BrenzuriStart free
Limits and known gaps
About this documentation

Limits and known gaps

Everything on this page is true of the code today. Where it is a gap rather than a decision, it says so.

On this page

This page lists what the API and the surrounding product do not do, as of this edition. Some are decisions and some are gaps; each row says which, and what to do instead.

Calling the API#

LimitDecision or gapWhat to do
There are no CORS headers. A web page on another origin cannot call the REST API, and the MCP server refuses an Origin that is not its own.Decision for nowCall from a server. Never put a key in a web page.
There is no pagination. GET /articles returns every article the credential can see.GapFilter with status, siteId and since.
There are no idempotency keys. Starting an article twice starts two, unless the site already has one on the subject.GapBefore retrying a start that timed out, list with status=generating. Agents and keys are protected by 409 article_exists.
There is no OpenAPI file and there are no SDKs.GapUse the field tables in Objects and the examples on these pages.
A created object comes back 200, not 201. An empty success is 204. Regenerating an illustration is 202.As builtBranch on success, not on a specific 2xx.
Public routes such as /api/v1/pricing answer 403 when a bearer header is present.As builtCall them without a credential.

Jobs and progress#

LimitDecision or gapWhat to do
MCP has no job tool and no progress notifications.GapPoll article.read until status is no longer generating.

What only a person can do#

LimitDecision or gapWhat to do
Approving, keeping a flag, comments, voices, Beats, schedules, connections, billing and settings are not available to a key or an agent.DecisionA person does them in the interface.
Keys, agent tokens, webhooks and connections are made and changed in the interface. There is no API for them.GapMake them in Developer and Connections.
A connectionId is matched as written, in its own upper-case form.As builtTake it from GET /sites/{siteID}/connections; do not lower-case it.
A key has no expiry and there is no rotation route.GapMake a new key, switch, revoke the old one.
The scopes and site of a key or agent cannot be changed after it is made.DecisionMake a new one. An OAuth agent is replaced by authorising again.

Identifiers and shapes#

LimitDecision or gapWhat to do
Ids are not cased alike: articles, claims, sources, briefs, jobs, connections and deliveries are upper-case; sites, brands, illustrations, webhooks and keys are lower-case. Webhook data.jobId and data.articleId are lower-case while the article inside is upper-case.GapCompare ids case-insensitively. Routes accept either case, except that a connectionId is matched as written.
A field that is not set is omitted, not null.As builtTreat a missing field as unset.
GET /articles/{id} has no SEO fields, no verification detail, no brief id, and quality check ids are internal.As builtDo not build logic on quality check ids.
A language version is written only in one of 22 languages, and only as an article of its own with its own approval. There is no route to write one again from the API, and no illustration of its own.DecisionAsk for versions in the brief or add them later. See Write in several languages.
thumbnailUrl on a site points at a route a key cannot call.As builtIgnore it.

Credits and limits#

LimitDecision or gapWhat to do
Rate limits are counted in memory by each engine process. A restart clears them.GapTreat 60 requests a minute as a ceiling, not a guarantee.
The 60-requests-a-minute limit is per credential. There is no workspace-wide limit.As builtSeveral keys do not share a limit.
Daily caps and allowances reset at 00:00 UTC, not on a rolling day and not in your timezone.DecisionRead resetsAt.
Site reads (5 a day) and topic checks (60 a day) are shared with people using the interface.As builtLeave room for them.

Agents over MCP#

LimitDecision or gapWhat to do
The transport is JSON-only: one message per POST, no stream, no session, no batching.As builtUse a client that supports plain HTTP MCP servers.
An agent is bound to one site. Changing the site or scopes means connecting again.DecisionAuthorise again from the client.
export.render returns Markdown as text. PDF and DOCX are made but an agent cannot download them.GapA person downloads them from the article, or use the REST export with a key.
The description of source.add says “a page or PDF”. Claim sources are read as HTML only.GapGive it a page that contains the claim as text.
A connection does not wait for an Owner to approve it. The person who signs in on the consent page decides, within their own role.As builtLimit the scopes and the cap on the consent page.

Webhooks#

LimitDecision or gapWhat to do
Rotating a secret ends the old one at once.As builtAccept a list of secrets in your receiver while you switch.
Delivery is at least once. A retry can follow a success you did not answer in time.As builtDeduplicate on the event id.
Brenzuri signs a timestamp but enforces no window. The receiver decides how old a request may be.As builtReject a timestamp more than 5 minutes from your clock.
There is no manual redeliver, except republishing an approved article.GapFix the endpoint; failed deliveries are retried for 24 hours.
Endpoints must be https on port 443 at a public address. Redirects are not followed.DecisionUse a public endpoint or a tunnel that terminates https on 443.

Delivery to a site#

LimitDecision or gapWhat to do
Brenzuri sends the whole article each time. To a custom site it cannot patch, update or unpublish anything: your site keeps the record it holds.DecisionReplace your record by articleId and version. See Deliver to a custom site.
A rewrite of an approved article updates the same WordPress post and sets it back to draft, so a post someone published goes back to draft.GapPublish it again in WordPress, after looking at the draft. See Deliver to WordPress.
The Connections form does not set a WordPress category.GapPosts take WordPress’s default category.
A custom site must accept a body of at least 8 MB when the article has a picture.As builtRaise the body limit of the endpoint and its web server.
Deliveries are at least once and a retry can arrive after a later version.As builtDeduplicate on deliveryId in the signed body and keep the highest version.
A delivery that timed out after the connection was made, or whose answer was too large, is not retried by Brenzuri.DecisionThe post may exist. A person retries it from the delivery log after looking. See Retries.
A WordPress update does not replace a featured image someone set by hand.DecisionSet the new picture by hand if you want it. The delivery log says “Kept the post’s own featured image.”