set_plan_quota
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/set_plan_quota, with a bearer credential and the action's payload as the JSON body.
Contract description
Set the quantity a plan includes for one measure, with no deploy. Super-admin (platform operator) only. The measure is one of the ten enforced entries. Among them are `log-retained-capacity`, the retained-bytes bound, the eighth; `gemini-flash-allowance`, the included AI allowance in token units, the ninth; and `push-messages-capacity`, the accepted push deliveries a month, the tenth. Or it is one of the served values (`free-idle-stop`, `development-halt-after-days`, `development-realm-account-limit`, `signin-code-sends-per-hour`, an end-user realm's emailed-code ceiling an hour, thirty where Unset, and the two egress limits, `egress-connections-per-minute` and `egress-bytes-per-day`, no bound where Unset). The retired `issue-tracking-calls` is refused.
A write of `backend-actions-capacity`, `data-transfer-capacity`, or `stored-data-capacity` recomputes the plan's live applications' states against the new row before the answer: a lowered row refuses and a raised row clears within the serving router's resolve interval. The answer counts the applications whose state changed (`states_changed`). The answer names the pricing registry cell the value must also be recorded in, the registry being the value's one home. A write of `database-connection-limit` re-asserts the plan's provisioned roles at once, and each running copy takes the value at its next deploy, promote, or `restart_application`.
Access and action metadata
{
"name": "set_plan_quota",
"resource": "account",
"tier": "reversible",
"grant": "super_admin",
"summary": "Super-admin: set one served plan quantity — a (plan, measure) row of the quota table, an enforced entry or a served value (`free-idle-stop`, `development-halt-after-days`, `development-realm-account-limit`, `signin-code-sends-per-hour`, `egress-connections-per-minute`, `egress-bytes-per-day`), `quantity` in base units or null for the Unset state — with no deploy; a write of `backend-actions-capacity`, `data-transfer-capacity`, or `stored-data-capacity` recomputes the plan's live applications' states against the new row before the answer, so a lowered row refuses and a raised row clears within the serving router's resolve interval, and the answer counts the applications whose state changed (`states_changed`, zero for any other row); the answer names the pricing.md registry cell the same session records by registrar transaction, the registry staying the value's one home and the table its served copy.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": true,
"openWorldHint": false
}
}
MCP catalog entry
{
"name": "set_plan_quota",
"tier": "reversible",
"scenario": "API-L0-12",
"summary": "Set the quantity a plan includes for one measure, with no deploy. Super-admin (platform operator) only. The measure is one of the ten enforced entries. Among them are `log-retained-capacity`, the retained-bytes bound, the eighth; `gemini-flash-allowance`, the included AI allowance in token units, the ninth; and `push-messages-capacity`, the accepted push deliveries a month, the tenth. Or it is one of the served values (`free-idle-stop`, `development-halt-after-days`, `development-realm-account-limit`, `signin-code-sends-per-hour`, an end-user realm's emailed-code ceiling an hour, thirty where Unset, and the two egress limits, `egress-connections-per-minute` and `egress-bytes-per-day`, no bound where Unset). The retired `issue-tracking-calls` is refused.\n\nA write of `backend-actions-capacity`, `data-transfer-capacity`, or `stored-data-capacity` recomputes the plan's live applications' states against the new row before the answer: a lowered row refuses and a raised row clears within the serving router's resolve interval. The answer counts the applications whose state changed (`states_changed`). The answer names the pricing registry cell the value must also be recorded in, the registry being the value's one home. A write of `database-connection-limit` re-asserts the plan's provisioned roles at once, and each running copy takes the value at its next deploy, promote, or `restart_application`.",
"owners": [
"PRC-L0-16",
"PRC-L0-01",
"API-L0-12",
"ACB-L0-26",
"DBS-L0-04",
"PRC-L0-02"
]
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["plan","measure","quantity"] |
| / |
`free`, `standard`, `pro`, or `unlimited`, the company's own plan, which no customer act selects yet. Type: string Allowed values: ["free","standard","pro","unlimited"] |
| / |
One of the ten enforced entries — `stored-data-capacity`, `backend-actions-capacity`, `data-transfer-capacity`, `database-connection-limit`, `schedule-minimum-interval`, `schedule-count-limit`, `deploys-per-day`, `log-retained-capacity`, `gemini-flash-allowance`, and `push-messages-capacity`. Of these, `log-retained-capacity` is the most bytes of serialized `app`-source log entries one environment holds retained at any instant. The entry `gemini-flash-allowance` is the included AI allowance per application per UTC month, in token units, and `push-messages-capacity` the accepted push deliveries per application per UTC month, one per device a send accepts. The token units are one per input token and five per output or thinking token. Or it is one of the six served values that enforce nothing: `free-idle-stop`, `development-halt-after-days`, `development-realm-account-limit`, `signin-code-sends-per-hour`, `egress-connections-per-minute`, and `egress-bytes-per-day`. Of these, `free-idle-stop` is the seconds a cold environment stays running after its last request, the Free plan's cell governing every Free or Standard development pod. Of these, `development-halt-after-days` is the days after a development environment's last deploy or resume at which the daily pass halts it. Of these, `signin-code-sends-per-hour` is an end-user realm's ceiling on emailed sign-in codes an hour, read at each code start. Of these, `egress-connections-per-minute` is the outbound connections an application may open per UTC minute on one tunnel proxy replica. Of these, `egress-bytes-per-day` is the bytes its outbound connections and its own upstream calls may carry per UTC day, both ways; an Unset cell of either is no bound. The value is the registry entry's name verbatim. An enforced entry refuses by name when unset; a served value reads as its statement's default. The retired entry `issue-tracking-calls` is refused. Type: string Allowed values: ["stored-data-capacity","backend-actions-capacity","data-transfer-capacity","database-connection-limit","schedule-minimum-interval","schedule-count-limit","deploys-per-day","log-retained-capacity","gemini-flash-allowance","free-idle-stop","development-halt-after-days","development-realm-account-limit","signin-code-sends-per-hour","egress-connections-per-minute","egress-bytes-per-day","push-messages-capacity"] |
| / |
The quantity in base units — bytes, actions, connections each process holds for `database-connection-limit` (the role's own limit is written as twice it), minutes, a count of schedules or deploys. The units are seconds for `free-idle-stop`, days for `development-halt-after-days`, accounts for `development-realm-account-limit`, sends for `signin-code-sends-per-hour`, connections a minute for `egress-connections-per-minute`, bytes a day for `egress-bytes-per-day`, token units for `gemini-flash-allowance`, and accepted deliveries for `push-messages-capacity`. Or pass `null` to record the cell as unset. Type: ["integer","null"] Minimum: 0 |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","quota"] |
| / |
Required value: 1 |
| / |
The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call. Type: string Pattern: ^[0-9a-f]{10}$ |
| / |
Type: object Required fields: ["plan","measure","quantity","set_at","set_by"] |
| / |
The row's plan: `free`, `standard`, or `pro`, or `unlimited`, the company's own plan, which no customer act selects yet. Type: string Allowed values: ["free","standard","pro","unlimited"] |
| / |
Type: string Allowed values: ["stored-data-capacity","backend-actions-capacity","data-transfer-capacity","database-connection-limit","schedule-minimum-interval","schedule-count-limit","deploys-per-day","log-retained-capacity","gemini-flash-allowance","free-idle-stop","development-halt-after-days","development-realm-account-limit","signin-code-sends-per-hour","egress-connections-per-minute","egress-bytes-per-day","push-messages-capacity"] |
| / |
Type: ["integer","null"] |
| / |
Type: string |
| / |
the operator's account id; seed for a row the migration wrote Type: string |
| / |
the registrar operation to run: the pricing.md cell, the value, and the stamp — the registry stays the one home (PRC-L0-01). For a write of `database-connection-limit`, it also says that each running copy keeps its injected `APP_DATABASE_CONNECTION_LIMIT` until its environment's next deploy, promote, or `restart_application` (DBS-L0-04) Type: string |
| / |
Present when the measure is `database-connection-limit` and the quantity is not null: the provisioned roles of the plan's live applications whose CONNECTION LIMIT this write re-asserted, each environment's role counted once (DBS-L0-04; PRC-L0-16). The daily pass converges any role the walk did not reach (PLD-L0-67). Type: integer |
| / |
Present with `reasserted`: each role the re-assert refused, as `<application id>/<environment>: <reason>`; empty where every role moved. Type: array |
| / |
Type: string |
| / |
the count of the plan's live applications whose usage state the write changed (ACB-L0-26; PRC-L0-16). A write of backend-actions-capacity or data-transfer-capacity recomputes the plan's live applications' two traffic states against the new row before the answer. A write of stored-data-capacity recomputes their stored-data state from the daily pass's recorded figure. So a lowered row refuses and a raised row clears within the serving router's resolve interval. Zero for a write of any other row, which recomputes nothing Type: integer Minimum: 0 |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"plan",
"measure",
"quantity"
],
"properties": {
"plan": {
"type": "string",
"enum": [
"free",
"standard",
"pro",
"unlimited"
],
"description": "`free`, `standard`, `pro`, or `unlimited`, the company's own plan, which no customer act selects yet."
},
"measure": {
"type": "string",
"enum": [
"stored-data-capacity",
"backend-actions-capacity",
"data-transfer-capacity",
"database-connection-limit",
"schedule-minimum-interval",
"schedule-count-limit",
"deploys-per-day",
"log-retained-capacity",
"gemini-flash-allowance",
"free-idle-stop",
"development-halt-after-days",
"development-realm-account-limit",
"signin-code-sends-per-hour",
"egress-connections-per-minute",
"egress-bytes-per-day",
"push-messages-capacity"
],
"description": "One of the ten enforced entries — `stored-data-capacity`, `backend-actions-capacity`, `data-transfer-capacity`, `database-connection-limit`, `schedule-minimum-interval`, `schedule-count-limit`, `deploys-per-day`, `log-retained-capacity`, `gemini-flash-allowance`, and `push-messages-capacity`. Of these, `log-retained-capacity` is the most bytes of serialized `app`-source log entries one environment holds retained at any instant. The entry `gemini-flash-allowance` is the included AI allowance per application per UTC month, in token units, and `push-messages-capacity` the accepted push deliveries per application per UTC month, one per device a send accepts. The token units are one per input token and five per output or thinking token. Or it is one of the six served values that enforce nothing: `free-idle-stop`, `development-halt-after-days`, `development-realm-account-limit`, `signin-code-sends-per-hour`, `egress-connections-per-minute`, and `egress-bytes-per-day`. Of these, `free-idle-stop` is the seconds a cold environment stays running after its last request, the Free plan's cell governing every Free or Standard development pod. Of these, `development-halt-after-days` is the days after a development environment's last deploy or resume at which the daily pass halts it. Of these, `signin-code-sends-per-hour` is an end-user realm's ceiling on emailed sign-in codes an hour, read at each code start. Of these, `egress-connections-per-minute` is the outbound connections an application may open per UTC minute on one tunnel proxy replica. Of these, `egress-bytes-per-day` is the bytes its outbound connections and its own upstream calls may carry per UTC day, both ways; an Unset cell of either is no bound. The value is the registry entry's name verbatim. An enforced entry refuses by name when unset; a served value reads as its statement's default. The retired entry `issue-tracking-calls` is refused."
},
"quantity": {
"type": [
"integer",
"null"
],
"minimum": 0,
"description": "The quantity in base units — bytes, actions, connections each process holds for `database-connection-limit` (the role's own limit is written as twice it), minutes, a count of schedules or deploys. The units are seconds for `free-idle-stop`, days for `development-halt-after-days`, accounts for `development-realm-account-limit`, sends for `signin-code-sends-per-hour`, connections a minute for `egress-connections-per-minute`, bytes a day for `egress-bytes-per-day`, token units for `gemini-flash-allowance`, and accepted deliveries for `push-messages-capacity`. Or pass `null` to record the cell as unset."
}
}
},
"response": {
"type": "object",
"required": [
"contract_version",
"quota"
],
"properties": {
"contract_version": {
"const": 1
},
"reference": {
"type": "string",
"pattern": "^[0-9a-f]{10}$",
"description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
},
"quota": {
"type": "object",
"required": [
"plan",
"measure",
"quantity",
"set_at",
"set_by"
],
"properties": {
"plan": {
"type": "string",
"enum": [
"free",
"standard",
"pro",
"unlimited"
],
"description": "The row's plan: `free`, `standard`, or `pro`, or `unlimited`, the company's own plan, which no customer act selects yet."
},
"measure": {
"type": "string",
"enum": [
"stored-data-capacity",
"backend-actions-capacity",
"data-transfer-capacity",
"database-connection-limit",
"schedule-minimum-interval",
"schedule-count-limit",
"deploys-per-day",
"log-retained-capacity",
"gemini-flash-allowance",
"free-idle-stop",
"development-halt-after-days",
"development-realm-account-limit",
"signin-code-sends-per-hour",
"egress-connections-per-minute",
"egress-bytes-per-day",
"push-messages-capacity"
]
},
"quantity": {
"type": [
"integer",
"null"
]
},
"set_at": {
"type": "string"
},
"set_by": {
"type": "string",
"description": "the operator's account id; seed for a row the migration wrote"
}
}
},
"detail": {
"type": "string",
"description": "the registrar operation to run: the pricing.md cell, the value, and the stamp — the registry stays the one home (PRC-L0-01). For a write of `database-connection-limit`, it also says that each running copy keeps its injected `APP_DATABASE_CONNECTION_LIMIT` until its environment's next deploy, promote, or `restart_application` (DBS-L0-04)"
},
"reasserted": {
"type": "integer",
"description": "Present when the measure is `database-connection-limit` and the quantity is not null: the provisioned roles of the plan's live applications whose CONNECTION LIMIT this write re-asserted, each environment's role counted once (DBS-L0-04; PRC-L0-16). The daily pass converges any role the walk did not reach (PLD-L0-67)."
},
"failed": {
"type": "array",
"items": {
"type": "string"
},
"description": "Present with `reasserted`: each role the re-assert refused, as `<application id>/<environment>: <reason>`; empty where every role moved."
},
"states_changed": {
"type": "integer",
"minimum": 0,
"description": "the count of the plan's live applications whose usage state the write changed (ACB-L0-26; PRC-L0-16). A write of backend-actions-capacity or data-transfer-capacity recomputes the plan's live applications' two traffic states against the new row before the answer. A write of stored-data-capacity recomputes their stored-data state from the daily pass's recorded figure. So a lowered row refuses and a raised row clears within the serving router's resolve interval. Zero for a write of any other row, which recomputes nothing"
}
}
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md