Limits and security
Limits
| What | Default |
|---|---|
| Requests per API token | 600 per minute |
| File size through the MCP | 10 MB (MCP_MAX_UPLOAD_MB) |
| File size through the API | 25 MB (UPLOAD_MAX_MB) |
| Task title | 200 characters |
| Description | 20,000 characters |
| Comment | 10,000 characters |
Past the rate limit the server answers 429 Too Many Requests; wait a moment and retry. Self-hosted instances
can change the defaults.
What a token can do
A bot sees only the projects it was added to, and does only what both its role in the project and its token's scopes allow. It cannot manage bots, tokens, members of other projects or workspaces, and it can never change a project's key. Everything it does is in the project's activity under its name.
Keeping tokens safe
- A token is shown once. Keep it in your MCP client's configuration, never in a repository or a prompt.
- Give each agent or machine its own token, with the fewest scopes it needs, and an expiry when you can.
- Revoke a token from the bot's page as soon as it may have leaked; requests with it fail at once.
Browsers
The MCP server refuses requests from browser origins it does not know (protection against DNS rebinding).
Agents and command-line clients send no Origin header and are always accepted.
The MCP trace
The MCP server reports every tool call to the API as the bot that made it. A call is kept with:
- the tool and its inputs, without file contents or anything that looks like a credential, and with long values cut;
- whether it worked, the first line of the answer or the error, and how long it took.
Calls are kept 30 days. Who can read them:
- the people who manage the bot (the workspace owner), on the bot's page under MCP activity;
- the bot itself, through
get_mcp_traceandget_mcp_insights; - nobody else: other bots and other workspaces get
404.
get_mcp_insights reads the trace for what to improve: tools that fail often, failures retried, long runs of
the same tool (a batch tool is missing) and slow tools. It is the start of a loop: propose improvement tasks,
ship them, then read it again to see whether they helped. Set MCP_TRACE_CALLS=false on the MCP server to turn
tracing off.