# Limits

Design producers below the public protocol ceilings and expect the running deployment or account policy to enforce lower operational values.

## Public protocol ceilings

| Resource | Maximum |
| --- | --- |
| Raw request body | 131072 bytes |
| Title | 200 characters |
| Notification body | 65536 UTF-8 bytes |
| Tags | 100 protocol / 20 default validation |
| Metadata | 50 pairs / 32768 serialized bytes |
| Actions | 5 |
| Deduplication key | 255 characters |

> **Runtime validation is authoritative.** JSON Schema cannot express every normalization and UTF-8 rule. Validate against the runtime contract or SDK, and do not assume every protocol ceiling is enabled for an account.

## Operational policy

The deployment can apply lower payload, tag, metadata, request-rate, storage, and retention limits. A deduplicated create does not consume a new stored-notification slot. Inspect current account usage in Settings and handle quota_exceeded and rate_limited as documented errors; no commercial plan or price is implied by these safety guards.

- [OpenAPI limits](/openapi.json)
- [Errors](/docs/errors-and-retries)
