OpenInspect
Reference

Limits reference

Every documented limit, cap, and default in OpenInspect, grouped by area, with where each one applies.

Last reviewed View as MarkdownEdit on GitHubGive feedback

This page collects the limits and defaults that OpenInspect enforces. Values marked as settings can be changed by an administrator; the rest are fixed.

Sessions

LimitValueWhere it applies
Repositories per session target10Ad-hoc multi-repository sets and environments
Prompt length64,000 charactersWeb prompts and child follow-up prompts sent with send-child-prompt
Unfinished prompts per session50Prompts that are pending or processing. A further prompt is rejected with "A session may have at most 50 unfinished prompts"
Images per prompt6Web and Slack prompts
Image size10 MiB eachPNG, JPEG, WebP, or GIF
Concurrent child sessions per parent5 by defaultSandbox setting maxConcurrentChildSessions
Total child sessions per parent15 by defaultSandbox setting maxTotalChildSessions
Session cost limitBlank by default (no limit); a positive USD amount when setSandbox setting maxSessionCostUsd, overridable per session from the Budget sidebar section

Boot and sandbox

LimitValueWhere it applies
Connect watchdog4 minutesFrom sandbox creation until the runtime first connects. Covers the provider launching the container, not your scripts
Boot budget30 minutes by defaultFrom sandbox creation until ready, including setup.sh and start.sh. Operators change it with SANDBOX_BOOT_TIMEOUT_MS
Heartbeat timeout90 secondsWhile connected (booting or ready), a runtime that stops sending heartbeats for this long is marked stale and stopped
Heartbeat interval30 secondsHow often the runtime reports in while connected
Tunnel ports10Sandbox setting tunnelPorts
Tunnel URL wait before start.sh30 seconds by defaultTUNNEL_WAIT_TIMEOUT_SECONDS in the sandbox; start.sh runs without fresh URLs if it expires
Final snapshot buffer10 minutes by default, 5 minutes minimumSandbox setting finalSnapshotBufferMs: time reserved before provider expiry to save state
Sandbox lifetimeBlank: 2 hours on Modal and E2B, 45 minutes (the maximum) on Vercel, the provider's own default on OpenComputer. When set: whole seconds, at least 1 secondSandbox setting sandboxTimeoutMs
Prompt execution timeoutThe configured sandbox timeout; otherwise the operator's EXECUTION_TIMEOUT_MS; otherwise 2 hoursHow long a message may stay processing before it is failed

Secrets

LimitValueWhere it applies
Secrets per scope50Global, repository, and environment scopes
Key length256 charactersAny scope
Key formatLetters, digits, and underscores; cannot start with a digitAny scope
Value size16 KBOne secret
Total value size per scope64 KBOne scope
Combined size per session128 KBGlobal plus the session target's secrets after merging. A larger payload fails the spawn with a per-scope byte breakdown
Reserved keysPYTHONUNBUFFERED, SANDBOX_ID, CONTROL_PLANE_URL, SANDBOX_AUTH_TOKEN, REPO_OWNER, REPO_NAME, GITHUB_APP_TOKEN, SESSION_CONFIG, RESTORED_FROM_SNAPSHOT, OPENCODE_CONFIG_CONTENT, PATH, HOME, USER, SHELL, TERM, PWD, LANGCannot be saved as secrets; the form shows a validation error

Managed skills

LimitValueWhere it applies
Canonical name64 charactersMust be unique. agent-browser, record-video, upload-screenshot, visual-verification, and customize-opencode are reserved
Description1,024 charactersSkill metadata
License200 charactersSkill metadata
Compatibility500 charactersSkill metadata
Metadata key / value100 / 500 charactersSkill metadata
Supporting files99 per skill revisionFiles beside the generated SKILL.md
Individual file256 KiBOne supporting file
Complete skill revision1 MiBInstructions plus supporting files
Managed skill content in a session5 MiBAll installed skills together
Supporting-file pathRelative, / separators, no . or .. segments, at most 10 segments or 240 UTF-8 bytes, no control characters, not SKILL.mdEach supporting file

Automations

LimitValueWhere it applies
Name length200 charactersAny automation
Instructions length15,000 charactersAny automation
Repositories and environments per automation10 combinedMulti-select is available on schedule triggers only
Minimum schedule interval15 minutesCron schedules
Webhook payload size64 KBInbound webhook triggers
Concurrent runs1 per automationScheduled and manual firings; a firing during an active run is recorded as Skipped
Consecutive failures before auto-pause3Timed-out runs count as failures; partial failures never reset the counter
Run execution timeoutThe session's execution budget (the configured sandbox timeout for the run's scope, otherwise the operator's EXECUTION_TIMEOUT_MS, otherwise 2 hours), plus a 100-minute sweep graceThe session fails its own prompt at the budget. If that result never reaches the scheduler, a sweep fails the run with execution_timeout once the grace has also passed. Timed-out runs count toward auto-pause
Slack thread continuation7 daysReplies in a triggering thread continue the same session
Slack thread context20 earlier messages, 1,024 characters eachPassed to the agent when the triggering message is a reply
Automations list page25 by default, 100 at mostGET /automations
Invocation history page100 at mostGET /automations/:id/invocations

Prebuilt images

LimitValueWhere it applies
Build timeout30 minutes by default, 60 minutes at mostSandbox setting buildTimeoutSeconds; covers clone and setup.sh
Vercel build cap35 minutesVercel limits sandbox lifetime to 45 minutes, so execution is capped to keep the finalization reserve
Finalization reserve10 minutes on top of the build timeoutCallback delivery and snapshot or checkpoint capture
Rebuild schedulerEvery 30 minutesChecks each enabled scope for new commits, a missing image, or an outdated runtime
Builds per scope1 at a timeA trigger while a build is in flight is a no-op

Slack

LimitValueWhere it applies
Images per message6, 10 MiB eachAttached images and images inside forwarded messages, PNG, JPEG, WebP, or GIF
Forwarded messages per request10Each shared message's text is truncated at 4,000 characters
Generated media per completion5 files, 10 MiB per file, 25 MiB totalMedia delivery, when the operator enables it
Target dropdown lifetime1 hourThe original request is kept while you pick a repository or environment
Thread-to-session mappingAbout 7 daysReplies after that may start target selection again
Thread messages included with a follow-upUp to 10Messages posted after the previous prompt and before the new request
Thread context for channel-message automationsUp to 20 messages, 1,024 characters eachOnly when the triggering message is a reply
Session instructions10,000 charactersSettings › Integrations › Slack › Session Instructions, appended to the first prompt of new Slack sessions
Routing rules100 rules, 100-character keywordsSettings › Integrations › Slack › Routing rules

Linear

LimitValueWhere it applies
Issue-to-session mapping7 daysAfter it expires, a new agent request may start a new session

PR Feedback Autofix

LimitValueWhere it applies
Attempts per pull request30 per 24 hours by defaultSettings › Integrations › GitHub › PR Feedback Autofix; "No Autofix attempt limit" removes the cap
Review comments per feedback item100One submitted review
Diff hunk per review comment4,000 charactersLonger hunks are truncated and flagged
Prompt size200,000 bytesThe follow-up prompt built from the feedback

Analytics

LimitValueWhere it applies
Time range7, 14, 30, or 90 days; 30 is the defaultThe Analytics page

Next steps

On this page