Skip to content

API usage policy

Requirements that partners using the KiTbetter Partner API must follow.

1. API key responsibilities

  • An API key is a per-partner credential, and the partner is responsible for storing and using it securely.
  • Keys must not be exposed in client-side code, public repositories, or anywhere else a third party can reach them — see Key management & security.
  • If a key is known or suspected to be leaked, the partner must revoke and reissue it immediately and notify the Company. Calls made with a leaked key may be treated as the partner's own use.

2. Respect rate limits

  • Partners must stay within their assigned rate limits.
  • On a 429 response, partners must adjust their retry interval according to Retry-After. Using multiple keys or generating abnormal traffic to circumvent limits is prohibited.
  • If you need to make high-volume calls, arrange it in advance through our support channels.

3. Data use & redistribution

  • Data provided through the API may be used only within the scope of the integration agreed with the Company.
  • Selling, sublicensing, or bulk-redistributing that data to third parties, or restructuring it into a separate database offered as an independent service, is prohibited.
  • Personal data obtained through member integration must be handled in accordance with applicable law and the Privacy policy, and destroyed without delay when the integration ends.

4. Suspension & revocation

The Company may suspend or revoke API key access in the following cases, with prior notice (or notice after the fact in urgent cases).

  • Violation of this policy or the Terms of service
  • Repeated or deliberate breach of rate limits, or attempts to circumvent them
  • Violation of the redistribution ban, or use beyond the purpose for which the data was obtained
  • Failure to act on a leaked key, or a confirmed security concern
  • Abnormal traffic that harms the service or other partners