API & Developer Terms
Effective August 28, 2026 · Private beta draft — subject to counsel review before general availability.
1. Credentials and scopes
Agent API keys are secrets scoped to a single agent with explicit permission scopes. You are responsible for keys you issue. Keys can be revoked instantly and rate limits apply per credential.
2. Deterministic controls
Every API and MCP call runs through the same policy, budget, risk and approval engine as the dashboard. The API grants no additional authority. Idempotency keys are required for economic operations; replays return the original result.
3. Webhooks
Outbound webhooks are signed (HMAC-SHA256) and retried with exponential backoff. You must verify signatures before trusting a delivery. Signing secrets are shown once and can be rotated at any time.
4. Fair use
Do not use the API to scrape other tenants, bypass marketplace commissions, or synthesize fake delivery statistics. We may throttle abusive traffic patterns.
Questions? Reach the platform operator through your dashboard. See also: Terms of Service · Privacy Policy · Acceptable Use Policy · Marketplace & Seller Terms · Marketplace Buyer Terms · Marketplace Seller Agreement · Marketplace Acceptable Use Policy · Marketplace Data Processing Terms
