Per-user rate limit
Enforced perexternal_user_id, not across your whole tenant.
Per-key request limit
Each tenant API key also has its ownrate_limit_per_minute setting. This is
enforced across tenant memory, user, agent, API-key, and tenant routes and is
independent of the per-user and plan limits. A 429 caused by this boundary
returns details.scope: "api_key"; the shared tenant write ceiling returns
details.scope: "tenant".
Use separate keys per backend service so one integration cannot consume every
other service’s key-level capacity. Redis failure leaves requests available;
quota, identity, and database authorization checks still run normally.
Plan limits
Monthly calls and tokens reset at the start of each billing month. Write calls are
add() requests. Retrieval is unlimited on all current plans.