This page lists every limit in Groundrule that a person can reach: lengths, expiry times, counts, and rate limits. Most rate limits are generous and exist to stop abuse; you’ll rarely meet them in normal use.
When a rate limit is reached, Groundrule refuses the request and says how to continue. Unless the table says otherwise, the message is “Too many attempts. Wait a few minutes and try again.” The limit resets on its own once the time window has passed. Limits counted “per network” are counted per IP address.
| What |
Limit |
| Password length |
10 to 128 characters. Common passwords, passwords of one repeated character, and passwords containing your email are refused. |
| Name |
120 characters |
| Email address |
254 characters. You can’t change it yet. |
| Email confirmation link |
Works once; expires after 24 hours |
| Sign-in link |
Works once; expires after 15 minutes |
| Password reset link |
Works once; expires after 30 minutes |
| Browser session |
30 days from sign-in |
| GitHub sign-in |
Complete the approval on GitHub within 10 minutes |
Only the newest link of each kind works. Requesting a new link replaces the old one.
| Action |
Per email |
Per network |
| Sign up |
3 an hour |
20 an hour |
| Resend the confirmation email |
3 an hour |
20 an hour |
| Sign in with a password |
10 every 15 minutes |
50 every 15 minutes |
| Request a sign-in link |
3 every 15 minutes |
20 an hour |
| Request a password reset |
3 an hour |
20 an hour |
| Open a confirmation, sign-in or reset link |
|
30 every 15 minutes |
| Change your password (signed in) |
10 every 15 minutes, per account |
|
Failed sign-ins never lock an account.
| What |
Limit |
| Workspace name, company name |
120 characters |
| Workspace URL name |
2 to 48 characters: lowercase letters, numbers, single dashes. Can’t be changed. |
| Allowed invitation domains |
20 |
| Email addresses per invitation batch |
20 (“Invite up to 20 people at once”) |
| Open invitations per workspace |
200 (“Too many open invitations”) |
| Invitation expiry |
7 days; works once |
| Sends per invitation, including the first |
5 (“This invitation was sent too many times. Revoke it and invite again later.”) |
| Time between resends of one invitation |
1 minute (“Sent less than a minute ago. Give it a moment to arrive.”) |
| Invitations sent |
50 an hour per admin, 200 a day per workspace (“You’ve sent a lot of invitations. Wait a while and try again.”) |
| Opening invitation pages |
60 every 15 minutes per network |
| Team name |
80 characters |
| Admins |
At least 1, always |
| What |
Limit |
| Token name |
80 characters |
| Token expiry |
30 days, 90 days, 1 year, or no expiry |
| Active tokens per person, per workspace |
25 (“You have 25 active tokens here. Revoke one you no longer use first.”) |
| Tokens created |
20 an hour per person |
Token from groundrule login |
Expires after 90 days |
groundrule login code |
Expires after 10 minutes |
Starting groundrule login |
20 an hour per network |
| Approval page lookups |
30 every 15 minutes per person; 60 per network |
| What |
Limit |
| Size of one uploaded scan report |
2 MB |
| Uploads per token |
60 an hour (“Too many scans uploaded. Try again later.”) |
| Uploads per workspace |
1,000 a day |
| Scans kept per repository |
The 20 most recent; older ones are removed when a new one is uploaded |
| What |
Limit |
Rule text in groundrule propose and the MCP server |
10 to 1,000 characters (“Say the rule in a sentence.”) |
--why |
1,000 characters |
--example |
2,000 characters |
| Proposals per person |
30 an hour (“Too many proposals. Wait a while and try again.”) |
| Proposals per workspace |
500 a day |
/groundrule rule in GitHub review comments |
At least 10 characters; longer rules are cut at 1,000. 60 an hour per GitHub App installation; further commands that hour are ignored. |
| Reason when rejecting a proposal |
Optional, 500 characters |
| What |
Limit |
| Describe a rule text |
10 to 2,000 characters (“Describe the rule in a sentence or two.”) |
| Title when accepting a proposal |
120 characters |
| Requirement when accepting a proposal |
2,000 characters |
| Rationale when accepting a proposal |
1,000 characters |
| What changed? note on an edit |
500 characters |
| Reason for turning a rule off |
3 to 500 characters (“Say why it’s off, in a few words.”) |
| Rules changed in one bulk action |
500 |
| Testing a check in the editor |
60 a minute per person |
| Hiding a promotion |
7, 30 or 90 days |
| Promotion threshold |
No findings for 7 days (14 before Enforce), with at least 2 scans per repository |
| What |
Limit |
| Uploaded file size |
10 MB (“Files can be up to 10 MB.”) |
| File types |
PDF, Word (.docx), Markdown, plain text (“This file type isn’t supported. Use PDF, DOCX, Markdown, or text.”) |
| PDF pages |
200 (“This PDF has … pages; the limit is 200. Split it into smaller documents.”) |
| Text in one document |
1,500,000 characters (“This document has more than 1,500,000 characters of text. Split it into smaller documents.”) |
| Paragraphs in one document |
5,000 (“This document has too many paragraphs. Split it into smaller documents.”) |
| Pasted text |
1,000,000 characters (“Paste up to a million characters.”) |
| Name of pasted text |
200 characters |
| An import you haven’t started |
Discarded after 24 hours |
| Document imports |
30 an hour per person (“Too many imports. Wait a while and try again.”) |
| Pull-request review imports |
10 an hour per person; up to 20 repositories; the last 30, 90, 180 or 365 days; at most the 2,000 newest review comments |
| Searching a connected app |
60 a minute per person |
| Listing GitHub repositories |
30 a minute per person |
| What |
Limit |
| Monthly budget |
$25 by default; any amount from $0 to $100,000 set by an admin. Resets on the 1st of each month (UTC). |
| Over budget |
Requests are refused before anything is sent: “This workspace has used $X of its $Y monthly AI budget. An admin can raise it in Settings → AI.” |
| AI drafts and descriptions |
60 an hour per person, 300 an hour per workspace (“Too many AI requests. Wait a few minutes and try again.”) |
| Instruction text sent to Draft with AI |
1,000 characters |
| Cached answers |
Kept 30 days with standard retention; none with zero retention |
More: AI settings and usage.