Limits
Per-plan and per-runtime caps, and which of them an Enterprise contract can raise.
The defaults below apply per workspace unless stated otherwise. VibeHost has two plans, Free and Business. Enterprise is not a third plan you can switch to. It is a contract you arrange with sales, and caps marked raisable are the ones such a contract can set higher.
Plan limits
This table is generated from PLAN_LIMITS, the same object the API enforces,
so it can't go stale. It shows both plans. An Enterprise contract negotiates
every row.
| Limit | Free | Business |
|---|---|---|
| Price | $0 / month | $20 / month or $199/yr (about $16.58/mo) per workspace |
| Static apps | 100 | unlimited |
| Storage | 5 GB | 500 GB |
| Bandwidth | 10 GB / month | 1 TB / month |
| Custom domains | 0 | 20 |
| Members | 3 | unlimited |
| Workspaces owned | 1 free workspace | Any number of Business workspaces |
| Password protection | No | Yes |
| Custom share images | No | Yes |
Over the storage cap, deploys return 402 until you free up space or upgrade.
Usage-based overage billing is not live yet, so going over is never a
charge today. Bandwidth is metered and shown on the usage card, but
nothing is blocked when you go over it.
Business is priced per workspace, not per account: one subscription
licences one workspace, so a second Business workspace is a second
$20/month subscription rather than an add-on to the first.
Business can also be billed yearly at $199/yr. That is about $16.58/mo, 17% less than twelve monthly payments.
The Free plan allows 1 free workspace you own; creating another free one returns 402 PLAN_LIMIT_EXCEEDED. Creating a Business workspace is never refused. Each one starts its own subscription.
Downgrading is not retroactive. Workspaces you already own are kept,
and only the next one you create is refused.
Apps & deployments
| Limit | Free | Business |
|---|---|---|
| Deploys per user per hour | 240 | 2,000 |
| Blob uploads per user per hour | 600 | 6,000 |
The deploy limit counts vibehost deploy, rollbacks and uploads together, per user, at the plan of the workspace you deploy to. The blob limit is separate and counted the same way. A chunked deploy, the CLI default for static apps, uploads one blob for each distinct file content (unique SHA-256) the server doesn't have yet. Files with identical content share one upload, so a first deploy of a site with more than 600 distinct files can hit the blob limit on Free while the deploy limit is barely touched. Past either limit, the API returns RATE_LIMITED (429) with a Retry-After header.
Old deployments stay until a workspace owner or admin runs vibehost gc, which keeps the last 5 per channel by default. Their bytes count toward the storage cap until then.
Tarball (deploy artifact)
| Limit | Default cap | Raisable? |
|---|---|---|
| Total archive size (compressed) | 500 MB | Yes (Enterprise) |
| Per-file size | 100 MB | Yes (Enterprise) |
| Entry count | 50 000 | Yes (Enterprise) |
| Symlinks | rejected (security) | No |
Absolute paths / .. traversal | rejected (security) | No |
Empty archive (no index.html) | rejected | No |
If you hit the entry-count cap, node_modules has almost always leaked into the build. Check what you're shipping with vibehost deploy --dry-run --json | jq '.data.fileCount'.
Custom domains
Custom domains are a Business feature, and the per-plan cap is in plan limits above. The ceilings below sit above that cap, so the plan cap always binds first.
| Limit | Default | Raisable? |
|---|---|---|
| Hostnames per app (technical ceiling) | 25 | Yes |
| Hostnames per workspace (technical ceiling) | 250 | Yes |
vibehost domain verify retries / min | 30 | Yes |
| DNS verify timeout | 3 s × 3 retries | No |
| Cert provisioning timeout | 5 min | No |
| Subdomain takeover protection | always on | No |
Redirects
| Limit | Default | Raisable? |
|---|---|---|
| Platform redirects per app | 500 | Yes |
_redirects file rules | unlimited (subject to tarball cap) | n/a |
Personal access tokens
| Limit | Default | Notes |
|---|---|---|
| Active PATs per user per workspace | 20 | Returns PAT_CAP_REACHED (409) |
| Max scopes per PAT | unlimited | Grant the fewest scopes the job needs |
| Resource binding (apps allowlist) | unlimited per PAT | |
| PAT expiry options | 30 / 60 / 90 / 365 days / never | Set at issuance |
| Plaintext shown after issuance | once, never again | Server stores sha256(plaintext) only |
API & rate limiting
| Limit | Cap | Notes |
|---|---|---|
| Anonymous reads to public deploys | not rate-limited | They still count toward your bandwidth allowance |
| Authenticated API calls per token per minute | 600 | Returns RATE_LIMITED (429); see headers for Retry-After |
| Failed auth attempts per IP per minute | 30 | Past the threshold, the IP is blocked for 5 min |
vibehost workspace invite per workspace per day | 50 | Anti-abuse |
vibehost app share-link create per app per hour | 60 | Anti-abuse |
Storage
Allowances are in plan limits above. Retention is separate:
| Resource | Free | Business | Enterprise |
|---|---|---|---|
| Log retention | 7 days | 30 days | per contract |
| Audit log retention | workspace-lifetime | workspace-lifetime | workspace-lifetime |
What happens over the storage cap is in plan limits above.
That table leaves out two details. The 402 also covers redeploys of an app
you already have live, not just new apps. And a downgrade hits you here first,
because the cap drops to the Free number while your usage stays where it was.
Build (server builds)
nextjs and node apps build inside a sandboxed server-side builder, by default or with --build server. The defaults are:
| Constraint | Cap |
|---|---|
| Build wall time | 10 min |
| RAM | 4 GB |
| Disk | 10 GB |
| Network egress | npm + GitHub allowlist |
npm install parallel jobs | 4 |
None of these apply to a static app or to --build client, because your machine does the build.
What's not a limit
- Apps don't expire on the free tier. Replit-style "Always-on" doesn't apply. Your app stays live as long as your workspace exists and you stay inside the Free storage cap (see plan limits).
- People with access to an app don't have to be in your workspace. Email grants work for outside addresses, even before the person signs up.
When you hit a limit
| Error code | What to do |
|---|---|
RATE_LIMITED | Wait the Retry-After window; check vibehost doctor for unusual CLI loops |
QUOTA_EXCEEDED | Upgrade plan, delete unused apps, or run vibehost gc to prune old deployments |
PLAN_LIMIT_EXCEEDED | Specific feature requires paid tier |
PAT_CAP_REACHED | Revoke old PATs at vibehost.com/settings/access-tokens |
TARBALL_INVALID (count exceeded) | node_modules has likely leaked into the build. Exclude it |
See errors reference for the full code list.
See also
- Runtimes lists runtime-specific constraints.
- Pricing has the feature matrix for each tier.
- Personal access tokens covers PAT-specific limits.