API usage policy
Requirements that partners using the KiTbetter Partner API must follow.
1. API key responsibilities
- An API key is a per-partner credential, and the partner is responsible for storing and using it securely.
- Keys must not be exposed in client-side code, public repositories, or anywhere else a third party can reach them — see Key management & security.
- If a key is known or suspected to be leaked, the partner must revoke and reissue it immediately and notify the Company. Calls made with a leaked key may be treated as the partner's own use.
2. Respect rate limits
- Partners must stay within their assigned rate limits.
- On a
429response, partners must adjust their retry interval according toRetry-After. Using multiple keys or generating abnormal traffic to circumvent limits is prohibited. - If you need to make high-volume calls, arrange it in advance through our support channels.
3. Data use & redistribution
- Data provided through the API may be used only within the scope of the integration agreed with the Company.
- Selling, sublicensing, or bulk-redistributing that data to third parties, or restructuring it into a separate database offered as an independent service, is prohibited.
- Personal data obtained through member integration must be handled in accordance with applicable law and the Privacy policy, and destroyed without delay when the integration ends.
4. Suspension & revocation
The Company may suspend or revoke API key access in the following cases, with prior notice (or notice after the fact in urgent cases).
- Violation of this policy or the Terms of service
- Repeated or deliberate breach of rate limits, or attempts to circumvent them
- Violation of the redistribution ban, or use beyond the purpose for which the data was obtained
- Failure to act on a leaked key, or a confirmed security concern
- Abnormal traffic that harms the service or other partners