[{"data":1,"prerenderedAt":695},["ShallowReactive",2],{"docs:\u002Fdocs\u002Flimits":3,"docs:nav":643},{"id":4,"title":5,"badge":6,"body":7,"description":634,"extension":635,"meta":636,"navigation":637,"order":626,"path":638,"section":639,"seo":640,"stem":641,"__hash__":642},"docs\u002Fdocs\u002Flimits.md","Limits & quotas",null,{"type":8,"value":9,"toc":622},"minimark",[10,15,77,90,100,107,121,125,128,187,193,242,249,253,341,345,443,447,508,516,520,525,551,555,565,569,615],[11,12,14],"h2",{"id":13},"rate-limits","Rate limits",[16,17,18,34],"table",{},[19,20,21],"thead",{},[22,23,24,28,31],"tr",{},[25,26,27],"th",{},"Limit",[25,29,30],{},"Value",[25,32,33],{},"Scope",[35,36,37,52,64],"tbody",{},[22,38,39,43,49],{},[40,41,42],"td",{},"Sustained request rate",[40,44,45],{},[46,47,48],"strong",{},"30 per minute",[40,50,51],{},"Per credential",[22,53,54,57,62],{},[40,55,56],{},"Burst",[40,58,59],{},[46,60,61],{},"3 per second",[40,63,51],{},[22,65,66,69,74],{},[40,67,68],{},"Credential provisioning",[40,70,71],{},[46,72,73],{},"5 per hour",[40,75,76],{},"Per source address",[78,79,80,81,85,86,89],"p",{},"Exceeding a request limit returns ",[82,83,84],"code",{},"429"," with ",[82,87,88],{},"Retry-After: 5",":",[91,92,97],"pre",{"className":93,"code":95,"language":96},[94],"language-text","HTTP\u002F1.1 429 Too Many Requests\nRetry-After: 5\n\n{\"error\":\"rate limited\",\"retryAfter\":5}\n","text",[82,98,95],{"__ignoreMap":99},"",[78,101,102,103,106],{},"The rate limit is keyed on the ",[82,104,105],{},"credential"," query parameter, so separate credentials get separate\nbudgets. If you need more throughput for a single workload, that is a plan conversation rather than\nsomething to engineer around by rotating credentials.",[108,109,112],"app-callout",{"title":110,"tone":111},"Thirty per minute is lower than it sounds — design for it","note",[78,113,114,115,120],{},"The API is a control plane, not a data path: object bytes never traverse it, so a well-built client\nmakes very few calls. A 1 GiB upload is two calls plus the direct shard writes. A client that hits 30\nper minute is usually making one call per small object rather than packing them into shared slabs —\nsee ",[116,117,119],"a",{"href":118},"\u002Fdocs\u002Fapi\u002Fslabs#packing-strategy","Packing strategy",".",[11,122,124],{"id":123},"storage-caps","Storage caps",[78,126,127],{},"Each credential carries caps recorded at provisioning:",[16,129,130,140],{},[19,131,132],{},[22,133,134,137],{},[25,135,136],{},"Cap",[25,138,139],{},"Enforced",[35,141,142,165,173,180],{},[22,143,144,147],{},[40,145,146],{},"Maximum stored bytes",[40,148,149,150,153,154,157,158,161,162],{},"Yes — ",[82,151,152],{},"402"," on ",[82,155,156],{},"prepare-write",", ",[82,159,160],{},"slabs",", and ",[82,163,164],{},"objects",[22,166,167,170],{},[40,168,169],{},"Daily read bytes",[40,171,172],{},"Recorded, not currently enforced",[22,174,175,178],{},[40,176,177],{},"Daily write bytes",[40,179,172],{},[22,181,182,185],{},[40,183,184],{},"Monthly spend",[40,186,172],{},[78,188,189,190,89],{},"Cap accounting is in ",[46,191,192],{},"whole 4 MiB sectors",[16,194,195,205],{},[19,196,197],{},[22,198,199,202],{},[25,200,201],{},"Endpoint",[25,203,204],{},"Accounted as",[35,206,207,219,232],{},[22,208,209,214],{},[40,210,211],{},[82,212,213],{},"POST \u002Fprepare-write",[40,215,216],{},[82,217,218],{},"totalShards × 4 MiB",[22,220,221,226],{},[40,222,223],{},[82,224,225],{},"POST \u002Fslabs",[40,227,228,231],{},[82,229,230],{},"sectors × 4 MiB"," per slab",[22,233,234,239],{},[40,235,236],{},[82,237,238],{},"POST \u002Fobjects",[40,240,241],{},"4 KiB per object",[108,243,246],{"title":244,"tone":245},"Small objects in their own slabs are expensive","warn",[78,247,248],{},"A 100 KiB object written as its own 10-of-15 slab is accounted at 15 whole sectors — 60 MiB, a 600×\noverhead against its logical size. This is arithmetic, not a penalty: 15 providers each hold a\nsector, and a sector is the unit they deal in. Pack small objects into shared slabs and the overhead\ndisappears.",[11,250,252],{"id":251},"erasure-coding-constraints","Erasure coding constraints",[16,254,255,264],{},[19,256,257],{},[22,258,259,262],{},[25,260,261],{},"Constraint",[25,263,30],{},[35,265,266,278,286,299,307,318,326,333],{},[22,267,268,275],{},[40,269,270,271,274],{},"Minimum redundancy (",[82,272,273],{},"totalShards \u002F minShards",")",[40,276,277],{},"1.5×",[22,279,280,283],{},[40,281,282],{},"Maximum redundancy",[40,284,285],{},"4.0×",[22,287,288,293],{},[40,289,290],{},[82,291,292],{},"minShards",[40,294,295,296],{},"≤ ",[82,297,298],{},"totalShards",[22,300,301,304],{},[40,302,303],{},"Default geometry",[40,305,306],{},"10 data + 5 parity = 15",[22,308,309,315],{},[40,310,311,314],{},[82,312,313],{},"encryptionKey"," length",[40,316,317],{},"exactly 32 bytes",[22,319,320,323],{},[40,321,322],{},"Duplicate provider within a slab",[40,324,325],{},"rejected",[22,327,328,331],{},[40,329,330],{},"Duplicate sector root within a slab",[40,332,325],{},[22,334,335,338],{},[40,336,337],{},"Sector size",[40,339,340],{},"4 MiB",[11,342,344],{"id":343},"request-constraints","Request constraints",[16,346,347,355],{},[19,348,349],{},[22,350,351,353],{},[25,352,261],{},[25,354,30],{},[35,356,357,368,376,387,395,413,425,433],{},[22,358,359,362],{},[40,360,361],{},"Object key",[40,363,364,365],{},"exactly 32 bytes, 64 hex characters, no ",[82,366,367],{},"\u002F",[22,369,370,373],{},[40,371,372],{},"Slab ID",[40,374,375],{},"exactly 32 bytes, 64 hex characters",[22,377,378,381],{},[40,379,380],{},"Provider public key",[40,382,383,386],{},[82,384,385],{},"ed25519:"," + 64 hex characters",[22,388,389,392],{},[40,390,391],{},"Sector root",[40,393,394],{},"64 hex characters",[22,396,397,406],{},[40,398,399,401,402,405],{},[82,400,105],{}," \u002F ",[82,403,404],{},"signature"," encoding",[40,407,408,409,412],{},"base64url ",[46,410,411],{},"with"," padding",[22,414,415,420],{},[40,416,417,405],{},[82,418,419],{},"appKey",[40,421,408,422,412],{},[46,423,424],{},"without",[22,426,427,430],{},[40,428,429],{},"Byte-slice JSON fields",[40,431,432],{},"standard base64 with padding",[22,434,435,440],{},[40,436,437],{},[82,438,439],{},"validUntil",[40,441,442],{},"unix seconds, decimal in the query, little-endian uint64 in the hash",[11,444,446],{"id":445},"pagination","Pagination",[16,448,449,464],{},[19,450,451],{},[22,452,453,455,458,461],{},[25,454,201],{},[25,456,457],{},"Mechanism",[25,459,460],{},"Default",[25,462,463],{},"Notes",[35,465,466,488],{},[22,467,468,473,482,485],{},[40,469,470],{},[82,471,472],{},"GET \u002Fslabs",[40,474,475,478,479],{},[82,476,477],{},"limit"," + ",[82,480,481],{},"offset",[40,483,484],{},"50",[40,486,487],{},"Not a stable cursor; entries can be missed if the set changes between pages.",[22,489,490,495,503,505],{},[40,491,492],{},[82,493,494],{},"GET \u002Fobjects",[40,496,497,478,499,502],{},[82,498,477],{},[82,500,501],{},"after"," timestamp",[40,504,484],{},[40,506,507],{},"Preferred. Stable enough for synchronisation; make application idempotent for timestamp ties.",[78,509,510,511,513,514,120],{},"For a complete enumeration, walk ",[82,512,494],{}," and collect slab IDs from the records rather than\npaging ",[82,515,472],{},[11,517,519],{"id":518},"signature-expiry","Signature expiry",[78,521,522,524],{},[82,523,439],{}," is chosen entirely by you. There is no server-imposed maximum, which means the\ndiscipline is yours:",[526,527,528,535,541],"ul",{},[529,530,531,534],"li",{},[46,532,533],{},"60 seconds"," for interactive calls.",[529,536,537,540],{},[46,538,539],{},"Minutes, not days."," A signed URL is a bearer capability until it expires; expiry is the only\nreplay protection in the scheme.",[529,542,543,550],{},[46,544,545,546,549],{},"Never sign a ",[82,547,548],{},"DELETE"," far into the future."," That signature is a deletion capability for as long\nas it remains valid, wherever the URL was logged.",[11,552,554],{"id":553},"no-cors","No CORS",[108,556,558],{"title":557,"tone":245},"The API cannot be called from a browser",[78,559,560,561,564],{},"No ",[82,562,563],{},"Access-Control-Allow-Origin"," header is sent on any endpoint, so cross-origin browser requests are\nblocked by the browser regardless of what you do client-side. Call the API from a server-side runtime,\nor proxy it through your own backend — which is the better pattern anyway, since it keeps your\ncredential's private key off the client.",[11,566,568],{"id":567},"availability-expectations","Availability expectations",[16,570,571,580],{},[19,572,573],{},[22,574,575,577],{},[25,576,201],{},[25,578,579],{},"Behaviour",[35,581,582,595,607],{},[22,583,584,588],{},[40,585,586],{},[82,587,156],{},[40,589,590,591,594],{},"May return ",[82,592,593],{},"503"," when provider availability dips. Always retry with backoff.",[22,596,597,600],{},[40,598,599],{},"Manifest endpoints",[40,601,602,603,606],{},"Expected to be consistently available; ",[82,604,605],{},"500"," is a bug worth reporting.",[22,608,609,612],{},[40,610,611],{},"Shard reads and writes",[40,613,614],{},"Depend on individual providers, which fail routinely. Your client should treat individual provider failure as normal and route around it.",[78,616,617,618,120],{},"The base tiers are provided without a service level agreement. Contractual availability and support\ncommitments are agreed on the Enterprise tier — see ",[116,619,621],{"href":620},"\u002Fpricing","pricing",{"title":99,"searchDepth":623,"depth":623,"links":624},3,[625,627,628,629,630,631,632,633],{"id":13,"depth":626,"text":14},2,{"id":123,"depth":626,"text":124},{"id":251,"depth":626,"text":252},{"id":343,"depth":626,"text":344},{"id":445,"depth":626,"text":446},{"id":518,"depth":626,"text":519},{"id":553,"depth":626,"text":554},{"id":567,"depth":626,"text":568},"Rate limits, storage caps, geometry constraints, and the size and encoding limits that apply to every request.","md",{},true,"\u002Fdocs\u002Flimits","Reference",{"title":5,"description":634},"docs\u002Flimits","c_pNbh4JRP0qqpqz7u69mwCuC-08zqRiTJwOp3_Lv24",[644,650,655,659,664,668,673,678,682,686,687,691],{"path":645,"title":646,"description":647,"section":648,"order":649,"badge":6},"\u002Fdocs\u002Fapi\u002Faccount","Account","GET \u002Faccount — stored, read, and written byte counters for your credential.","API reference",5,{"path":651,"title":652,"description":653,"section":648,"order":654,"badge":6},"\u002Fdocs\u002Fapi\u002Fobjects","Objects","Register, read, list, and delete objects — ordered lists of slab segments with encrypted keys and opaque metadata.",4,{"path":656,"title":657,"description":658,"section":648,"order":626,"badge":6},"\u002Fdocs\u002Fapi\u002Fplacement","Placement","POST \u002Fprepare-write — get the providers, contracts, and access tokens for writing a slab's shards.",{"path":660,"title":661,"description":662,"section":648,"order":663,"badge":6},"\u002Fdocs\u002Fapi\u002Fprovisioning","Credentials","Provision, verify, and revoke the ed25519 credential that is both your API identity and your account.",1,{"path":665,"title":666,"description":667,"section":648,"order":623,"badge":6},"\u002Fdocs\u002Fapi\u002Fslabs","Slabs","Register, read, list, unpin, and prune erasure-coded slabs — the layer that records which provider holds which shard.",{"path":669,"title":670,"description":671,"section":672,"order":626,"badge":6},"\u002Fdocs\u002Fauthentication","Authentication","Every request is signed with ed25519 over a blake2b hash of the method, host, path, expiry, and body. Here is the exact construction, with working code.","Guides",{"path":674,"title":675,"description":676,"section":677,"order":626,"badge":6},"\u002Fdocs\u002Fconcepts","Concepts & data model","Sectors, shards, slabs, objects, and accounts — what each one is, why the model has no filenames, and what that means for your integration.","Introduction",{"path":679,"title":680,"description":681,"section":639,"order":663,"badge":6},"\u002Fdocs\u002Ferrors","Errors","Status codes, the two different error body formats, and the one case where a failure arrives with a 200.",{"path":683,"title":684,"description":685,"section":677,"order":663,"badge":6},"\u002Fdocs","Overview","Tessera is an HTTP API for storing encrypted, erasure-coded objects across independent storage providers. This is the reference for it.",{"path":638,"title":5,"description":634,"section":639,"order":626,"badge":6},{"path":688,"title":689,"description":690,"section":672,"order":663,"badge":6},"\u002Fdocs\u002Fquickstart","Quickstart","Provision a credential, upload an object across 15 providers, and read it back. Fifteen minutes, one file of code.",{"path":692,"title":693,"description":694,"section":672,"order":623,"badge":6},"\u002Fdocs\u002Frecovery","Recovery without Tessera","How to retrieve your data if Tessera is unavailable, unwilling, or permanently gone — and what you need to keep on hand for that to work.",1786190914722]