API Terms
Version 1.1 — Effective August 28, 2026 (posted August 28, 2026)
Prior versions: 1.0, posted July 4, 2026.
These API Terms are provided by Oystercatcher, LLC, a Connecticut limited liability company ("Oystercatcher," "we," "our," or "us"), and govern programmatic access to the Oystercatcher platform. Programmatic access takes two forms. The first is the documented REST API (the "API"), available to customers whose subscription or Order Form includes API access (currently the Enterprise plan, or as stated in an Order Form). The second is "AI Connections": access through Oystercatcher's Model Context Protocol (MCP) server by an AI assistant (such as Claude or ChatGPT, or an AI-enabled developer tool) acting on behalf of an authorized user. AI Connections is included in subscriptions and free trials whose plan includes it (currently every paid plan and the 14-day free trial). Except where these API Terms expressly distinguish between the two forms, references to the "API" in Sections 1, 3 through 6, and 8 through 10 include AI Connections, and these API Terms apply to both forms of programmatic access. Section 2 governs credentials for each form as stated there; Section 7 applies only to AI Connections. For a free trial that includes AI Connections, references in these API Terms to a subscription or subscription term include the trial and its term. Capitalized terms not defined here have the meanings given in the Terms of Use.
1. License
Subject to your compliance with these API Terms, the Terms of Use, and the Acceptable Use Policy ("AUP"), we grant you a non-exclusive, non-transferable license to access and use the documented API for your internal business use during your subscription term. These API Terms supplement the Terms of Use (or Master Subscription Agreement) and the Acceptable Use Policy; for API use specifically, these API Terms control to the extent of a direct conflict, except that the Data Processing Agreement controls as to the processing of personal data.
2. API Keys and Personal Access Tokens
API keys for the REST API are issued per organization. Personal access tokens for AI Connections are issued per individual user. Both are "keys" for purposes of this Section. Keys are our Confidential Information: you must keep them confidential, must not publish or embed them in client-side code or public repositories, and must rotate them (or, for personal access tokens, revoke and reissue them) promptly upon any known or suspected compromise. You are responsible for all use of your keys, whether or not authorized by you, until you notify us of a compromise and the affected keys are rotated or revoked.
3. Rate Limits and Fair Use
We may set, and may change from time to time, rate limits and other usage parameters for the API. You may not circumvent or attempt to circumvent rate limits, including by using multiple API keys, spoofing requests, or distributing requests to disguise their origin. We may throttle, deprioritize, or temporarily block traffic that we reasonably determine to be abusive or to threaten the stability or security of the Service.
4. Data Use
Data retrieved via the API is subject to the same restrictions as data accessed in the application, including Section 6 of the Terms of Use and Sections 5 and 6 of the AUP. In particular:
- API data is for your internal business use only;
- No resale, sublicensing, or redistribution of the data;
- No bulk replication of the database — you may not use the API to copy, reconstruct, or maintain a substantial portion of our database;
- No FCRA or eligibility uses of any kind, as described in Section 5 of the AUP; and
- Records you retrieve through documented export endpoints are "exports" and are governed by Section 6 of the Terms of Use (internal business use, suppression obligations, no resale) — they are not subject to the cache limits below and, subject to those continuing obligations, survive termination of your subscription. Other API responses may be cached for performance purposes only and must be refreshed or purged within thirty (30) days of retrieval and deleted upon termination of your subscription.
5. Prohibited Conduct
In addition to the restrictions in the Terms of Use and the AUP, you may not:
- Reverse engineer, probe, or access non-public endpoints of the API;
- Publish benchmarks or performance comparisons of the API without our prior written consent; or
- Use the API to build, or assist a third party in building, a product or service that competes with the Service.
6. Changes and Deprecation
We version the API. We will provide at least 90 days' notice before removing a documented endpoint or making a materially breaking change to one, except where a change is required to address a security vulnerability or legal obligation, in which case we will provide as much notice as is reasonably practicable. Non-breaking changes — such as adding endpoints, fields, or optional parameters — may be made at any time without notice, and your integration should tolerate them.
7. AI Connections
AI Connections lets an AI assistant provided or operated by a third party (an "Assistant Provider," such as Anthropic or OpenAI) access the Service on behalf of one of your authorized users, after that user expressly authorizes the connection and subject to your administrative controls. The following applies to AI Connections:
(a) Acting on your behalf. Actions taken and data retrieved through a connected assistant are attributed to the authorizing user and to you, and count against your plan's quotas, to the same extent as if performed directly in the application. You are responsible for the instructions your users give their assistants and for the actions those assistants take within your account.
(b) Data retrieved into an assistant. Data retrieved through AI Connections is subject to Section 4 (Data Use) to the same extent as data retrieved through the API, including the prohibitions on resale, redistribution, bulk replication, and FCRA or eligibility uses. Records retrieved through the documented export tool are "exports" governed by Section 6 of the Terms of Use, including the suppression obligations. The cache-refresh and deletion obligations of Section 4 apply to copies in systems you control; retention of assistant conversation content by your Assistant Provider is addressed by subsection (c), not by those obligations.
(c) Your Assistant Provider relationship. Your Assistant Provider's storage, retention, and use of data your users retrieve into assistant conversations are governed by your or your user's agreement with that Assistant Provider, not by these API Terms, and Oystercatcher is not responsible for it. You are responsible for choosing Assistant Providers and settings consistent with your obligations under Section 4 and Section 6 of the Terms of Use.
(d) Controls and revocation. Administrators may disable AI Connections, disable personal access tokens, or restrict connections by role at any time in settings; individual users may revoke their own connections at any time. Oystercatcher may also revoke a user's connections and tokens upon security events, such as a password change or "sign out everywhere," or when a plan change removes the feature. After a free trial or subscription ends, we may in our discretion allow limited read-only access through AI Connections; any such access remains subject to these API Terms and may be withdrawn at any time.
(e) No circumvention. You may not use AI Connections to circumvent quotas, rate limits, plan gating (including the plan gating of the REST API), or the restrictions of Section 4, including by scripting an assistant to perform bulk extraction that Section 4 would prohibit if performed directly. A user's holding of multiple personal access tokens is not, by itself, circumvention.
(f) Changes to tools. We may add, change, or remove individual AI Connections tools as the feature evolves, and Section 6's notice periods do not apply to those tools. This subsection does not otherwise limit Section 6.
8. Availability
API availability is covered by the Service Level Agreement where the customer's plan includes it. No separate availability commitment applies to the API.
9. Suspension
We may suspend API access immediately, without prior notice, where continued access poses a security risk to the Service or other customers, or in the event of your material breach of these API Terms. For other violations, we will provide notice and a reasonable opportunity to cure before suspension where practicable. We will restore access promptly once the grounds for suspension are resolved.
10. No Warranties Beyond the Terms
The API is provided subject to the disclaimers, limitations of liability, and other protective provisions of the Terms of Use. Nothing in these API Terms creates any warranty, representation, or commitment beyond those expressly stated in the Terms of Use.
Contact
Oystercatcher, LLC
API support: [email protected]
Legal inquiries: [email protected]