Limits
What Mast counts, what each plan allows, and what happens at the edges: a sender that posts too fast, a key that turns up in a public commit, a probe pointed at a name that no longer exists, and a card that stops going through.
Channels and keys
Every channel has one live key, the secret part of its send URL. Rotating a key issues a new one and leaves the old one working for seven days, so for that week the channel holds two.
| Plan | Channels | Keys |
|---|---|---|
| Free | 5 | 10 |
| Solo | 100 | 500 |
| Team | 100 | 500 |
| Company | 100 | 500 |
If you bought the Mast Pager app, you get at least 100 channels and 500 keys whatever plan the account is on, and the same without an account at all.
Archived channels don't count. Keys count while they can still send: the live one, and an old one inside its seven-day overlap.
At a cap, creating a channel (or un-archiving one) answers 402 with code plan_limit, and the message names the cap and the plan:
{
"error": {
"code": "plan_limit",
"message": "The Free plan allows 5 channels and this account has 5. Nothing was deleted; remove one or upgrade to add more.",
"limit": 5,
"used": 5,
"plan": "Free"
}
}Rotating is never refused. At the key cap, a rotation retires the old key on the spot instead of giving it the seven-day overlap, and the response carries "grace_skipped": "key_cap" so a script can tell. Update the sender straight away in that case.
After a downgrade
Moving to a plan with lower caps deletes nothing. Every channel you already have keeps its key and keeps accepting sends. What changes is that new channels are refused until you are under the cap, and the account owner gets one page saying how many channels and keys the account holds against the new plan's numbers.
How fast you can send
Each channel key takes 60 sends a minute, and one owner takes 600 a minute across all their keys. Past either, the send answers 429 Too Many Requests with Retry-After: 1.
On a vital, an over-limit send still counts as a beat. The vital's last-beat time moves (at most once every 15 seconds) and the body is dropped, so a job stuck in a tight loop is shown as alive, not as a flatline. The answer says so:
{
"error": {
"code": "rate_limited",
"message": "Too many sends to this channel. The beat was counted and the body dropped.",
"counted": true,
"body_dropped": true
}
}On an ordinary channel an over-limit send is dropped and the answer has no counted field.
A key in a public commit
Mast keys have a fixed shape, mk_ and 40 hex characters, and GitHub's secret scanning looks for it in public repositories. When GitHub reports one of your keys, Mast:
- revokes it at once, with no seven-day overlap,
- issues the channel a new key,
- pages you on that channel: "One of your Mast keys was found in a public commit at url. It has been rotated; update the sender."
Nothing is paused and nothing else changes. The channel keeps paging with its new key, which the app shows the next time it syncs. Anything still posting the old key gets 404 until you give it the new URL.
A key that was already revoked when it turned up is left alone.
Probes that pause themselves
A probe pauses on its own in two cases. Either way the reason shows on the probe, and resuming it from the dashboard starts it checking again.
The target is gone. If every check for 7 days fails because the name doesn't resolve or there is no route to it, the probe pauses as unreachable and the account owner gets one email. A target that answers with an error, times out or refuses the connection is down, not gone, and keeps being checked and paged.
Nobody signs in. An account with no sign-in for 83 days gets an email saying its probes pause in 7 days. At 90 days, and never less than 7 days after that email, the probes pause as inactive and a second email says so. Signing in resumes them within the hour. Where an account has never signed in on the web, its last API token use stands in for a sign-in, and the email says which one it went by.
Vitals and channels aren't affected by either.
When the card fails
A declined renewal changes nothing for 14 days. After 14 days past due:
- escalation stops after the first page: the page to you goes out, and the steps that would hand it to someone else don't,
- probes pause, with the reason
billing.
The pager keeps paging. Every send to a channel you own, and every vital's page to you, reaches your phone the whole time. When the card goes through, escalation comes back and the probes resume within the hour. Nothing is deleted. Billing has the rest.