Limits

Updated 27 Sep 2026

The numbers that apply to a zone and an account, in one place. There is no limit on the number of zones, hostnames or purges, none on requests, which are counted but never charged, and none on the size of an upload or on how long an event stream or a WebSocket stays open.

Files and requests#

WhatLimit
Largest file stored20 GB. A larger file is passed through from your origin, unstored
Stored wholeFiles up to 10 MB. Larger files are stored in 5 MB pieces. These sizes are binary (10 MB is 10,485,760 bytes); the statistics and the invoice use decimal units
Byte ranges per requestOne. A multi-range request is answered with its first range
Request line and headers64 KB together, plus a small allowance, which also bounds the URL. Over it, 431
Request bodyAny size, for as long as it takes to send. A body with nothing arriving for 125 seconds is dropped with a 408, and one your origin stops taking for 125 seconds with a 502
Idle connectionClosed after 120 seconds
Stale copy served while a refresh runsUp to 24 hours past its expiry
Origin, fetching a file to store10 seconds to connect, 30 seconds to start answering, 60 seconds of stall
Origin, for everything else10 seconds to connect; 125 seconds to start answering, counted from the moment the whole request has reached your origin; 125 seconds of silence in the middle of an answer. Everything else is a request with a cookie or a login, a form, an upload, an API call, a page on a full site, an event stream and a WebSocket
Origin retriesThree tries when the connection fails before your origin has the request. A request with a body is sent once. One your origin accepted and did not start answering in time is not tried again, unless it went through a Home PoP, when a GET is tried once more straight to your origin
Requests waiting on your origin at once, at one locationHalf of all that location's requests waiting on origins, so no one site can hold the rest. Past it a request waits up to 30 seconds for a place, then gets a 503 with Retry-After
Event streams and WebSocketsOpen for as long as they carry something; closed after 125 seconds with nothing moving (a WebSocket: in either direction). A zone may have at most half of what one location can hold open at once. See Server-sent events and WebSockets
Redirects followed at the origin9 in a chain, with Follow Redirects on; a longer chain is a 502
Purge URL2,048 characters
A change to a zone reaching every locationAbout 5 seconds; a purge the same
StatisticsHourly detail for up to 31 days; any period up to 366 days by day

Rules and names#

WhatLimit
Blocked addresses, and always-allowed addresses1,000 entries in each list
Blocked AS numbers200
Hostname253 characters of letters, digits and hyphens, in labels of up to 63 characters (62 from the second label on), the last label letters only
Zone name4 to 40 letters and digits
Uploaded certificate64 KB of PEM, with a key of up to 16 KB: RSA of 2048 bits or more, or EC on P-256, P-384 or P-521

API and account#

WhatLimit
API requests per minute600 per client address and 300 per API key, in fixed one-minute windows; over it, 429 with Retry-After
Support attachmentsUp to 5 files, 10 MB each and 15 MB in all
Sign-in attempts10 failures in 15 minutes locks the email address, or the connecting address, until fewer than 10 fall inside the last 15 minutes
Session24 hours, extended by use
Password reset link3 hours

What does not exist#

  • HTTP/3. HTTPS is served over HTTP/2 and HTTP/1.1 with TLS 1.2 or 1.3, and plain HTTP over HTTP/1.1, over IPv4 and IPv6 alike. WebSockets open over HTTP/1.1, which is what browsers use for them.
  • Cache preloading. The first viewer's request fetches a file.
  • Rules per path. Settings and blocking rules apply to a whole zone.
  • Rate limiting or bot protection that you configure. The edge limits how fast one address may ask and how many requests, open connections and requests waiting on your origin it may hold at once, answering 429 with a Retry-After past that, and lets one zone hold at most half of a location's requests waiting on origins and of its open connections, for the sake of every site it serves; a zone has no rules of its own for it.
  • Compression at the edge. A file is stored and served as your origin sent it.

Ask a human

To
Subject
Docs: Limits

Read and answered by the people who build CacheGenie, seven days a week.

Write to us