Limits protect the client, control plane, runtime, and guest independently. An account or endpoint can impose a lower limit than the client maximum.
Client bounds
| Boundary | Current value |
|---|---|
| API key | 32–256 visible ASCII bytes |
| Session ID | 32 lowercase hexadecimal characters |
| SSH public key input | 512 bytes maximum |
| Default command timeout | 120 seconds |
| Maximum command timeout | 3,600 seconds |
| Command stdin through the SDK | 16 MiB |
| File transfer through the SDK | 16 MiB per file |
| Legacy workload upload | 16 MiB |
| Legacy run instances | 64 maximum |
Account CPU, memory, disk, active-session, and expiry policy are returned by
jio usage rather than fixed in the client.
Common status codes
| Status | Meaning | Safe response |
|---|---|---|
400 | Invalid input or unsupported shape | Correct the request; do not retry unchanged |
401 | Missing, invalid, or revoked API key | Re-authenticate without logging the key |
404 | Resource or endpoint not found | Confirm the endpoint and session ownership |
409 | Lifecycle conflict, quota, or worker state | Refresh current state before deciding |
410 | Session expired | Stop using the ID; cleanup may still be pending |
412 | Session generation changed | Read the current generation, then reconsider |
428 | Required generation fence missing | Update the client or send If-Match |
503 | Operation unavailable; outcome may be unknown | Reconcile state before retrying |
Error responses use a bounded JSON object:
{
"error": "human-readable message"
}Retry rules
- Retry reads with bounded exponential backoff.
- Retry a create or lifecycle request only with the same idempotent identity.
- After a timeout or
503, inspectjio listorGET /v0/sessions/{id}first. - Never assume a local SSH timeout cancelled the guest process.
- Make destroy part of success, failure, signal, and worker-shutdown paths.