Run budget, limits and rights
The run budget, advanced limits, address scope, licence and forking rights, and secret references of a workflow.
Every workflow carries its own limits and rights, fixed into each version. Limits bound what a run may read and how long it may take; rights say who may run the agent, see its source or copy it. This page explains each setting in the builder's Settings tab, its range and default, and what happens when a run reaches it. It is for creators tuning a workflow before testing.
Run budget#
Settings → Run budget:
| Setting | Range | Default | Meaning |
|---|---|---|---|
| Maximum RPC calls | 1 to 64 | 16 | "The most blockchain reads one run may make. The run stops there and reports what it has." |
| Run timeout (seconds) | 1 to 120 | 60 | The whole run's time limit. |
When the budget runs out, no further steps start: "The workflow reached its read limit, so no further steps started." When the timeout passes: "The workflow reached its duration limit; no further steps started." Either way the report is failed and a buyer is not charged.
Provider identity checks, snapshot cross-checks and retries count against the budget as well as the tools' own reads. Leave some room above the reads you expect.
Advanced limits and scope#
Settings → Advanced limits and scope ("Steps, timeouts, log ranges, report size, per-tool call ceilings and which addresses a run may read"):
| Setting | Range | Default | Meaning |
|---|---|---|---|
| Maximum steps | 3 to 32 | 16 | The most steps the workflow may have, counting Inputs and Report output. |
| Step timeout (seconds) | 0.5 to 60 | 20 | The longest one step may run. |
| Maximum graph depth | 2 to 16 | 8 | "How many steps may run one after another." |
| Maximum log block span | 0 to 250,000,000 | 0 | "The widest block range one log read may cover, counted from the block the run pins. 0 turns log reads off." |
| Maximum paged requests | 0 to 5 | 0 | How many log reads and Solana address-history pages one run may request. Every such request counts, including the first. "0 turns paging off." |
| Maximum report size (KiB) | 1 to 256 | 128 | The largest report the run may produce. |
| Call ceiling for (tool) | 1 to the tool's maximum, and at most the run budget | The lower of the two | The most calls this tool may make in one run. |
| Address scope | Two options, see below | Only addresses supplied as inputs | Which addresses a run may read. |
| AI cost cap per run (US$) | Up to US$0.20; production quotes allow at most US$0.05 | US$0.05 | Only shown when the workflow has an AI analysis step. See AI analysis steps. |
What a run reports when it reaches these limits:
- a step that runs too long: "The step exceeded its 20000 ms timeout.";
- a log read wider than the span: "evm.token-activity requested eth_getLogs over 2000 blocks; the version allows at most 0.";
- one page too many: "evm.token-activity requested page 1 with eth_getLogs; the version allows at most 0 paged requests per run.";
- a tool over its ceiling: "Tool evm.token-metadata reached its declared ceiling of 11 calls."
Tools that read event logs or Solana address history need both Maximum log block span and Maximum paged requests raised. The first-party research workflows that read recent logs use a span of 10,000 blocks and 5 paged requests; those that read a contract's full history use the maximum span.
Address scope#
| Option | A run may read |
|---|---|
| Only addresses supplied as inputs | Addresses the buyer supplied as inputs, plus fixed platform contracts a tool was reviewed to read (for example a DEX factory or a lending pool). |
| Inputs plus addresses seen in captured results | The above, plus addresses that appear in results captured earlier in the same run (for example the owner an earlier step found), and addresses a tool derives from in-scope values (for example a Solana program-derived address of the input mint). |
A read outside the scope is refused, for example "evm.permissions requested 0x…, outside the input-bound address scope.", and the run fails. Log reads without an address are always outside the scope. The listing shows your scope under the workflow's permissions, so buyers know what it may read.
Licence, source and forking#
Settings → Licence, source and forking ("Who may run the agent, see its source or copy it"). "Running a hosted agent, seeing its source and copying it are separate permissions. Per-run fees pay for platform execution; AGENTEX does not collect or promise royalties on copies used outside the platform."
| Setting | Options | Shown on the listing as |
|---|---|---|
| Licence | Free text, up to 100 characters. New workflows start with "All rights reserved". | The licence name. |
| Source visibility | Private; Listed, source private; Listed, source visible | Used by the rules below. |
| Hosted use | Buyers may run the hosted agent; Only I run it | "Buyers can run it through a listing" or "Only the creator can run it". |
| Source viewing | Only me; Anyone who can see the published version | "Source is private to the creator" or "Source is publicly viewable". |
| Fork permission | Not permitted; Permitted; Permitted with attribution | "Forking is not permitted", "Forking is permitted" or "Forking is permitted with attribution". |
| Attribution notice | Free text, up to 300 characters | The notice, next to the rights. |
The rules between them:
- Showing the source to anyone needs Listed, source visible.
- Allowing forks needs the source to be viewable by anyone.
- Permitted with attribution needs an attribution notice.
With Only me, buyers still see your inputs, report sections, tools, chains, limits and permissions, but not your steps or their settings. With Anyone who can see the published version, the steps are visible too.
Studio currently offers duplication for the platform's workflow template only. Attribution you inherited from a duplicate is listed under Attribution at the top of Settings and stays with every version.
Secret references#
Settings → Secret references accepts named references (in the form secret://binding/name) that would let public web steps use a private API key kept on the server. Studio has no place to store a secret's value, no approved tool reads secret references today, and a workflow that declares one cannot pass the platform checks ("Secret references are not evaluable by the local fixture suite."). Leave this group empty.
Never put a key, password or seed phrase in a fixed value, an input name or a description. The server refuses workflows that appear to embed credentials: "The package appears to embed a credential. Secrets must be references in private bindings, never values."