Get started

Limits and safety

How Invx keeps a runaway agent in check, what your agent hears back when a call is refused, and how your data is protected.

Rate limits#

Per key or connected app:

LimitAllowance
All tool calls120 per minute
Write calls30 per minute, on top of the overall limit

Past a limit, a call returns Rate limit exceeded, retry in <n>s. Repeated calls with an invalid key or token from one network address are limited as well.

Errors#

A refused call is a normal tool result marked as an error, with one sentence your agent can act on:

MessageMeaning
This credential is read-only and cannot call this tool.Use a key with read and write access.
Rate limit exceeded, retry in <n>sWait and retry.
Invalid input. Check these fields: …The named fields are missing or malformed.
Client not found. Call list_clients to find the id.Look the id up instead of guessing it.
Company settings required. …Fill in your business details in Invx first.
Something went wrong. Try again.A server error. Check the result with a read tool before retrying a write.

Error messages never echo back the values that were sent.

Safety#

  • Your account only. Every call is scoped to the account that owns the key or approved the connector.
  • Confirmed deletes. Deleting an invoice needs its exact invoice number; deleting a client needs its exact name. A mismatch deletes nothing.
  • Issued invoices are frozen. Editing a client or your business details never rewrites invoices already issued.
  • Customer text is data, not instructions. Every tool tells the agent to treat names, addresses and descriptions as text to display, never as instructions to follow.
  • PDF links are private. get_invoice_pdf_link returns a link that only works in a browser signed in to Invx.
  • Audited. Every tool call is logged with the tool, the credential, the record id, the outcome and the duration, never with invoice or client contents.