Apidoor
Terms and Conditions
Last Updated:
Version: 1.1
Welcome to Apidoor. These Terms and Conditions are a binding agreement between you and the person or entity that operates Apidoor. They govern your access to and use of Apidoor websites, applications, documentation, API gateway, subscriptions, and related services.
Apidoor is built for developers, independent businesses, and teams that provide APIs to their own customers. In these Terms, the person or business that creates an Apidoor account is the seller. A seller's customer is a person or business that uses the seller's API. Sellers subscribe to Apidoor. Their customers do not become Apidoor subscribers merely because their requests pass through the service.
By creating an account, selecting a subscription, clicking an action that refers to these Terms, or accessing or using the service, you agree to these Terms. If you use Apidoor for a business or other organization, you represent that you have authority to accept these Terms for that organization. If you do not agree, do not create an account or use the service.
1. Apidoor and You
Apidoor is the service provider under these Terms. References to Apidoor, we, us, or our mean the person or entity that operates the Apidoor service. References to you or your mean the seller accepting these Terms and, when applicable, the business or organization that seller represents.
Questions about these Terms may be submitted through a support channel made available in the service or through the Apidoor website. Legal notices from Apidoor may be delivered through the service, to the email address associated with your account, or by another reasonable electronic method. You are responsible for keeping your account contact information current.
2. Definitions
- Account Data means information used to create, authenticate, administer, support, or bill an Apidoor account.
- API Traffic means requests and responses transmitted through an Apidoor gateway for a seller's API.
- Customer means a person or business that receives access to a seller's API. A customer belongs to the seller, not to Apidoor.
- Documentation means the seller guides and technical information Apidoor makes available for the service.
- Seller Data means project configuration, customer records, domains, API key records, access settings, and other information a seller submits to or creates in the service.
- Service means Apidoor websites, dashboard, documentation, API gateway, subscriptions, and related features.
- Usage Data means operational records about API Traffic, such as request time, method, request path, status, latency, project, API key, customer attribution, and outcome.
3. Eligibility and Authority
You must be at least 18 years old and legally capable of entering into a binding agreement. Apidoor is intended for commercial and professional use. You may use it as an individual seller or on behalf of a business, but you may not create an account for someone else without authorization.
You may not use the service if applicable law prohibits you from receiving it, if your account was previously terminated for material abuse, or if you are acting for a person or organization that is prohibited from using the service.
4. The Apidoor Service
Apidoor places a managed gateway in front of a seller's existing API. Depending on the seller's plan and the features currently released, the service may provide project gateway addresses, customer API keys, request forwarding, monthly request limits, short-window rate limits, usage analytics, exports, alerts, route controls, access labels, webhooks, browser-origin controls, and verified custom gateway domains.
Apidoor does not create or operate the seller's upstream API. It is not a marketplace for the seller's API, does not promise that the seller will earn revenue, and does not collect payments from the seller's API customers unless a separate written service expressly says otherwise. Features, plan availability, and supported behavior are described in the service and Documentation.
You receive a limited, nonexclusive, nontransferable, and revocable right to access and use the service during your account term in accordance with these Terms and the Documentation. No ownership interest in Apidoor is transferred to you.
5. Accounts and Security
You must provide accurate account information and protect your sign-in methods and authorized devices. Do not share account credentials. If the service expressly enables separate team or authorized-user access, each person must use their own access method and you are responsible for managing that access. You are responsible for activity performed through your account unless it results directly from Apidoor's breach of these Terms. Notify Apidoor promptly if you suspect unauthorized account access or compromised credentials.
- Keep upstream verification secrets, API keys, billing access, and account credentials confidential.
- Do not place secrets in public source code, public documentation, support messages, or other locations where unauthorized people can obtain them.
- Distribute customer API keys only to their intended recipients. Revoke and replace a key when compromise is suspected, and deactivate or revoke it when access is no longer needed.
- Use separate test credentials and low-risk projects when validating a new configuration.
Apidoor may suspend or revoke credentials, or require you to replace them, when reasonably necessary to protect the service, a seller, a customer, or another person.
6. Projects, Upstream APIs, and Domains
You represent that you own or have all rights and permission needed to connect each upstream API, route API Traffic to it, configure access controls for it, and use each project name, hostname, domain, trademark, and other identifier you provide. You remain responsible for the upstream API, its content, its availability, its security, and its compliance with law and third-party agreements.
- Do not configure an upstream that you are not authorized to use.
- Do not use Apidoor to bypass another service's authentication, license, geographic restriction, security control, or usage limit.
- Do not configure Apidoor as an open proxy or as a way to reach arbitrary, private-network, local, or infrastructure-management destinations.
- Keep upstream security controls in place so requests cannot bypass the intended Apidoor gateway path.
- Test request forwarding, error handling, access rules, quotas, and fallback procedures before relying on a project for production traffic.
For a custom gateway domain, you must control the hostname and maintain the required DNS records. Domain verification, certificate issuance, renewal, and DNS propagation depend on external systems and may take time or fail. Apidoor may pause or remove a domain after failed validation, loss of plan entitlement, removal, infringement, impersonation, phishing, or other abuse. A standard Apidoor gateway address remains available only where the service and Documentation say it does.
7. Authorization to Process API Traffic
You direct and authorize Apidoor and its service providers to receive, transmit, and transiently process API Traffic as needed to operate the gateway. This includes applying authentication, quotas, rate limits, route controls, browser-origin rules, configured headers, webhooks, and other seller-selected controls. It also includes creating Usage Data and inspecting or blocking traffic when reasonably necessary for security, abuse prevention, legal compliance, troubleshooting, or protection of the service.
You are responsible for obtaining every notice, consent, contractual right, and other legal basis required for Apidoor to process API Traffic and related data under your instructions. You must not direct Apidoor to intercept or process communications that you are not legally authorized to handle.
8. Your Relationship With API Customers
You, not Apidoor, provide your API to your customers. You are solely responsible for your customer agreements, pricing, invoices, collections, refunds, taxes, support, service commitments, privacy notices, data rights, acceptable-use rules, and disputes. Apidoor is not a party to those customer relationships and is not your partner, agent, reseller, merchant, employer, fiduciary, or payment processor for them.
- Explain to customers how their API requests and related data are processed.
- Issue API keys only to authorized customers and apply limits that are appropriate for your API.
- Respond to customer support, privacy, billing, refund, and legal requests relating to your API.
- Ensure your API, customer content, responses, and business practices comply with applicable laws and do not infringe another person's rights.
- Do not state or imply that Apidoor endorses, certifies, guarantees, or sells your API.
9. Subscriptions, Billing, Cancellation, and Taxes
Apidoor may offer a Free plan and paid subscription plans. Current prices, billing frequency, features, allowances, and renewal information are shown before purchase in the application. Paid plans are billed in advance and automatically renew for successive billing periods until canceled. You authorize Apidoor and its payment service providers to charge the payment method associated with your account for recurring fees and applicable taxes.
You may cancel a paid subscription using the cancellation method Apidoor makes available for that subscription, which may include an application billing control or an Apidoor support channel. Unless the purchase flow states otherwise, cancellation takes effect at the end of the current paid billing period and paid access continues until that date. Deleting a project or discontinuing gateway use does not by itself cancel a subscription.
Except where required by law or expressly stated in writing at purchase, fees are nonrefundable and Apidoor does not provide credits for partial billing periods, unused allowances, or unused features. Fees exclude taxes unless shown otherwise. You are responsible for applicable sales, use, value-added, withholding, and similar taxes other than taxes based on Apidoor's net income. Apidoor may collect taxes when required.
Apidoor may change plan prices with advance notice appropriate to the change and applicable law. A price change applies no earlier than the next renewal identified in the notice. Payment failures may result in retries, restricted billing actions, downgrade, suspension, or termination according to the subscription status reported to Apidoor. You remain responsible for accrued charges.
10. Plans, Allowances, Limits, and Retention
Each plan may limit projects, active API keys, accepted gateway requests, retained usage history, or access to particular features. Current limits are shown in the application and Documentation. Plan allowances apply to the seller account, while a seller-defined API key quota applies only to that key. Short-window rate limits are separate from monthly allowances and quotas.
- An accepted request counts after a valid and active key passes the applicable checks and is accepted for forwarding, even if the upstream later returns an error or times out.
- A request blocked because a credential is missing, invalid, inactive, revoked, or already over an applicable limit does not count as an accepted gateway request.
- Monthly allowances and monthly API key quotas use the UTC calendar-month boundaries described in the Documentation.
- When an account-wide plan allowance or an API key quota is reached, Apidoor may reject additional requests with an appropriate limit response until the limit resets or the applicable limit or plan changes.
- Apidoor does not automatically charge usage overages unless a purchase flow and separate written terms expressly provide for them.
Request-level Usage Data is made available to you according to the usage-history window included in the current plan. Data may remain in operational systems after it leaves that visible window, but you must not assume that unavailable data is retained or recoverable. An upgrade does not guarantee that data outside a prior plan's window will become available. A downgrade may apply a shorter usage-history window and lower allowances when it becomes effective. Existing resources are not deleted solely because of a plan change. Creation or reactivation above the new resource limits may be blocked, while existing projects and keys continue working subject to the new monthly request allowance and feature entitlements. You are responsible for exporting information you need to keep.
11. Feature Controls and Seller Configuration
You are responsible for understanding and testing every setting you enable. Access controls reduce risk but do not replace secure upstream authentication, authorization, validation, monitoring, or business continuity practices.
- Browser-origin controls affect browser behavior. They are not authentication and do not stop non-browser clients.
- Route controls supplement API key authentication. When required state cannot be confirmed, Apidoor may reject a request rather than risk unauthorized forwarding.
- Webhook delivery can be delayed, retried, duplicated, or received out of order. Verify webhook signatures and make receivers idempotent.
- Usage analytics and CSV exports are operational information. They are not guaranteed accounting, tax, invoicing, or customer-billing records.
- Alerts are a convenience and may be delayed or missed. You remain responsible for monitoring usage, limits, credentials, and service health.
12. Seller Data, API Traffic, and Usage Data
As between you and Apidoor, you retain your ownership rights in Seller Data, your upstream API, API Traffic, your names and marks, and your customer relationships. These Terms do not transfer ownership of that material to Apidoor.
You grant Apidoor a worldwide, nonexclusive, limited right to host, copy, transmit, display, modify for technical formatting, and otherwise process Seller Data and API Traffic only as reasonably needed to provide, secure, maintain, troubleshoot, and support the service, enforce these Terms, comply with law, and follow your documented instructions. This right ends when the relevant data is deleted, except for temporary backups, legal retention, security records, and rights that must continue to complete an authorized action.
Apidoor may create and use aggregated or de-identified operational statistics that do not identify a seller, customer, or individual. Apidoor will not treat your API payloads as its own content or use them to train a general-purpose artificial intelligence model under these Terms.
13. Privacy, Security, and Sensitive Data
Apidoor may process Account Data, Seller Data, Usage Data, website usage information, support information, and billing-related information to operate, secure, administer, support, and improve the service. Apidoor processes API Traffic only as needed to provide the gateway, follow your instructions, troubleshoot, protect the service, and comply with law. API request and response content necessarily passes through the gateway, but Apidoor does not intentionally store request or response bodies as ordinary usage-history records. Your access to request-level Usage Data is governed by the usage-history window included in your plan.
Apidoor uses reasonable administrative, technical, and organizational measures appropriate to the service, but no online system is perfectly secure. You are responsible for deciding whether the service is appropriate for your data and risk profile, minimizing the data you send, configuring your upstream securely, and meeting your own privacy and security obligations.
Unless Apidoor expressly agrees in a separate written agreement that covers the relevant workload, you must not use the service to process protected health information subject to a business associate agreement, complete payment-card numbers, card security codes, PINs, magnetic-stripe or chip authentication data, account passwords, government identification numbers, highly sensitive financial credentials, data collected from children under 13, biometric or genetic identifiers, precise location data, or other data subject to specialized legal or security requirements that the service is not documented to support.
These Terms are not a complete privacy notice or data processing addendum. If applicable law requires a separate privacy notice, data processing agreement, security schedule, or subprocessor disclosure for your use, you must obtain it from Apidoor before sending the affected data.
14. Acceptable Use
You may use Apidoor to provide and protect APIs that you are authorized to operate. You may not use the service, directly or indirectly, to do any of the following:
- Break the law, violate sanctions or export controls, infringe intellectual property or privacy rights, or facilitate fraud.
- Distribute malware, phishing content, spam, stolen credentials, unlawful surveillance, or material intended to harm people or systems.
- Access, probe, scan, test, or exploit an account, system, network, API, domain, or data without authorization.
- Interfere with the service, create a denial of service, impose an unreasonable load, or evade quotas, rate limits, plan restrictions, or security controls.
- Use another seller's account, project, API key, customer record, usage data, or configuration without permission.
- Resell access to Apidoor itself as a standalone or competing gateway service. This restriction does not prevent you from providing your own API to customers through Apidoor.
- Misrepresent your identity, your authority, your affiliation with Apidoor, or the source or destination of traffic.
- Use the service for emergency response, life-support, weapons control, or another safety-critical purpose where interruption or incorrect operation could reasonably cause death, personal injury, or severe physical damage.
Apidoor may investigate suspected abuse and preserve relevant information as permitted by applicable law and Apidoor's privacy commitments. Apidoor may disclose information only as described in the Confidential Information section, an applicable privacy notice or agreement, or as otherwise permitted or required by law. Reporting a good-faith security issue through an authorized channel is not prohibited by this section.
15. Third-Party Services
Apidoor relies on third-party providers for functions such as account access, billing, hosting, networking, storage, domain validation, certificates, email, monitoring, and analytics. Those dependencies may affect availability and performance. Apidoor may change providers when reasonably needed to operate the service.
Your direct use of a separate third-party product may be governed by that provider's terms. Apidoor is not responsible for an upstream API, DNS provider, customer system, or other third-party service that you select or control. Nothing in this section limits an obligation that Apidoor cannot lawfully disclaim.
16. Availability, Maintenance, and Service Changes
Unless Apidoor signs a separate service-level agreement with you, the service has no guaranteed uptime, response time, delivery time, or recovery objective. Maintenance, software changes, provider outages, internet conditions, DNS or certificate problems, security events, legal requirements, usage limits, and failures in your upstream or customer systems may interrupt service.
Apidoor may modify, replace, add, or discontinue features. When practical, Apidoor will provide reasonable notice of a material change that significantly reduces a paid core function. Apidoor may make immediate changes when needed for security, legal compliance, provider requirements, or service integrity.
You are responsible for monitoring your API, maintaining backups and exports, preserving your upstream access controls, and planning a recovery or fallback path appropriate to your business. Apidoor may fail closed and reject traffic when identity, entitlement, credential, quota, routing, or security state cannot be confirmed safely.
17. Preview and Evaluation Features
Apidoor may offer preview, experimental, or evaluation features. These features may be incomplete, change without the same notice as generally available features, contain defects, have limited support, or be discontinued. They are provided for testing and feedback and should not be used for production workloads unless Apidoor expressly says they are ready for that use.
Complimentary, evaluation, or promotional access does not promise future free access, a particular launch benefit, or continued availability. Apidoor will not automatically enroll a participant in a paid plan unless the participant receives the required billing disclosures and affirmatively chooses that plan.
18. Intellectual Property and Feedback
Apidoor and its licensors own the service, software, Documentation, designs, interfaces, branding, and related intellectual property, excluding Seller Data and third-party material. Except for the limited right to use the service under these Terms, no license is granted by implication or otherwise. You may not copy, modify, reverse engineer, distribute, sell, lease, or create a competing service from protected portions of Apidoor except to the extent applicable law does not allow that restriction.
If you voluntarily provide feedback or suggestions, you grant Apidoor a perpetual, worldwide, nonexclusive, royalty-free right to use that feedback to improve and promote the service without an obligation to compensate you. This does not grant Apidoor rights in your Seller Data, API Traffic, trademarks, or confidential business information merely because they are discussed while giving feedback.
19. Confidential Information
If one party discloses nonpublic information that is marked confidential or should reasonably be understood as confidential, the receiving party will use it only to perform or receive the service and will protect it using reasonable care. Confidential information does not include information that the recipient lawfully knew without restriction, receives lawfully from another source, develops independently, or that becomes public without breach.
A recipient may disclose confidential information to personnel and service providers who need it and are bound by confidentiality obligations, or when required by law. When legally permitted, the recipient will give reasonable notice before a compelled disclosure. This section does not create a promise that every item of API Traffic is retained or reviewable by Apidoor.
20. Suspension, Termination, and Data After the Account Ends
You may stop using the service at any time and may cancel a paid subscription using the cancellation method Apidoor makes available for that subscription. Account closure and subscription cancellation are separate actions unless the service clearly states otherwise.
Apidoor may restrict or suspend access immediately when reasonably necessary to address a security threat, compromised credential, illegal or abusive activity, sanctions concern, court or government requirement, nonpayment, material harm to the service or another person, or a material breach that cannot safely remain uncured. For an ordinary remediable breach, Apidoor will try to provide reasonable notice and an opportunity to cure when practical. Apidoor may terminate an account if the issue is not cured, the breach is serious or repeated, or continued service creates unacceptable legal, security, or operational risk.
When an account ends, your right to use the service ends and gateway traffic may stop. You should export information you need before termination. Apidoor may delete Seller Data and Usage Data according to its retention and backup practices, subject to legal obligations, security needs, dispute preservation, and any separate written agreement. Apidoor is not your permanent archive or backup system.
Terms that by their nature should continue after termination remain effective, including accrued payment obligations, ownership, confidentiality, disclaimers, indemnification, liability limits, dispute provisions, and general contract terms.
21. Disclaimer of Warranties
To the fullest extent permitted by law, the service is provided as is and as available. Apidoor disclaims implied warranties of merchantability, fitness for a particular purpose, title, noninfringement, and any warranties arising from course of dealing or usage of trade.
Apidoor does not warrant that the service will be uninterrupted, error free, perfectly secure, compatible with every upstream or customer system, or that every request, alert, webhook, certificate, usage record, or configuration will succeed. Apidoor does not warrant your API, your customer relationships, your compliance with law, or any business result. Nothing in these Terms excludes a warranty or right that applicable law does not allow the parties to exclude.
22. Indemnification
To the extent permitted by law, you will defend, indemnify, and hold harmless Apidoor and the people involved in operating it from third-party claims, damages, judgments, penalties, costs, and reasonable legal fees arising from your upstream API, Seller Data, API Traffic, domains, customer relationships, breach of these Terms, violation of law, infringement of another person's rights, or failure to obtain required permissions and notices.
Apidoor will give you reasonable notice of a covered claim and reasonable cooperation at your expense. You may control the defense with qualified counsel, but you may not settle a claim in a way that admits fault by Apidoor, imposes an obligation on Apidoor, or fails to release Apidoor without Apidoor's written consent. This section does not require you to indemnify Apidoor for a claim to the extent caused by Apidoor's own fraud, willful misconduct, or another responsibility that applicable law does not permit Apidoor to shift.
23. Limitation of Liability
To the fullest extent permitted by law, neither party will be liable under these Terms for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost business opportunity, business interruption, loss of goodwill, or loss of data, even if the party knew those damages were possible.
To the fullest extent permitted by law, Apidoor's total aggregate liability arising out of or relating to the service or these Terms will not exceed the greater of one hundred United States dollars or the fees you paid to Apidoor for the service during the 12 months immediately before the event giving rise to the claim.
These exclusions and limits apply regardless of the legal theory and are an essential part of the agreement, but they do not apply to liability that cannot be excluded or limited under applicable law. Some jurisdictions do not allow certain exclusions or limits, so part of this section may not apply to you.
24. Legal Compliance and Export Controls
Each party will comply with laws that apply to its own performance under these Terms. You are responsible for laws that apply to your API, customers, content, privacy practices, marketing, billing, taxes, and use of the service.
You represent that you and the people controlling your account are not prohibited from receiving the service under applicable trade sanctions or export-control laws, and that you will not use or provide the service in a prohibited destination or for a prohibited end use. Apidoor may restrict access when reasonably required to comply with those laws.
25. Governing Law and Disputes
Before filing a formal claim, each party agrees to give the other a written description of the dispute and make a good-faith effort to resolve it informally for at least 30 days. This requirement does not prevent either party from seeking urgent injunctive or equitable relief when needed to prevent immediate misuse, infringement, or security harm.
These Terms and disputes arising from them are governed by applicable United States federal law and the law of the state in which Apidoor's operator is principally established, without regard to conflict-of-law principles. A claim that is not resolved informally may be brought in a court that has lawful jurisdiction over the parties and the dispute. The United Nations Convention on Contracts for the International Sale of Goods does not apply. Mandatory rights and venues that applicable law does not permit the parties to change remain unaffected.
26. Changes to These Terms
Apidoor may update these Terms as the service, law, or business changes. The current version, effective date, and last-updated date will be published with the Terms. When a change is materially adverse, Apidoor will provide advance notice through the service, account email, or another reasonable method when practical. Changes needed immediately for law, security, or narrowly operational reasons may take effect sooner.
Changes apply prospectively from their stated effective date. If Apidoor asks you to accept updated Terms, you must do so before continuing the affected use. Otherwise, continued use after the effective date means you accept the updated Terms. If you do not agree, you must stop using the service and cancel any subscription before the change takes effect.
27. General Terms
- Entire agreement. These Terms, the applicable purchase disclosures, and any written agreement expressly incorporated into them form the agreement for the service. A signed order form, data processing agreement, or service-level agreement controls over these Terms only for its specific subject if it expressly says so.
- Assignment. You may not assign these Terms without Apidoor's written consent. Apidoor may assign them in connection with a merger, acquisition, financing, reorganization, sale of assets, or transfer of the service, subject to applicable law.
- No agency. These Terms do not create a partnership, joint venture, employment, fiduciary, franchise, or agency relationship.
- No third-party beneficiaries. These Terms do not give rights to anyone other than you and Apidoor, except an indemnified party may enforce the indemnification section.
- Severability. If a provision is unenforceable, it will be limited to the minimum extent necessary and the remaining provisions will continue in effect.
- No waiver. A failure or delay in enforcing a provision is not a waiver of the right to enforce it later.
- Force majeure. Neither party is responsible for delay or failure caused by events beyond its reasonable control, except that this does not excuse payment obligations already due.
- Headings. Section headings are provided for convenience and do not change the meaning of these Terms.
- Electronic records. You agree that these Terms, notices, disclosures, and records relating to the service may be provided electronically, subject to rights that applicable law does not allow you to waive.
28. Contact Information
For questions or concerns about these Terms, use a support channel made available in your Apidoor account or visit https://apidoor.io. Do not include passwords, full API keys, upstream secrets, payment-card data, or sensitive customer information in a support request.
29. Acceptance of Terms
By creating an Apidoor account, selecting or renewing a paid subscription, clicking an action that refers to these Terms, or continuing to access or use the service after these Terms take effect, you acknowledge that you have read, understood, and agree to them.