Go Flipbooksby CrownThrive
Legal and policy center

agreement

API Terms

Current asset API boundaries, credential controls, quotas, attribution, and replay protection.

Version
2026-08-30
Canonical URI
/legal/api-terms
Fingerprint
SHA-256 81fce3b2fe92ce028f6fe299fdb4d02f679c31d22ed1b6aea8c7ab6bb3de75b2
01

Credentials

The current developer Bearer surface is limited to tenant-bound asset registration and metadata reads with operator-pre-provisioned live credentials. Bearer activation is a separate operator-controlled deployment switch, and the runtime rejects clients whose owner lacks either an immutable external subject or a matching canonical-provider verification receipt in the append-oriented audit chain. Self-service credential listing, issuance, rotation, and revocation remain unavailable until their request-bound identity and strong-authentication controls are implemented.

02

Business effects

Asset mutations use replay-protected request IDs, correlation data, exact storage readback, and post-commit reconciliation. Reusing an X-Request-Id is rejected; it does not replay an earlier result. A successful transport response is not proof of any separate provider or economic effect.

03

Access limits

Publication, analytics, rights, license, order, organization, embed, and outbound-webhook resource scopes are reserved and not operational. Test credentials cannot use the production data plane. Invalid scopes, revoked credentials, tenant mismatches, and quota violations fail closed.