Skip to main content
The short version of the rules your integration runs under.
This page is an informational summary. The canonical API Terms live at ebrc.in/api-terms and govern if anything here reads differently. Holding or using an API key is acceptance of them.

The rules, in plain language

  • Keys and attribution. Every call made with your account’s key is your instruction, whoever in fact made it. Keys are shown once, non-transferable, and yours to safeguard; replacements are issued on request through support.
  • Fair use. The published rate limits and the free general-use allowance form part of the terms. Circumventing limits, including by key rotation or distributed calling, is a material breach.
  • Environments. Nothing in the sandbox is legally binding, and sandbox artefacts must not be presented as real certificates. Production access follows the NDA and production agreement, e-signed in the console, and every certificate records the environment that produced it.
  • End-customer mandates. Filing for an exporter entity requires that entity’s own recorded authorisation, granted at its connection step. A platform must be able to evidence the mandate for every entity it files for.
  • Data. What you submit or retrieve is your (or your customer’s) content; personal data within it is handled under the Privacy Policy. You warrant the DPDP notices and consents behind any end-customer data you transmit.
  • Prohibited. Misrepresenting identity or authority, filing without a mandate, reselling raw API access without a written agreement, publishing benchmarks without consent, and security testing outside coordinated disclosure to amin@eximfiles.io.
  • Change and precedence. The API evolves with reasonable notice of breaking changes and carries no SLA unless a signed agreement says otherwise. If documents conflict: signed agreement, then API Terms, then Terms of Service, then this documentation.

Read the full text