Limits
The values below are the values on proxium.tech today. A limit of 0 means no limit.
Request and response size
| Limit | Value | At the limit | Source |
|---|---|---|---|
| Request body | 32 MiB | 413, with a plain-text body. | src/server.rs::max_body_bytes |
| Provider answer, buffered | 64 MiB | The attempt fails. proxium moves to the next entry of the plan. | src/upstream.rs::read_capped |
| Stored answer body | 32 K characters, where 1 K is 1,024 | proxium cuts the stored copy. The caller gets the full answer. | src/types.rs::BODY_MAX_CHARS |
| Model id on image, speech and video calls | 200 characters of A-Z a-z 0-9 . _ - : | 400 bad_model. | src/server.rs::model_id_is_urlsafe |
Time
| Limit | Value | At the limit | Source |
|---|---|---|---|
x-proxium-timeout-ms | At most 120000 ms | proxium lowers a larger value to this value. It ignores 0, a negative value and text. The next row uses the lowered value. | src/engine.rs::deadline_from_headers |
Whole failover plan, with x-proxium-timeout-ms | The header value | 502 upstream_failed, with client deadline exceeded in the message. | src/engine.rs |
| Whole failover plan, without the header | No limit | Each attempt keeps its own limit. | src/engine.rs |
| One buffered attempt, not streamed | 120 s | The attempt fails as a timeout. proxium moves to the next entry. | src/upstream.rs::UpstreamClient::new |
| Connection to a provider | 10 s | The attempt fails. proxium moves to the next entry. | src/upstream.rs |
| Gap between two reads of a stream | 300 s | proxium ends the stream. The timer also runs while the provider prepares its first byte. A stream has no limit on its total time. | src/upstream.rs::stream_read_timeout |
With x-proxium-timeout-ms, the deadline covers the plan up to the first byte of a stream. After the first byte, only the gap between reads applies.
Failover and retry
| Limit | Value | At the limit | Source |
|---|---|---|---|
| Entries in one failover plan | 4 | proxium stops and answers 502 upstream_failed. | src/chain.rs::MAX_FAILOVER_CHAIN |
| Extra tries of one entry | 1 | Only after a 5xx, 408, 429 or "warming" answer. | src/engine.rs::EngineConfig |
Wait for a provider's Retry-After | 30 s at most | proxium waits the smaller of Retry-After and 30 s, then tries again. | src/engine.rs::EngineConfig |
| Failures that open a circuit breaker | 5 inside 10 minutes | proxium skips the provider. | src/circuit.rs |
| Open time after a transient failure | 30 s | proxium allows a trial call. | src/circuit.rs::TRANSIENT_RESET_MS |
| Open time after a rejected credential or an exhausted quota | 30 minutes | proxium allows a trial call. | src/circuit.rs::QUOTA_RESET_MS |
| Trial successes that close a breaker | 2 | The breaker closes. | src/circuit.rs::PROBE_SUCCESSES |
| Failover price guard | Not active | Failover can reach a model at any price. | src/engine.rs::price_guard |
Spend and rate
| Limit | Value | At the limit | Source |
|---|---|---|---|
| Key calls per hour | 0 on a key that the console creates | 429 tenant_capped, retry-after: 60. | src/accounts.rs::mint_team_key |
| Key cost per day | 0 on a key that the console creates. Not enforced on proxium.tech. | None. | src/server.rs::budget_limits |
| Key requests and tokens per minute | 0 on a key that the console creates | 429 tenant_capped, retry-after: 60. | src/store_pg.rs::PgKeyStore::resolve |
| Sender calls per hour | You set it. 0 by default. | 429 source_capped, retry-after: 60. | src/source_limits.rs |
| Sender dollars per day | You set it. 0 by default. | 429 source_capped, retry-after: 60. | src/source_limits.rs |
| Monthly cap of the project | None during the open beta | None. | src/credits.rs |
The calls window is a rolling 60 minutes. The cost window is a rolling 24 hours, in hourly buckets. The rate windows are a rolling 60 seconds.
Names and lists
| Limit | Value | At the limit | Source |
|---|---|---|---|
| Key name on the Keys screen | 60 characters | proxium drops a longer name. The key is unnamed. | src/accounts.rs::mint_team_key |
| Endpoint name | 60 characters | 400 bad_name. | src/tenant_api_endpoints.rs::create |
| Vendor name on the Providers screen | 1 to 40 characters of a-z 0-9 -, with no - at either end | 400 bad_name. | src/tenant_endpoints.rs::MAX_NAME |
| Models of one vendor | 200 | 400 too_many_models. | src/tenant_endpoints.rs::MAX_MODELS |
How soon a change applies
| Change | Value | Source |
|---|---|---|
| A routing, sender-ceiling or cache-charge change in the console | At once on the server that saved it, and within 30 s on every server | src/main.rs::spawn_config_refresh |
| The monthly spend that the credit check reads | Refreshed every 30 s | src/main.rs::spawn_config_refresh |
| The model list of each vendor | Read again every 21600 s | src/model_refresh.rs::DEFAULT_REFRESH_SECS |