Help Centre Contact Sales
Sign in
Noxtill
Skip to content
LEGAL

API & Integration Terms

API keys, external provider access, rate limits, data flow, webhooks, credential revocation, responsibility and integration permissions.

Version
1.0
Last updated
October 10, 2026
Reading time
2 min

Noxtill LLC · API & Integration Terms · Version 1.0 · noxtill.com/legal/api-terms

AT A GLANCE

  • Authorization and scope

    A Customer is responsible for authorizing integrations only with accounts it lawfully controls.

  • Secrets and key security

    API credentials must be treated as secret material, rotatable and revocable; limit scopes and never expose secrets in public URLs, browser logs, AI prompts or unauthorized tickets.

  • Webhooks and retries

    External calls can fail, be delayed or be duplicated.

  • Provider availability

    Connected vendor terms, regional availability, rate limits and commercial changes are independent of Noxtill.

API keys, external provider access, rate limits, data flow, webhooks, credential revocation, responsibility and integration permissions.

A Customer is responsible for authorizing integrations only with accounts it lawfully controls. Connections are scoped to declared permission grants; unlinking stops future token use subject to provider behavior, legal holds and data already imported.

External calls can fail, be delayed or be duplicated. Use signed webhook verification, event idempotency, deterministic retries, bounded execution, audit logs and visible pending states. Never mark a payment, booking, signature or posting complete merely because an AI agent said so.

Connected vendor terms, regional availability, rate limits and commercial changes are independent of Noxtill. The Customer may incur charges directly with those vendors. Noxtill cannot guarantee third-party API uptime.

Authorization and scope

A Customer is responsible for authorizing integrations only with accounts it lawfully controls. Connections are scoped to declared permission grants; unlinking stops future token use subject to provider behavior, legal holds and data already imported.

Secrets and key security

Webhooks and retries

External calls can fail, be delayed or be duplicated. Use signed webhook verification, event idempotency, deterministic retries, bounded execution, audit logs and visible pending states. Never mark a payment, booking, signature or posting complete merely because an AI agent said so.

Provider availability

Connected vendor terms, regional availability, rate limits and commercial changes are independent of Noxtill. The Customer may incur charges directly with those vendors. Noxtill cannot guarantee third-party API uptime.

Questions about this document: support@noxtill.com · Privacy: privacy@noxtill.com · Noxtill LLC, 4539 N 22nd St, Ste R, Phoenix, AZ 85016, United States.

Related documents