API terms of use

Terms governing access to a company's API by developers, partners and customers, drafted for a fixed fee of £995 in five working days.

Share

API terms of use

Terms of use for an API offered to developers and businesses, drafted for how the API is accessed and what is built on it, covering registration and keys, the licence to call the API and to use the data, rate limits and fair use, the developer's applications and end users, data protection between the parties, changes and deprecation, liability and suspension, and the prohibition on misuse. £995, delivered in five working days.

Buy now, £995

An API gives other people's software access to yours, and the terms have to govern what those people build, how much they call, what they do with the data they receive, and what happens to their applications when the API changes. They also have to set the licence, deal with data protection where personal data flows in either direction, and give the provider a way to suspend access and stop misuse. I draft those terms for a fixed fee of £995, delivered in five working days.

Who this is for

Software and data businesses in England and Wales offering an API to third-party developers, integration partners and customers, whether free with a product, metered and paid, or offered to partners under a separate commercial agreement that these terms sit under.

What matters in API terms of use

Registration, keys and who is responsible

The terms should require developers to register, accept the terms for themselves or the business they act for, keep API keys and credentials confidential, be responsible for all calls made with their keys, and notify compromise promptly. Access using another party's credentials or beyond the authorisation given is an offence under section 1 of the Computer Misuse Act 1990, and the terms should say that the provider may act on it and may verify identity for paid or sensitive access.

The licence to call the API and to use the data

The developer receives a limited, revocable licence to call the API to build and operate applications that comply with the terms, and the terms should say what may be done with the responses: displayed to the developer's users, cached for a stated period, not stored beyond it, not resold, not used to train models or to build a competing service unless expressly permitted. The provider's data may be protected by copyright and by database right under the Copyright and Rights in Databases Regulations 1997, and the terms should reserve those rights.

Rate limits, fair use and paid tiers

The terms should set rate limits and quotas by tier, say that the provider may throttle or suspend calls that exceed them or that degrade the service, define fair use for anything unmetered, and, for paid tiers, state the metering, the fees, when they are invoiced and interest on late payment under the Late Payment of Commercial Debts (Interest) Act 1998. Circumventing limits, scraping instead of calling the API, and automated account creation should be prohibited.

The developer's applications and end users

The developer is responsible for its applications, for their compliance with law, for its end users and their data, and for not misrepresenting the provider's involvement, and the terms should require attribution where the provider wants it, prohibit use of the provider's marks beyond stated guidelines under the Trade Marks Act 1994, require the developer to have its own privacy notice and terms with its users, and allow the provider to review and reject applications that breach the terms.

Data protection between provider and developer

Personal data may flow both ways, and the terms should say which party is controller of what: the developer is usually an independent controller of its users' data that it sends to the API, and the provider a controller of the data it holds and returns, with each responsible for its own compliance under the UK GDPR; where the provider processes data on the developer's behalf, the processor terms under Article 28 apply. Security obligations under Article 32 should be stated for both, with breach notification between them.

Changes, deprecation, suspension and liability

The provider should be able to change the API, and the terms should commit to a stated notice period for breaking changes and deprecation of versions, so that developers can adapt, while allowing immediate changes for security. The provider may suspend or terminate access for breach, misuse or non-payment, and on notice for any reason, and its liability should be capped at the fees paid or a stated sum for free access, with consequential loss excluded and the cap tested under section 11 of the Unfair Contract Terms Act 1977, because developers are businesses. English law applies and third-party rights are excluded under the Contracts (Rights of Third Parties) Act 1999.

What it costs

SaaS terms of service, £995. Your standard customer-facing terms. Five working days.

Buying online forms the engagement on payment. The scope is what the saas and technology contracts page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A bespoke contract drafted for how your product is sold, delivered and supported
  • Service levels you can meet, with remedies that are proportionate rather than aspirational
  • A liability position that is defensible and will survive enterprise procurement
  • IP and data provisions that fit together rather than contradicting each other
  • A commercial note on where you will get pushback and what is worth conceding
  • One round of amendments

What is not included

  • Negotiating individual enterprise deals, which I quote separately
  • Advice on the law of jurisdictions outside England and Wales
  • Technical security certification or audit
  • Regulatory advice for regulated sectors such as financial services or health

Questions I am often asked

A developer is storing our data and selling it on. What can we do?

If the terms limit caching to a stated period and prohibit resale, the developer is in breach and infringing your rights in the data. Suspend the key under the terms and require deletion; the database right and copyright support a claim if it continues.

Can we change the API without notice?

For security, the terms allow it. For breaking changes and deprecation, a stated notice period is what developers expect and what makes the terms reasonable. The terms set the period.

Who is responsible for a developer's app breaching data protection law?

The developer, as controller of its users' data, and the terms say so. The provider's responsibility is for the data it holds and returns, and for its own security.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.