1.Acceptance of Terms & Eligibility
These Terms of Service ("Terms") constitute a legally binding agreement between you ("Customer", "Provider", "Consumer", or "User") and PayloadAPI ("Platform", "we", "us", or "our"). By creating an account, publishing an API, routing requests through the PayloadAPI Edge Gateway, or accessing our web interfaces, you agree to be bound by these Terms.
If you are entering into these Terms on behalf of an entity, organization, or company, you represent and warrant that you have the legal authority to bind that entity to these provisions.
2.Accounts, Organizations & Credential Security
PayloadAPI operates an organization-based tenancy model. Every application, subscription, and provider listing belongs to an Organization governed by role-based access control (RBAC):
- Identity & Authentication: Users must maintain valid contact credentials. Passkeys, session cookies, and bearer tokens must be safeguarded.
- API Keys: Edge gateway requests authenticate using app-scoped secret keys (
payload_test_...orpayload_live_...). You are solely responsible for keeping private credentials confidential. - Compromise Notification: You must immediately revoke compromised API keys through the Workspace settings console and report unauthorized access.
3.API Consumer Terms: Subscriptions, Quotas & Budgets
3.1 Hard Quotas by Default
To protect consumers against unexpected overage charges, all plans enforce hard request and meter caps by default at the edge data plane. When quota is exhausted, the edge gateway returns HTTP 429 (PX_QUOTA_EXCEEDED) without upstream execution.
3.2 Explicit Overage & Budget Controls
Overage billing is never enabled automatically. A consumer must explicitly opt into overages in their Workspace and specify an absolute monthly budget cap. If the monthly budget cap is reached, further requests are denied until quota resets or the cap is adjusted.
3.3 Meter Accuracy
Metering operates on defined dimensions including requests, input tokens, output tokens, compute seconds, megabytes transferred, and result items. Telemetry is deduplicated with cryptographic idempotency keys.
4.API Provider Obligations & Verification Gauntlet
4.1 Listing and Verification
Publishing an API to the verified marketplace is free. Prior to public visibility in the catalog, every API submission must pass the automated and specialist verification gauntlet:
- Upstream Safety & SSRF: Upstream targets are validated against internal IP blocklists, private networks, and routing loops.
- Specification Conformance: OpenAPI, AsyncAPI, GraphQL, or MCP schemas are syntactically and semantically validated.
- Domain Provenance: Providers must verify DNS domain ownership of target upstreams.
- Live Endpoint Health: Real-time synthetic probes evaluate latency, error rates, and TLS handshake security.
4.2 90-Day Deprecation Notice
Providers agree not to introduce breaking changes without publishing a parallel major version and providing at least ninety (90) days of advance deprecation notice to active subscribers.
5.Platform Pricing & Transparent Commission Structure
PayloadAPI commits to a transparent commercial model without hidden fees or pay-to-win mechanics:
Commission Rate: PayloadAPI retains exactly 10% of the API subtotal on paid subscriptions and metered usage, excluding applicable taxes, payment processor fees, and refunded amounts. There are no monthly listing subscriptions for providers.
No Paid Ranking: Catalog ranking, trust scoring, and search results are computed solely from verified operational telemetry, uptime, latency, specification freshness, and real buyer reviews. Paid placement is strictly prohibited.
6.Data Processing, Request Capture & Privacy
6.1 Default 7-Day Encrypted Capture
To facilitate debugging, operational visibility, and auditability, request and response payloads passing through the Edge Gateway are captured in encrypted storage for a default retention period of 7 days.
6.2 Automated Redaction & Zero-Knowledge Encryption
- Header & Token Stripping: Authorization headers, bearer tokens, API keys, cookies, and payment card numbers are permanently redacted prior to persistence.
- Isolated Keys: Stored payloads are encrypted with per-organization encryption keys in dedicated regional buckets.
- Irreversible Deletion: Payloads are permanently and automatically purged upon expiration of the 7-day window.
6.3 Total Capture Opt-Out
Buyers have full sovereign control to disable request and response body capture entirely, or to customize capture rules at the Organization, Application, API, or Endpoint level.
7.Acceptable Use Policy & Prohibited Conduct
Users of the marketplace and edge gateway agree not to:
- Distribute malware, trojans, ransomware, or malicious exploits via API payloads.
- Execute carding attacks, fraud, botnet amplification, or unauthorized credential stuffing.
- Attempt to bypass Durable Object rate limits, edge quotas, or security boundaries.
- List duplicate, pirated, or deceptive API specifications that infringe on third-party rights.
- Scrape, reverse engineer, or decompile the edge data plane or gateway proxy infrastructure.
8.Billing, Disbursements & 7-Day Self-Serve Refund Policy
8.1 7-Day Self-Serve Refunds
Consumers may request a full refund within seven (7) days of subscribing to any paid API plan, provided that less than 10% of the included quota has been consumed. Self-serve refunds are processed immediately to the original payment method.
8.2 Provider Disbursement Schedules
Provider net earnings are settled according to platform trust profiles:
- Verified Low-Risk Providers: 90% paid on a rolling T+7 schedule, with 10% held in a 28-day rolling reserve.
- Standard / New Providers: Disbursed at T+28 following completion of initial compliance and dispute periods.
9.Service Level Agreements & Reliability Credits
PayloadAPI targets 99.95% monthly availability for the edge data plane gateway. Verified SLA breaches by third-party providers with published uptime commitments trigger automated prorated billing credits applied to the consumer's next billing cycle.
10.Intellectual Property & Proprietary Rights
Providers retain all copyright, patent, trademark, and trade secret ownership in their backend services and API implementations. By publishing an API, providers grant PayloadAPI a worldwide license to proxy, inspect, route, and generate client documentation for registered endpoints.
11.Limitation of Liability & Warranty Disclaimers
Except as expressly provided in writing, the platform is provided on an "AS IS" and "AS AVAILABLE" basis. To the maximum extent permitted by applicable law, PayloadAPI disclaims all implied warranties, including merchantability, fitness for a particular purpose, and non-infringement.
In no event will PayloadAPI be liable for indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, or business opportunities.
12.Suspension, Termination & Support Contacts
PayloadAPI reserves the right to suspend or terminate accounts that engage in severe terms violations, fraud, or malicious activity. For questions regarding these Terms or compliance matters, contact:
- Legal & Compliance:
legal@payloadapi.com - Support Console: Available in the Workspace under Support & Help
- Security Inquiries:
security@payloadapi.com