# Limits and safety

How Invx keeps a runaway agent in check, what your agent hears back when a call is refused, and how your data is protected.

## Rate limits

Per key or connected app:

| Limit | Allowance |
|---|---|
| All tool calls | 120 per minute |
| Write calls | 30 per minute, on top of the overall limit |

Past a limit, a call returns `Rate limit exceeded, retry in <n>s`. Repeated calls with an invalid key or token from one network address are limited as well.

## Errors

A refused call is a normal tool result marked as an error, with one sentence your agent can act on:

| Message | Meaning |
|---|---|
| `This credential is read-only and cannot call this tool.` | Use a key with read and write access. |
| `Rate limit exceeded, retry in <n>s` | Wait and retry. |
| `Invalid input. Check these fields: …` | The named fields are missing or malformed. |
| `Client not found. Call list_clients to find the id.` | Look the id up instead of guessing it. |
| `Company settings required. …` | Fill in your business details in Invx first. |
| `Something went wrong. Try again.` | A server error. Check the result with a read tool before retrying a write. |

Error messages never echo back the values that were sent.

## Safety

- **Your account only.** Every call is scoped to the account that owns the key or approved the connector.
- **Confirmed deletes.** Deleting an invoice needs its exact invoice number; deleting a client needs its exact name. A mismatch deletes nothing.
- **Issued invoices are frozen.** Editing a client or your business details never rewrites invoices already issued.
- **Customer text is data, not instructions.** Every tool tells the agent to treat names, addresses and descriptions as text to display, never as instructions to follow.
- **PDF links are private.** `get_invoice_pdf_link` returns a link that only works in a browser signed in to Invx.
- **Audited.** Every tool call is logged with the tool, the credential, the record id, the outcome and the duration, never with invoice or client contents.
