Retrieve plan limits

View as Markdown
The caps that are actually enforced for the workspace right now: plan limits plus purchased agent add-ons (added to `maxAgents`). Creating a resource past a cap answers 403 `BILLING_ERROR` with `metadata: { limit, current, tier }`. This is the endpoint to read before doing that work in bulk. Values of `9999`, `99999` or `-1` mean effectively unlimited. With no active subscription `tier` is `none` and every cap is 0, except `audioRetentionDays` (7) and `features` (Starter's flags). The per-plan general API rate limit (Starter 120, Growth 200, Business 300, Enterprise 600 requests/min) is not part of this response. **Consistency.** Cached server-side for 5 minutes (30 seconds when there is no subscription), and the response carries `Cache-Control: private, max-age=300`. Plan changes and payment-processor events clear the server cache. **Access** - **Required scope:** `full`. Signed-in users need the `owner`, `admin` or `billing` role. - **Rate limit:** Billing — 15 requests/min per workspace, shared by every `/api/billing` route. See [Rate limits](/rate-limits). - **Plan:** Available on every plan.

Authentication

AuthorizationBearer
Workspace API key: `jl_` followed by 64 lowercase hex characters, created by the workspace owner in the dashboard (**Settings → API Keys**) and sent as `Authorization: Bearer jl_...`. The plaintext is shown once, at creation; Jelliu stores only a SHA-256 hash. A workspace can hold up to 25 active keys. | Scope | GET / HEAD | POST / PUT / PATCH / DELETE | Admin-only routes | | --- | --- | --- | --- | | `read` | Yes | No | No | | `write` | Yes | Yes | No | | `full` | Yes | Yes | Yes | Operations restricted to admins or owners reject keys without the `full` scope with `403`, and say so in their description. No key, whatever its scope, can mint or revoke API keys or rotate a webhook secret — that requires a signed-in owner session. A revoked key stops authenticating within about 10 seconds. See [Authentication](/authentication).

Response headers

Cache-ControlstringOptional
Private cache for five minutes.

Response

Effective limits.
dataobject

Errors

401
Unauthorized Error
403
Forbidden Error
429
Too Many Requests Error