| New user API token | No expiry; valid until revoked; full value shown once. |
| Existing user token | Keeps its recorded expiry. |
| Saved logins on one computer | At most 64. profile_limit_reached saves no new login: remove one with ohmyhost logout --profile-name NAME --json, then log in again. |
| Database query | Explicit Dev/Prod; one read-only statement, 4 KiB SQL, 32 scalar parameters, 100 rows and five seconds. |
| Database write | Explicit Dev/Prod; one INSERT/UPDATE/DELETE/upsert, 64 KiB SQL, up to 100 JSON parameters, 1,000 directly affected rows and five seconds. |
| Application database call | One statement per call: 64 KiB SQL, 100 parameters and 1 MiB total parameter data; each JSON parameter at most 64 KiB. transaction([...]) takes up to 25 statements; results at most 1,000 rows, 1 MiB and 10,000 values. SQL statements time out after ten seconds. |
| Held application database connection | Two transaction/auth connections per physical data area; 100 statements, 30 seconds total and five seconds idle. Shared Dev/Prod use the same pool. |
| Direct database login | read or confirmed write; five minutes to 24 hours, one hour by default; at most three active per project environment. Connection URI returned once. |
| Write retry | Keep the original idempotency key; an existing receipt observes one attempt, and unknown outcomes must be inspected before any deliberately new write. |
| Deployment plan | Valid 24 hours; after deployment_plan_expired, plan again. |
| Promotion, rollback, deletion and data-change plans | Confirmation valid ten minutes; use the plan’s ETag and token. An expired or invalid confirmation needs a fresh plan. |
| Project context | At most 500 lines / 32 KiB. |
| Saved project notes | At most 250 lines / 16 KiB. |
| SQL export | One accepted request per project per rolling 24 hours; 256 MiB plaintext maximum. |
| Export download | Signed URL valid 24 hours; encrypted ZIP retained seven days. A new link requires at least 24 hours of remaining retention: download within the first six days. |
| Protected Dev access | One persistent owner-managed share link without automatic expiry; each opening starts a browser session of at most 12 hours. Rotation or revocation blocks old links and sessions on their next request. Public Dev needs no link. |
| Request and scheduled run | At most 50 ms CPU and ten subrequests per customer invocation; network waiting is not CPU time. Excess CPU answers 429 Runtime limit exceeded; a scheduled attempt may last 120 seconds. |
| Browser policy and media | Declare only required browser origins and capabilities in runtime.browser; server egress is separate. Defaults, CORS, nonces, media and microphone opt-in are explained in Browser security. |
| Standard database compute | Free 0.25 CU / 1 GB / 60 s; Paid 0.5 CU / 2 GB / 60 s. |
| Performance database compute | Paid 1 CU / 4 GB / 300 s; 2.5× compute credits per equal active duration. |
Outbound fetch | At most 13 exact HTTPS origins in runtime.egress.allow, without paths, trailing slash, ports, credentials, IP literals or local hosts. Unlisted origins answer 403 Egress denied. Redirects answer 502 Egress upstream unavailable; 304 Not Modified passes. Commit and deploy a changed list. |
| Build | Node.js 24 with internet access; eight minutes including install. Frozen installs skip lifecycle scripts. Next.js uses next build or next build --webpack; Vite/TanStack use vite build with at most one direct tsc, tsc --noEmit, tsc -b or tsc --build stage before or after it. Bun is pinned to 1.2.22. Runtime secrets are absent: commit generated inputs and intentional public build values. |
| Worker size | Next.js main module: at most 15 MiB uncompressed and 10 MiB gzipped. Other modules: at most 5 MiB each. Total modules: 10 MiB, or 15 MiB for Next.js. Exceeding a limit fails the build. |
| Build output | Static output needs index.html: at most 10 MiB per file, 25 MiB and 1,000 files total; compressed artifact at most 30 MiB. A build_failed excerpt ending with ohmyho.st packaging: names the output limit. |
| Private files | Create-once logical keys in each data identity; shared Dev/Prod share keys, and a fresh reset identity can reuse old names. Physical bucket quota is 1 GiB including open reservations. Signed capabilities last at most five minutes. Files · Change data assignments. |
| File batch operations | readMany and deleteMany accept 1–4,000 distinct logical keys. Control framing/JSON is at most 4 MiB; consume or cancel each read body before the next item and require complete stream framing. Files. |