Runtime Limits
These are implementation limits, not a guarantee that every combination is enabled on every deployment. Workspace plans and account-specific policies can impose additional restrictions.
| Surface | Limit or behavior |
|---|---|
| Cloud task/callback timeout | 30 seconds by default for each sandbox invocation. |
| Returned calls | At most 32, with at most 8 KiB calldata per call and 64 KiB total. Submission routes can be narrower. |
| Roles/Lift submission | Up to 32 calls per run, executed atomically in one sponsored UserOperation; the encoded operation must stay under 40,000 bytes of calldata (about 36 KiB of task calldata). |
| Permission manifest | 16 KiB UTF-8; at most 50 distinct declarations. |
| Runtime storage | 100 MiB serialized JSON per executable. |
| Management storage transport | 16 MiB; smaller than runtime storage capacity. |
| Webhooks | Ten active URLs per executable; 60 new executions per minute per named URL. |
| Webhook body | 256 KiB JSON. |
| Webhook result retention | 24 hours. Changed-storage snapshot inline up to 1 MiB; otherwise download link. |
| Webhook synchronous wait | Up to 55 seconds; then asynchronous result polling. |
| Upload archive | At most 10 MiB and 16 entries in the archive reader. |
Execution concurrency
Persistent state is protected by an executable-level lock and optimistic versions. A webhook request encountering active work is rejected with 409 execution_in_progress. Do not assume overlapping invocations will queue indefinitely or replay missed ticks.
Calls and value
The public task Call shape is { to, data }. It does not expose native value or delegatecall. Declared releases require each call to carry a selector covered by the manifest. Roles scopes enforce zero-value Call execution and reject administration targets/selectors.
The general 32-call guard is not a promise of batching on the current Roles/Lift route. Lift's supported account and transaction format has additional constraints.
JSON state
Storage must remain a plain JSON object. BigInts, undefined values, non-finite numbers, negative zero, and unsafe prototype keys are rejected. Store large integer amounts as decimal strings. A large state object is reloaded and validated around runs; keep checkpoints compact even when below the size cap.
For failures, inspect execution logs before retrying a potentially submitted transaction.