SDK limits
Request bounds enforced by the TypeScript SDK and Carpo APIs.
The SDK checks input shape and some request sizes before sending a request. Carpo applies additional per project, environment, database, bucket, and Function limits. A successful TypeScript check does not bypass server validation or authorization.
Database Data API
| Input | SDK bound |
|---|---|
| Page size | 1 to 100 rows |
| Page number | 1 to 100,000 |
| Page offset | Up to 1,000,000 rows |
| Selected columns | 1 to 100 distinct names |
Conditions in one where object | Up to 25 |
in or notIn list | 1 to 100 values |
Rows in insertMany or upsert | 1 to 100 |
| Values in a row object | Up to 100 columns |
| String values | Up to 64 KiB each |
| Exact count | Adds a separate query |
Database values are strings, numbers, booleans, or null. The browser Data API does not support raw SQL, joins, or transactions. update() and delete() require at least one condition.
Storage
| Input | SDK bound |
|---|---|
| Object list page | 1 to 1,000 entries; default 100 |
| Version and trash page | 1 to 100 entries; default 100 |
| Delete batch | 1 to 100 unique object keys |
| Download URL expiry | 1 second to 7 days |
| Parallel multipart transfers | 1 to 10; default 3 |
| Requested part URLs | 1 to 100 per request |
| Part number | 1 to 10,000 |
| Custom metadata | Up to 100 fields and 8 KiB before Carpo upload metadata |
Object keys must be valid relative paths. The SDK rejects reserved internal keys, traversal segments, control characters, backslashes, leading slashes, and keys outside the Carpo key limit.
Functions and Realtime
Function IDs must be non empty and at most 128 characters. A Function path must be a local path beginning with / and at most 4,096 characters. Realtime subscriptions support up to 100 distinct table names on a connection.
Upload bytes are transferred to R2 with signed URLs, so they do not pass through the Carpo API JSON request body limit. The bucket, R2, and project quota limits still apply.