API Section 01
Purpose and application
These KoolArchitect API Terms of Service govern access to and use of KoolArchitect APIs, webhooks, developer credentials, software development kits, integration endpoints, event streams, test environments, and related developer services made available by Kool&Tech.
API Section 02
Contract structure
API access is available only under an accepted KoolArchitect Order Form, Subscription Agreement, developer enrollment, integration schedule, or other written authorization. These terms supplement the Master Services Agreement and KoolArchitect Acceptable Use Policy.
API Section 03
Definitions
API includes documented application programming interfaces and related developer services. API Client means software that calls the API. Developer Credential includes keys, tokens, secrets, certificates, and OAuth clients. Customer Application means software developed or controlled by Customer that uses the API.
API Section 04
Eligibility and authority
Customer must have an active eligible subscription and all required permissions. The person enabling access represents authority to bind Customer and to authorize API processing, connected systems, service accounts, users, scopes, and data exchange.
API Section 05
Limited API license
Subject to payment and compliance, Kool&Tech grants Customer a limited, revocable, nonexclusive, nontransferable right during the applicable term to call documented APIs solely for authorized internal business purposes and approved Customer Applications.
API Section 06
Documentation
Customer must follow current API Documentation, including supported endpoints, methods, schemas, authentication, scopes, pagination, errors, idempotency, retries, webhooks, limits, and version requirements. Examples are illustrative and may require adaptation.
API Section 07
Developer credentials
Credentials must be uniquely assigned where supported, stored securely, restricted to authorized systems, protected from client-side exposure, rotated when necessary, and revoked when no longer required or suspected compromised.
API Section 08
Authentication and authorization
Customer must use supported authentication and authorization methods, validate tokens, request only necessary scopes, preserve tenant and workspace boundaries, and enforce authorization within the Customer Application.
API Section 09
Least privilege
Customer must request and maintain the minimum scopes, roles, objects, environments, and data access necessary. Broad administrative credentials must not be used where a narrower service identity or delegated scope is available.
API Section 10
Environments
Production, sandbox, preview, test, and development environments may have different data, limits, availability, features, retention, and support. Nonproduction access must not be assumed suitable for production workloads.
API Section 11
Requests and responses
Customer is responsible for valid requests, field formats, encoding, headers, identifiers, pagination, concurrency, validation, and interpretation of responses. A successful technical response does not independently confirm business approval, legal validity, or data accuracy.
API Section 12
Idempotency and duplicate prevention
Where supported, Customer should use documented idempotency controls and transaction identifiers. Customer remains responsible for preventing duplicate records, payments, messages, actions, or side effects caused by retries, timeouts, or client errors.
API Section 13
Errors and retry behavior
Customer must handle status codes, error bodies, timeouts, partial failures, pagination changes, asynchronous processing, and retry instructions. Automated retries must use reasonable backoff and must not amplify an outage or repeatedly submit invalid requests.
API Section 14
Rate limits and quotas
Kool&Tech may apply request, burst, concurrency, object, payload, storage, webhook, AI, daily, monthly, or plan-based limits. Limits may differ by endpoint, plan, environment, Customer, security condition, and infrastructure capacity.
API Section 15
Throttling and traffic management
Kool&Tech may reject, delay, queue, throttle, prioritize, or temporarily restrict calls to protect security, cost, reliability, fair use, provider dependencies, or other Customers. Customer must honor documented limit and retry signals.
API Section 16
Usage measurement and overages
API usage may be measured for operations, capacity, security, billing, abuse prevention, and plan enforcement. Overage fees, included usage, reset periods, and upgrade requirements apply only as stated in the Order Form or pricing schedule.
API Section 17
Payloads and file handling
Customer must comply with documented size, format, content-type, schema, and file restrictions. Customer must not submit malformed, malicious, excessive, encrypted-without-authorization, or unsupported payloads.
API Section 18
Webhooks and events
Customer must authenticate webhook sources where supported, protect endpoints, validate event signatures, tolerate duplicates and out-of-order events, return appropriate responses, and avoid placing sensitive information in insecure logs.
API Section 19
Event delivery
Webhook and event delivery may be delayed, retried, duplicated, filtered, or unavailable. Customer must not rely on webhook delivery as the sole control for financial, safety, legal, or irreversible actions without reconciliation and appropriate safeguards.
API Section 20
Customer Data and API data
Customer retains Customer Data and authorizes processing needed to provide API services. Customer is responsible for lawful collection, instructions, schemas, field mapping, data quality, classification, minimization, retention, exports, and downstream copies.
API Section 21
Privacy and Personal Data
API processing involving Personal Data is governed by the DPA, Privacy Policy, service configuration, Customer instructions, and applicable law. Customer must provide required notices, consents, legal basis, and data-subject handling.
API Section 22
Restricted data
Customer must not transmit passwords, complete payment-card data, private keys, highly sensitive regulated data, or other restricted information unless the applicable API, plan, security controls, and written agreement expressly permit it.
API Section 23
Security requirements
Customer must implement reasonable application security, secret management, transport protection, input and output validation, dependency management, logging controls, vulnerability handling, access review, and incident response appropriate to API risk.
API Section 24
Credential and security incidents
Customer must promptly revoke or rotate compromised credentials, contain affected applications, preserve relevant evidence, report material API-related incidents, and cooperate with reasonable investigation and remediation requests.
API Section 25
Acceptable use
All API use must comply with the KoolArchitect Acceptable Use Policy. Customer must not use the API for attacks, scraping, surveillance, spam, fraud, circumvention, competitive model training, unauthorized extraction, or resource abuse.
API Section 26
Reverse engineering and hidden interfaces
Customer must not discover or call undocumented interfaces, derive source code, extract models or prompts, bypass controls, manipulate internal identifiers, or use error behavior to obtain unauthorized information.
API Section 27
Customer Applications
Customer is solely responsible for Customer Applications, including design, testing, availability, support, user disclosures, security, permissions, legal compliance, billing, and actions performed through Customer credentials.
API Section 28
End-user responsibilities
If Customer exposes API-enabled functionality to others, Customer must maintain enforceable terms and privacy disclosures, control access, provide support, prevent misuse, and remain responsible for end-user activity under Customer credentials.
API Section 29
Third-party services
API functions may depend on Odoo, Microsoft, cloud, AI, communications, payment, identity, storage, or other providers. Their terms, limits, changes, outages, and data practices may affect API behavior and availability.
API Section 30
AI-enabled endpoints
AI-enabled endpoints may produce variable, incomplete, inaccurate, or non-unique Outputs. Customer must implement human review, context-appropriate validation, transparency, safety, and approval controls before consequential use or automated action.
API Section 31
Agents and tool invocation
API-connected agents may invoke only approved tools and scopes. Customer must implement authorization, stop conditions, transaction limits, recipient checks, traceability, segregation of duties, and human approval where appropriate.
API Section 32
API changes
Kool&Tech may add, modify, secure, limit, replace, or remove endpoints, fields, schemas, events, authentication methods, and features to improve the Platform, address risk, comply with law, respond to providers, or evolve the product.
Supported versions, compatibility expectations, migration requirements, and version identifiers will be described in Documentation where applicable. Customer is responsible for monitoring notices and maintaining compatible API Clients.
API Section 34
Deprecation
Where commercially reasonable and appropriate to the change, Kool&Tech may provide notice or migration guidance for material deprecation of generally available paid APIs. Emergency security, legal, provider, or reliability changes may require shorter or immediate action.
API Section 35
Preview and beta APIs
Preview, experimental, beta, sandbox, and evaluation APIs may change or end without notice, may have reduced controls or support, and are not subject to production SLA, warranty, compatibility, or retention commitments unless expressly stated.
API Section 36
Availability and maintenance
API availability targets, maintenance terms, status communications, and service credits apply only if expressly included in a signed SLA Schedule. No public uptime percentage is created by these terms.
API Section 37
Developer support
Support may include documented access, authentication, errors, incidents, and published API behavior according to the selected plan. Architecture, coding, debugging Customer Applications, migration, and custom integration work may require Professional Services.
API Section 38
Monitoring and enforcement
Kool&Tech may monitor API metadata, volumes, errors, authentication events, security signals, usage patterns, and provider information to operate services, enforce limits, bill usage, investigate abuse, and protect the Platform.
API Section 39
Restriction and suspension
Kool&Tech may restrict or suspend credentials, endpoints, applications, integrations, workspaces, or accounts for nonpayment, excessive use, instability, compromise, prohibited activity, legal requirements, material breach, or significant risk.
API Section 40
Termination
API rights end when the applicable subscription, Order Form, developer authorization, or agreement ends. Customer must stop calls, revoke credentials, remove secrets, disable webhooks, and complete required transition or export actions.
API Section 41
Intellectual property
Kool&Tech retains the API, Platform, Documentation, schemas, SDKs, software, designs, models, prompts, interfaces, and related intellectual property. No rights are granted except the limited API access expressly stated.
Kool&Tech may use non-confidential feedback about APIs, Documentation, and developer tools without restriction or obligation, provided Customer Confidential Information is not disclosed.
API Section 43
Warranty and disclaimers
API services are subject to the warranties and disclaimers in the controlling agreement. Kool&Tech does not guarantee uninterrupted calls, error-free responses, permanent schemas, third-party availability, or fitness for every integration or decision.
API Section 44
Risk allocation
Liability limits, excluded damages, indemnification, confidentiality, force majeure, governing law, and disputes are governed by the Master Services Agreement or other controlling contract.
API Section 45
Order of precedence
For API matters: signed amendment or Change Order; Order Form or API Schedule; SLA Schedule; DPA; Master Services Agreement; KoolArchitect Subscription Agreement; these API Terms; KoolArchitect Acceptable Use Policy; Documentation; other incorporated policies.
API Section 46
Terms updates
Kool&Tech may update these terms for future or renewed API access. Application to active paid API access follows the governing agreement, accepted renewal, change notice provisions, and applicable law.
API Section 47
Developer contact
Questions about API eligibility, authentication, scopes, limits, webhooks, versioning, deprecation, security, or support may be sent to info@koolandtech.com. Secrets and full credentials must not be included in messages.