Limits and budgets
Every size, depth and count limit the API enforces, read from the code.
Each value below is read from the member that enforces it. A limit with a key can be changed in configuration; the others are fixed.
| Limit | Value | Configure with | What happens |
|---|---|---|---|
| Default page size | 50 | Alvo:Api:DefaultPageSize | A list request that sends no limit gets a page of this many rows. |
| Maximum page size | 200 | Alvo:Api:MaxPageSize | A larger limit is refused with 422 malformed-query (invalid-page-size); it is never silently capped. |
| Request body | 1048576 bytes (1 MiB) | Alvo:Api:MaxRequestBodyBytes | A larger body is refused before it is parsed: 422 validation (body-too-large) on a write, 422 malformed-query on a query sent as a body. |
| Payload depth | 32 | Alvo:Api:MaxPayloadDepth | A body nested deeper is refused with 422 (body-too-deep). |
| Payload keys | 512 | Alvo:Api:MaxPayloadKeys | A body carrying more property names, counted at every depth, is refused with 422 (body-too-many-fields). In a batch the count applies per row. |
| Batch rows | 1000 | Alvo:Api:MaxBatchRows | A batch with more rows is refused with 422 validation (batch-too-many-rows) and nothing is written; split it into several batches. |
Idempotency-Key length | 255 bytes | Alvo:Api:MaxIdempotencyKeyBytes | A longer Idempotency-Key, measured in UTF-8 bytes, is refused with 422 malformed-query (no violation code) rather than shortened, so two different keys never collapse into one. It can only be lowered. |
| Filter depth | 32 | — | A filter nested deeper is refused with 422 malformed-query (filter-too-deep). |
| Filter terms | 256 | — | A filter with more comparisons and connectives in total is refused with 422 malformed-query (filter-too-wide). |
in candidates | 1000 | — | An in list with more values is refused with 422 malformed-query (too-many-in-candidates). |
| Dev-key secret minimum | 32 characters | — | A dev API key whose secret is shorter stops the host at start. openssl rand -hex 16 produces exactly this length. |
| CEL nesting depth | 32 | — | A CEL expression nested deeper (parentheses, ternaries, unary operators, function arguments) is refused before it runs: a Management API apply answers 422 validation (descriptor), and a host booting with it refuses to start. |
See Configuration keys for every key, and Problem types for the refusal a request over a limit receives.