# Limits

Last updated: 2026-10-10

## Requests

| Limit | Value |
|---|---|
| Request body | 64 KB; 168 KB for `receipt/verify` and `/mcp` (413 `body_too_large`) |
| URL length | 2,048 characters, http or https, ports 80 and 443 |
| Quote | 1,000 characters after normalisation |
| Quotes per `verify/quotes` call | 20 |
| Citations per `verify/citations` call | 10 |
| `verify/document`: document size, pairs per document, pairs per part | 60,000 bytes; 100 (the rest skipped as `beyond_limit`); 10 |
| URLs per `check/links` call | 10 |
| Citations, quotes, pairs or URLs per free-trial call (`verify/citations`, `verify/quotes`, `verify/document`, `check/links`) | 3; a larger batch gets the normal 402 offer (`details.reason` `trial_too_large`) |
| Packages per `check/packages` call | 10 |
| Attest note | 280 characters |
| Receipt sent to `receipt/verify` | 163,840 characters (160 KB; a receipt with every field at its cap is about 128 KB, whatever characters the site's certificate names and headers use) |

## Fetching

| Limit | Value |
|---|---|
| Redirects | 5, each checked again |
| Connect timeout | 5 seconds |
| Total timeout | 10 seconds |
| Body size | 2 MB as received, 2 MB after decompression |
| Content types | HTML, XHTML, plain text, JSON |
| PDF | `fetch`, `verify/quote`, `verify/quotes` and `verify/citations` only. Text layer only, no OCR; the body cap above applies. Up to 1,000 pages and 2,097,152 characters (then signal `pdf_truncated`). Each PDF gets 5 seconds and 64 MB of buffers plus a 64 MB heap (else `pdf_timeout`, `pdf_over_budget` or `pdf_out_of_memory`, charged like any page we cannot read). 2 PDFs are read at once across all callers, with a queue of 16; then 503 `over_capacity` (`details.reason` `pdf_queue_full`) with `Retry-After`, not charged |
| Text returned by `fetch` | 20,000 characters (hashes cover the full text) |
| robots.txt | cached up to 1 hour; 5-second timeout |

## Rates

| Limit | Value |
|---|---|
| Per caller IP address | 60 paid-route requests a minute |
| `verify/citations`, `verify/quotes` and `verify/document` calls where every citation or quote fails (422, not charged), per caller IP address, counted together | 6 a minute, counting batches still running; then 429 with `details.reason` `uncharged_failures` |
| `verify/citations`, `verify/quotes` and `verify/document` calls being matched, across all callers, shared | 2 at once, with a queue of 8; then 503 `over_capacity` with `Retry-After`, not charged |
| Per target host | 1 request a second and 30 a minute, across all callers |
| crates.io lookups (`check/packages`) | 1 a second across all callers; a call that would wait over 20 seconds gets 429; free trial calls hold at most half of that queue |
| Whole service | 8 fetches at once, with a queue of 32 |
| Lightning (L402) invoices, where L402 is on | 30 unpaid per caller IP address in 10 minutes, 1,000 open in all. An invoice whose request you then pay with x402 does not count |

Over a limit you get 429 `rate_limited` with a `Retry-After` header, before any payment is asked for. Back off for the time it gives.

## What the fetcher does not do

- Run JavaScript, use proxies or rotate IP addresses.
- Solve or get past CAPTCHAs or bot checks.
- Send cookies, logins or your headers.
- Reach private or internal addresses.
- Fetch pages that robots.txt or our opt-out list disallows.

## Network

Payments run on Base Sepolia, a test network. See [Payments](/docs/payments).
