The caps that are actually enforced for the workspace right now: plan limits plus
purchased agent add-ons (added to maxAgents). Creating a resource past a cap answers
403 BILLING_ERROR with metadata: { limit, current, tier }. This is the endpoint to
read before doing that work in bulk.
Values of 9999, 99999 or -1 mean effectively unlimited. With no active subscription
tier is none and every cap is 0, except audioRetentionDays (7) and features
(Starter’s flags). The per-plan general API rate limit (Starter 120, Growth 200,
Business 300, Enterprise 600 requests/min) is not part of this response.
Consistency. Cached server-side for 5 minutes (30 seconds when there is no
subscription), and the response carries Cache-Control: private, max-age=300. Plan
changes and payment-processor events clear the server cache.
Access
full. Signed-in users need the owner, admin or billing role./api/billing route. See Rate limits.Workspace API key: jl_ followed by 64 lowercase hex characters, created by the workspace owner in the
dashboard (Settings → API Keys) and sent as Authorization: Bearer jl_.... The plaintext is shown once,
at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys.
Operations restricted to admins or owners reject keys without the full scope with 403, and say so in
their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret —
that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds.
See Authentication.