API keys, external provider access, rate limits, data flow, webhooks, credential revocation, responsibility and integration permissions.
External calls can fail, be delayed or be duplicated. Use signed webhook verification, event idempotency, deterministic retries, bounded execution, audit logs and visible pending states. Never mark a payment, booking, signature or posting complete merely because an AI agent said so.
Connected vendor terms, regional availability, rate limits and commercial changes are independent of Noxtill. The Customer may incur charges directly with those vendors. Noxtill cannot guarantee third-party API uptime.
Authorization and scope
A Customer is responsible for authorizing integrations only with accounts it lawfully controls. Connections are scoped to declared permission grants; unlinking stops future token use subject to provider behavior, legal holds and data already imported.
Secrets and key security
Webhooks and retries
External calls can fail, be delayed or be duplicated. Use signed webhook verification, event idempotency, deterministic retries, bounded execution, audit logs and visible pending states. Never mark a payment, booking, signature or posting complete merely because an AI agent said so.
Provider availability
Connected vendor terms, regional availability, rate limits and commercial changes are independent of Noxtill. The Customer may incur charges directly with those vendors. Noxtill cannot guarantee third-party API uptime.
