This page is an informational summary. The canonical API Terms live at
ebrc.in/api-terms and govern if anything here
reads differently. Holding or using an API key is acceptance of them.
The rules, in plain language
- Keys and attribution. Every call made with your account’s key is your instruction, whoever in fact made it. Keys are shown once, non-transferable, and yours to safeguard; replacements are issued on request through support.
- Fair use. The published rate limits and the free general-use allowance form part of the terms. Circumventing limits, including by key rotation or distributed calling, is a material breach.
- Environments. Nothing in the sandbox is legally binding, and sandbox artefacts must not be presented as real certificates. Production access follows the NDA and production agreement, e-signed in the console, and every certificate records the environment that produced it.
- End-customer mandates. Filing for an exporter entity requires that entity’s own recorded authorisation, granted at its connection step. A platform must be able to evidence the mandate for every entity it files for.
- Data. What you submit or retrieve is your (or your customer’s) content; personal data within it is handled under the Privacy Policy. You warrant the DPDP notices and consents behind any end-customer data you transmit.
- Prohibited. Misrepresenting identity or authority, filing without a mandate, reselling raw API access without a written agreement, publishing benchmarks without consent, and security testing outside coordinated disclosure to amin@eximfiles.io.
- Change and precedence. The API evolves with reasonable notice of breaking changes and carries no SLA unless a signed agreement says otherwise. If documents conflict: signed agreement, then API Terms, then Terms of Service, then this documentation.
Read the full text
- API Terms, the canonical document
- Terms of Service
- Privacy Policy