
Esc
↑↓navigate↵open⌘Jpreview
On this page

Limits and quotas

The quotas every org starts with, the API's rate limits, and the size limits of commands, files and computer-use actions.

pols applies three kinds of limits: quotas per org, which decide how many sandboxes, hours, templates and keys you may use; rate limits, which protect the shared control plane; and size limits on individual calls. pols org shows your quotas and current use at any time.

Quotas

New orgs start with these quotas. If you need more, write to us and we raise them for your org.

Quota Default What counts
Running sandboxes 5 sandboxes that run or are starting
Sandboxes 20 sandboxes that exist, running or stopped
Sandbox-hours per month 500 running time in the calendar month (UTC), summed over all sandboxes
Templates 10 your org’s own templates; the system template does not count
API keys 25 keys that are neither revoked nor expired

Quotas are checked when you create, fork or resume a sandbox, save a template or create an API key. A call over a quota fails with quota_exceeded; stop or delete something, or pick a smaller size, and try again. The same error also means the host has no room for the size you asked for right now.

The monthly hours are a hard limit

Sandbox-hours count every running second of every sandbox, whatever its size. At 80 percent of the monthly hours, the org’s users get an email. At 100 percent, pols stops the org’s running sandboxes. Their disks are kept, and you can resume them when the next month starts or after your quota was raised.

Rate limits

The API currently allows:

Limit Rate Burst
Requests per client address 50 per second 100
Requests per org 20 per second 40
Lifecycle calls per org (create, fork, stop, resume, delete, save template) 1 per second 10
Failed authentications per client address 1 every 5 seconds 20
Exec, file, computer-use and CDP calls in progress per org 16 at once

Over a limit, the API answers 429 with the error code rate_limited and a Retry-After header that says how many seconds to wait. The CLI and the TypeScript client report the error; retry after the given time and run fewer calls in parallel. A request body that stalls for 30 seconds is answered with 408 and the code timeout.

Commands, files and the desktop

What Limit
Command timeout (pols exec --timeout, timeout_seconds) 600 seconds by default, at most 86,400 (24 hours)
Output of a non-streamed command (API ExecResult) 4 MiB per stream; stream larger output
Output of sandbox_exec over MCP 512 KiB per stream
Standard input with pols exec --stdin 768 KiB
File upload (pols cp, PUT .../files) 1 GiB per file
File read over MCP (file_read) 1 MiB
Text typed by one computer-use action 10,000 characters
Scroll amount of one computer-use action 1 to 50 wheel clicks
Vault 100 entries of up to 32 KiB each
Secrets named on one sandbox 100
Allowlist entries of an egress policy 64 CIDR prefixes
Link Valid for
Login link for a private port open within 5 minutes; the browser session then lasts 12 hours
Desktop link 12 hours, while the sandbox keeps running
Browser (CDP) URL connect within 5 minutes
SSH certificate the gateway uses inside the sandbox 2 minutes per login
Website login link 15 minutes, once
Website session 7 days

Port sessions, desktop links and CDP URLs stop working when the API key that created them is revoked. A CDP connection that is already open is not cut when its URL expires.