Reference
Limits at a glance
Every number in one place: plans, sizes, lifetimes and caps.
Every number Gridline enforces, in one place. Plan limits are checked by the API itself, so these are exactly what you will meet.
By plan
| Free | Basic | Premium | |
|---|---|---|---|
| Price | $0 | $5 per active employee per month | $300 a month, flat |
| Files per billing period | 10 | 100 | 1,000 |
| Past the file quota | Uploads refused (402) | Uploads refused (402) | $0.50 per extra file |
| Employees | 0 | 10 | No limit |
| Quality rules | 3 | 25 | No limit |
| Versions of one file | 5 | 50 | No limit |
| Webhook endpoints | 1 | 5 | No limit |
| API requests per minute (whole company) | 30 | 120 | 600 |
Files
| Limit | |
|---|---|
| Formats | CSV, XLS, XLSX |
| Size of an upload | 25 MB |
| Size of an upload through an AI agent | 8 MB (larger files use POST /files) |
| A download link lives | 5 minutes |
| Profiled in one report | The first 100,000 rows and 200 columns |
| Preview | First 50 rows × 50 columns, cells cut at 200 characters |
| Expanded size of an XLSX | 200 MB (a guard against files that blow up when opened) |
| Files you may grant access to | 100 people per file |
People and keys
| Limit | |
|---|---|
| Password length | 8 to 128 characters |
| Access token lifetime | 15 minutes |
| Refresh token lifetime | 30 days, and single use |
| Active API keys per person | 25 |
| Comment length | 5,000 characters |
| People mentioned in one comment | 50 |
| Unique-value rules per company | 10 (on every plan) |
Requests
| Limit | |
|---|---|
| Items per page | 1 to 100 (default 20) |
| Sign-in attempts | 10 a minute per address |
| Forgot password, resend activation | 5 a minute per address |
| Plan changes | 10 a minute, in their own budget |
| Idempotency keys are remembered for | 24 hours |
| Analytics range | At most 366 days |
| GraphQL depth / cost / page size | 6 / 1,000 / 50 |
Live connections and webhooks
| Limit | |
|---|---|
| Files watched per connection | 20 |
| Watch commands | 20 per 10 seconds per connection |
| Typing events | 5 per second |
| Webhook delivery attempts | 5, with a growing delay |
| Failed deliveries before an endpoint is disabled | 20 in a row |
| Delivery history kept | 30 days |
How long things are kept
| What | Kept |
|---|---|
| Read notifications | 90 days (unread ones stay) |
| Webhook delivery history | 30 days |
| Idempotency records | 24 hours |
| The audit log | Permanently: it cannot be edited or removed |
| Files, reports and comments | Until deleted |