Per plan
Everything in this table is counted across the whole workspace, not per project. Pro and Team accept 10% over the event and delivery numbers before they bite; Free stops at the number. Single sign-on (SAML or OIDC) is planned and not available yet, on any plan.
The same on every plan
Monthly quotas
Every monthly quota resets at 00:00 UTC on the 1st of the month, whatever day your subscription renews. Home shows this month’s events, deliveries and AI tokens against your plan, with a warning from 80%.- Events. Every accepted submission counts once, however many records it makes, and so does every event a cron trigger, WebSocket trigger or database source writes. Refused requests and recognised duplicates are not counted. The count is exact: one counter per workspace. Past the ceiling, a new event is refused with
429and not stored. The answer carries"reason": "quota_exceeded",reset_at, anupgrade_urlandRetry-After: 3600. A trigger or source shows the refusal instead. - Deliveries. One delivery is one event sent to one destination, counted when it is created. Retries are free, and replays count. Past the ceiling, deliveries are held, not dropped: see The delivery allowance and holds.
- AI tokens. The input and output tokens of every AI call count: AI trigger runs, and workflow
call_aiandagent_callsteps. There is no grace: once the allowance is used, the next AI call is refused before the model runs, and its step or run fails. See AI allowance. - AI trigger runs. Each AI trigger run counts once it starts running; one that fails is not counted. Past the quota, a new run fails.
The burst limit
Each credential has a burst limit of about 100 requests per 10 seconds, the same on every plan:- on ingest, per endpoint URL and per ingest key, and per Data API key;
- on
/admin/apiand/mcptogether, per API key, per connected agent and per person signed in to the console.
429 and a Retry-After: 10 header.
The burst limit is a best-effort burst guard, not an exact count. It runs on Cloudflare’s rate limiting, where each Cloudflare location counts separately and its count catches up within seconds. So a short burst can get through above 100 before the first 429, and a sender whose requests reach several Cloudflare locations is counted once at each. It is there to stop a runaway sender, not to meter one. The monthly event quota is separate from it, and exact.
The customer portal’s API has the same kind of guard, at about 60 calls a minute per portal token.