> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ebrc.in/llms.txt
> Use this file to discover all available pages before exploring further.

# API Terms

> What the eBRC API Terms mean for your integration: keys and attribution, fair use, environments, end-customer mandates, and prohibited integrations, in plain language.

The short version of the rules your integration runs under.

<Note>
  This page is an informational summary. The canonical API Terms live at
  [ebrc.in/api-terms](https://ebrc.in/api-terms) and govern if anything here
  reads differently. Holding or using an API key is acceptance of them.
</Note>

## The rules, in plain language

* **Keys and attribution.** Every call made with your account's key is your
  instruction, whoever in fact made it. Keys are shown once, non-transferable,
  and yours to safeguard; replacements are issued on request through support.
* **Fair use.** The published [rate limits](/authentication#rate-limits) and
  the [free general-use allowance](/pricing) form part of the terms.
  Circumventing limits, including by key rotation or distributed calling, is a
  material breach.
* **Environments.** Nothing in the sandbox is legally binding, and sandbox
  artefacts must not be presented as real certificates. Production access
  follows the NDA and production agreement, e-signed in the console, and every
  certificate records the environment that produced it.
* **End-customer mandates.** Filing for an exporter entity requires that
  entity's own recorded authorisation, granted at its connection step. A
  platform must be able to evidence the mandate for every entity it files for.
* **Data.** What you submit or retrieve is your (or your customer's) content;
  personal data within it is handled under the
  [Privacy Policy](https://ebrc.in/privacy-policy). You warrant the DPDP
  notices and consents behind any end-customer data you transmit.
* **Prohibited.** Misrepresenting identity or authority, filing without a
  mandate, reselling raw API access without a written agreement, publishing
  benchmarks without consent, and security testing outside coordinated
  disclosure to [amin@eximfiles.io](mailto:amin@eximfiles.io).
* **Change and precedence.** The API evolves with reasonable notice of
  breaking changes and carries no SLA unless a signed agreement says
  otherwise. If documents conflict: signed agreement, then API Terms, then
  Terms of Service, then this documentation.

## Read the full text

* [API Terms](https://ebrc.in/api-terms), the canonical document
* [Terms of Service](https://ebrc.in/terms-of-service)
* [Privacy Policy](https://ebrc.in/privacy-policy)
