> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ohmyho.st/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For account actions, read https://ohmyho.st/skills/ohmyhost-get-started/SKILL.md and use the authenticated ohmyho.st CLI or local product MCP. Mintlify search only reads documentation. Preserve the customer’s selected project, environment and authentication provider.

# Limits, errors and polling

> Understand bounded requests, permissions and long-running operations.

| Capability | Current contract |
| - | - |
| New user API token | No expiry; valid until revoked; full value shown once. |
| Existing user token | Keeps its recorded expiry. |
| Saved logins on one computer | At most 64. `profile_limit_reached` saves no new login: remove one with `ohmyhost logout --profile-name NAME --json`, then log in again. |
| Database query | Explicit Dev/Prod; one read-only statement, 4 KiB SQL, 32 scalar parameters, 100 rows and five seconds. |
| Database write | Explicit Dev/Prod; one INSERT/UPDATE/DELETE/upsert, 64 KiB SQL, up to 100 JSON parameters, 1,000 directly affected rows and five seconds. |
| Application database call | One statement per call: 64 KiB SQL, 100 parameters and 1 MiB total parameter data; each JSON parameter at most 64 KiB. `transaction([...])` takes up to 25 statements; results at most 1,000 rows, 1 MiB and 10,000 values. SQL statements time out after ten seconds. |
| Held application database connection | Two transaction/auth connections per physical data area; 100 statements, 30 seconds total and five seconds idle. Shared Dev/Prod use the same pool. |
| Direct database login | `read` or confirmed `write`; five minutes to 24 hours, one hour by default; at most three active per project environment. Connection URI returned once. |
| Write retry | Keep the original idempotency key; an existing receipt observes one attempt, and unknown outcomes must be inspected before any deliberately new write. |
| Deployment plan | Valid 24 hours; after `deployment_plan_expired`, plan again. |
| Promotion, rollback, deletion and data-change plans | Confirmation valid ten minutes; use the plan's ETag and token. An expired or invalid confirmation needs a fresh plan. |
| Project context | At most 500 lines / 32 KiB. |
| Saved project notes | At most 250 lines / 16 KiB. |
| SQL export | One accepted request per project per rolling 24 hours; 256 MiB plaintext maximum. |
| Export download | Signed URL valid 24 hours; encrypted ZIP retained seven days. A new link requires at least 24 hours of remaining retention: download within the first six days. |
| Protected Dev access | One persistent owner-managed share link without automatic expiry; each opening starts a browser session of at most 12 hours. Rotation or revocation blocks old links and sessions on their next request. Public Dev needs no link. |
| Request and scheduled run | At most 50 ms CPU and ten subrequests per customer invocation; network waiting is not CPU time. Excess CPU answers `429 Runtime limit exceeded`; a scheduled attempt may last 120 seconds. |
| Browser policy and media | Declare only required browser origins and capabilities in `runtime.browser`; server egress is separate. Defaults, CORS, nonces, media and microphone opt-in are explained in [Browser security](/browser-security). |
| Standard database compute | Free 0.25 CU / 1 GB / 60 s; Paid 0.5 CU / 2 GB / 60 s. |
| Performance database compute | Paid 1 CU / 4 GB / 300 s; 2.5× compute credits per equal active duration. |
| Outbound `fetch` | At most 13 exact HTTPS origins in `runtime.egress.allow`, without paths, trailing slash, ports, credentials, IP literals or local hosts. Unlisted origins answer `403 Egress denied`. Redirects answer `502 Egress upstream unavailable`; `304 Not Modified` passes. Commit and deploy a changed list. |
| Build | Node.js 24 with internet access; eight minutes including install. Frozen installs skip lifecycle scripts. Next.js uses `next build` or `next build --webpack`; Vite/TanStack use `vite build` with at most one direct `tsc`, `tsc --noEmit`, `tsc -b` or `tsc --build` stage before or after it. Bun is pinned to `1.2.22`. Runtime secrets are absent: commit generated inputs and intentional public build values. |
| Worker size | Next.js main module: at most 15 MiB uncompressed and 10 MiB gzipped. Other modules: at most 5 MiB each. Total modules: 10 MiB, or 15 MiB for Next.js. Exceeding a limit fails the build. |
| Build output | Static output needs `index.html`: at most 10 MiB per file, 25 MiB and 1,000 files total; compressed artifact at most 30 MiB. A `build_failed` excerpt ending with `ohmyho.st packaging:` names the output limit. |
| Private files | Create-once logical keys in each data identity; shared Dev/Prod share keys, and a fresh reset identity can reuse old names. Physical bucket quota is 1 GiB including open reservations. Signed capabilities last at most five minutes. [Files](/files) · [Change data assignments](/environments#change-data-assignments). |
| File batch operations | `readMany` and `deleteMany` accept 1–4,000 distinct logical keys. Control framing/JSON is at most 4 MiB; consume or cancel each read body before the next item and require complete stream framing. [Files](/files). |

## API versions and interface changes

Product endpoints use the `/v1` route family. The CLI, SDK and MCP are released together under one version; `/v1` does not yet promise a stable interface.

While the interface is young, request fields, commands and supported behavior can change without a guaranteed deprecation or sunset notice period. Pin the client release used by an automation, and review the [changelog](/changelog), [current release](https://ohmyho.st/client-release.json) and [OpenAPI contract](/api) before updating. Only the current release is published; older release URLs return 404, so keep your own copy and checksum of an archive you pin. A pinned client does not freeze the server contract or guarantee that every older client remains compatible.

## Request failures

Act on `code`, `suggested_action` and `retryable`; HTTP status only groups [error codes](/troubleshooting#error-codes). `401`: authenticate. `402`: credits, Paid access or a Stop budget block the request. `403`: the account lacks permission, GitHub lacks repository access, an interactive login is required or Performance needs Paid. `409`: a prerequisite must change, such as GitHub connection, sender domain, plan or ETag. An API `429` requires waiting for `Retry-After`. Repeat an unchanged request only when `retryable` is true; an uncertain response keeps the original request and idempotency key. Never start another payment or destructive mutation with a new key merely because its result is unknown.

Database API reads and writes retain application RLS. Empty results are not proof that no rows exist, and the write count does not include every possible trigger/cascade effect. Use [database access](/database) for the request and receipt contract.

An oversized application result answers non-retryable SQLSTATE `54000`: page reads or split writes. `query()`, `transaction()` and an autocommit held statement roll back a rejected `RETURNING` write or `WITH` statement. Inside your own `BEGIN`, the effects remain in that open transaction: send `ROLLBACK` or end the held scope without `COMMIT`. Input rejected before sending is `database_query_invalid`; an idle or expired held scope is `database_unavailable` and needs a new scope.

A `billing_issue` refers to an existing invoice. Follow its address-correction or contact action and preserve that invoice; a new payment or disabled tax is not a retry strategy. [Billing issues](/billing#resolve-a-tax-issue-on-the-original-invoice).

## Waiting for work

The original operation is the source of progress. CLI `--wait` has a bounded local wait; the operation can continue afterward. MCP status tools return current observations. Follow the response's polling interval and stop on terminal state.

For pending mail verification, follow the returned `next_check_after_seconds`, currently 60 seconds. Custom-domain status returns no interval: check it again after DNS changes have had time to propagate rather than rebuilding. A Skill instruction to poll does not schedule a future agent run. Arrange your harness's supported scheduler when authorized, or keep the operation ID and return the next command to the user.

[OpenAPI schemas](/api) contain the exact field, request and endpoint limits. [Status](/status) · [Export](/backups).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.