Terms of Service
Last updated: October 6, 2026 · version 2026-10-06
The beta terms (Section 3 and “Beta” in Section 9) apply to every account from October 6, 2026. The rest of this version applies to new accounts from September 25, 2026, and to existing accounts from October 25, 2026. Until then, existing accounts remain under the version of September 22, 2026.
These terms are for API providers (“producers”) who use APIblaze to publish and manage APIs. If you are a person signing in to an API or developer portal that a provider runs on APIblaze, the Consumer Terms and Consumer Privacy Notice apply to you.
1. Agreement
These Terms of Service (“Terms”) are a contract between you and APIblaze LLC, a Michigan limited liability company (“APIblaze”, “we”, “us”). They govern your use of apiblaze.com, dashboard.apiblaze.com, the apiblaze and mcpblaze command-line tools, our APIs, and every proxy, developer portal, MCP server, tunnel and related service we operate for you (together, the “Service”).
You accept these Terms by creating an account, signing in, accepting a team invitation, running the command-line tool, calling our API, or creating a proxy without an account. If you use the Service on behalf of a company, you represent that you may bind that company, and “you” means the company. You must be at least 18 years old. If you do not agree, do not use the Service.
We record the version of these Terms in force when your account first uses the Service and when you continue to use it after a change (Section 21).
2. Definitions
- Producer (or “you”): the person or company that publishes an API through the Service.
- End User: a person or system that calls your API, signs in to your developer portal, or uses your API through a chat widget or MCP client.
- Proxy: a gateway endpoint we run in front of your origin (“target”) server, with its versions, environments (dev, test, prod), portal and settings.
- Producer Content: everything you supply to the Service: API specifications, configuration, transformation rules, policies, portal branding, secrets, and anything imported from repositories you connect.
- End-User Records: records about your End Users held by the Service: identities, group memberships, access requests, API-key metadata and usage.
- Credits: the prepaid balance on a billing account, denominated in US dollars, from which usage is deducted (Section 9).
3. The Service
APIblaze provides, as configured by you:
- A globally distributed API gateway that proxies requests to your origin, with per-route authentication, authorization rules, rate limits, request and response transformation, validation, and a development tunnel to a machine of yours.
- Identity for your End Users: API keys, OAuth 2.0 / OpenID Connect sign-in through providers you choose (GitHub, Google, Microsoft, Facebook, Auth0, or any OpenID Connect issuer), groups and permissions, pre-approval rules, and a hosted developer portal.
- Model Context Protocol (MCP) servers generated from your API, and an AI chat widget through which End Users can talk to your API.
- AI-assisted tooling for you: drafting specifications from captured development traffic, generating models and templates, and reviewing traffic.
- Request logs, analytics, audit logs and alerts.
- Custom domains, published “recipes”, and a self-service export of your configuration and End-User Records (Section 10).
The Service as a whole is currently in beta, as shown by a “Beta” label on the dashboard and website; Section 16 applies with particular force while it is. Features marked “beta”, “preview” or “experimental” may change or be withdrawn without notice. We may change any part of the Service; where a change materially reduces functionality you rely on, we will give at least 30 days’ notice by email or on the dashboard where practicable, and otherwise as much notice as we reasonably can.
4. Accounts, teams and anonymous use
- Accounts. You sign in with a supported identity provider. Provide accurate information and keep your account, API keys, tokens and secrets confidential. You are responsible for everything done with your credentials; tell us at once at security@apiblaze.com if you suspect misuse.
- Teams. One company is one team. Owners can add and remove members, set roles, set your own terms and privacy links for your End Users, and delete the team. Members you invite are bound by these Terms; you are responsible for their use.
- Anonymous proxies. You may create a proxy without an account. It runs on our sandbox domain with a bootstrap key valid for 30 days and a claim code. These Terms apply to it. We delete unclaimed proxies that have served no traffic for 72 hours, or have been silent for 30 days, together with their data.
- Operators. Our staff (“operators”) can view and change your configuration, suspend resources, and read the logs and records described in the Privacy Policy, to run and protect the Service and to support you.
5. Acceptable use
You agree not to use the Service, and not to let anyone use it through you, to:
- break any law, or infringe anyone’s intellectual property, privacy or other rights;
- publish, proxy or host anything that is malicious, deceptive or fraudulent: malware, phishing, credential harvesting, or a portal, domain, name or branding that impersonates another person, company or service;
- point a proxy at a target you are not authorized to expose, or at a target on a public threat list (we check targets against Google Web Risk and our own denylist and refuse those that match);
- collect End-User personal data beyond what your End Users would reasonably expect from their relationship with you, or use it in a way that violates Section 6;
- send unsolicited email through the Service’s invitation or access-request features;
- probe, scan, overload, or interfere with the Service, other customers’ proxies, or our providers; bypass rate limits, quotas, credit checks or access controls; or reverse engineer the Service except where the law allows it;
- use the AI features to generate content that is illegal or that violates the usage policies of the model providers we route to;
- resell the Service as such, or use it to build a competing gateway service with our technology.
Report abuse to report@apiblaze.com. We may remove or disable content, proxies, portals, recipes or domains that we reasonably believe violate this Section or the law, and act under Section 11.
6. Your content, your End Users’ data, and our roles
Producer Content. You keep all rights in your Producer Content. You grant us a worldwide, non-exclusive, royalty-free licence to host, store, copy, transform, transmit, display and otherwise process it as needed to provide the Service to you, and to your End Users on your behalf, for as long as you use the Service plus the retention periods in the Privacy Policy. You represent that you have the rights needed to grant this licence.
End-User Records: you are the controller, we are the processor. For personal data about your End Users that we process on your behalf, you decide why and how it is processed; we process it only to provide the Service to you, on your documented instructions (your configuration and use of the Service), and for the limited platform-security purposes described in the Consumer Privacy Notice, for which we act as an independent controller. This Section is our data-processing agreement.
You must:
- have a lawful basis for the End-User data you collect through the Service, including consent where the law requires it;
- name APIblaze as a service provider (processor) in your own privacy policy, and, when your End Users sign in through your own application rather than our hosted login, make sure they are shown your terms and privacy policy;
- use End-User data only for the purposes your End Users would reasonably expect from their relationship with you; not sell it, and not re-identify, enrich or correlate End-User records in ways they have not agreed to;
- honour End Users’ rights (access, correction, deletion, objection, portability) and tell us within 7 days if you need our help to answer a request; and
- keep exported End-User Records secure (Section 10).
We will:
- process End-User data only as described here and in the Privacy Policy and Consumer Privacy Notice;
- use only the subprocessors listed in the Privacy Policy, and give at least 30 days’ notice on that page before adding one, so that you can object, except where a change is urgently needed for security or to keep the Service running, in which case we update the page as soon as we can;
- protect it with the measures described in the Privacy Policy, and tell you without undue delay, and within 72 hours of confirming it, about any breach affecting your End-User data;
- help you answer End-User requests with the tools in the dashboard and, where those are not enough, by email; and
- delete or return End-User Records when you delete a tenant, a team or your account, subject to the retention periods in the Privacy Policy.
Secrets you store with us. Origin credentials, OAuth client secrets, provider secrets and similar values you store in the Service are encrypted with keys we hold. To operate the Service we can decrypt and use them, and the dashboard can reveal an OAuth client secret to your team members with the right role. If you need secrets that we can never read, keep them at your origin.
Our data. Identifiers we mint (for example internal user ids), abuse-protection state, analytics derived across customers, and the software of the Service are ours.
7. AI features
- The chat widget, MCP tooling and AI drafting features send content to third-party language-model providers through OpenRouter. That content can include End-User chat messages, responses from your API, captured development traffic (only when you run traffic review on it), and your API structure. We request routing that excludes providers who retain or train on inputs. The providers are listed in the Privacy Policy.
- You may supply your own model API key instead (“bring your own key”). Requests then go to that provider under your agreement with them; we do not store the key.
- AI output can be wrong, incomplete or unsafe. You are responsible for reviewing it before relying on it, and for what your End Users can do through the chat widget, which calls your API with their identity and permissions.
- Do not send special categories of personal data (health, biometric, financial account, government identifiers and the like) through AI features.
8. Developer portals, domains and recipes
- Portals run on a subdomain of portal.apiblaze.com or on your custom domain. They carry your name and branding; you are responsible for what they say and for your End Users’ experience on them. Our Consumer Terms and Consumer Privacy Notice are linked from our hosted sign-in screen.
- You must own or control any custom domain you connect. We may remove a domain that is used for abuse or that you no longer control.
- Recipes you publish become public. You grant other users a licence to install and use them, and you may not publish recipes that violate Section 5. We may take down a recipe at any time.
9. Fees, credits and payment
Prepaid credits, no subscription. The Service is pay-per-use, funded from a prepaid Credit balance. There are no plans, seat fees, minimums or end-of-month invoices. The pricing page is the authoritative price list; at the date of these Terms it is:
- Requests, per billing account per calendar month: $0.003 each for the first 5,000; $0.001 each for the next 5,000; $0.0005 each beyond 10,000. A request to your API and a request to our management APIs cost the same; authentication, permission checks, transformation and validation inside a request are included.
- End-User logins: the first 2,000 per month are free, then $0.005 each. API keys: the first 500 active keys are free, then $0.01 per key per month. Revocation, member removal and other clean-up are always free, even with an empty balance.
- AI chat: $0.01 per turn plus the model cost multiplied by 1.25, or a flat $0.01 per turn with your own model key.
- Email sent by the Service on your behalf (invitations, access requests): $0.01 per email flow.
- Custom domain: $0.15 per domain per month, prorated, the only recurring fee.
- Free tier: 2,500 requests and 10 chat turns without an account; 2,500 more requests on sign-up.
Top-ups. You buy Credits from $10 through Stripe, our payment processor, by card. Credits are added when Stripe confirms payment. We do not see or store your card number.
Beta. While APIblaze is in beta (shown by a “Beta” label on the dashboard), recharging Credits is free: a recharge tops your balance up to a cap shown in the dashboard (currently $10), and no payment is taken. Beta Credits are Promotional Credits: they have no cash value, cannot be refunded, transferred or exchanged, and are removed when your account closes. Beta Credits you hold when the beta ends stay usable, but further free recharges stop and top-ups return to paid. We may change the cap or end the beta at any time. We may remove Beta Credits or suspend free recharges for an account we reasonably believe is abusing them, for example by creating several accounts.
When Credits run out, billable requests are paused with HTTP 402 until you top up. Your configuration and counters are kept.
Refusals are free. A request that we reject before it reaches your origin (over quota, failed authentication or authorization, failed validation) is refunded in Credits automatically. A request that reaches your origin is billed whatever your origin answers.
No refunds; no expiry. Credits are non-refundable, including any unused balance when you close your account, except where applicable law requires a refund. Purchased Credits do not expire while the Service operates. If we discontinue the Service, Credits remain usable until it shuts down, and any balance left at that point is not refundable except where applicable law requires a refund (Section 11). Promotional, free-tier and sign-up Credits are removed at closure.
Taxes. Prices exclude sales tax, VAT, GST and similar taxes. Where we are required to collect them, Stripe adds them at checkout based on the billing address and tax ID you provide; otherwise you are responsible for them. Provide a valid tax ID if you are a business outside the United States.
Price changes. We may change prices by publishing the new price list on the pricing page. A price increase applies from the first day of the calendar month after publication; a decrease applies at once. You can export and leave at any time (Section 10).
Disputes. Tell us at billing@apiblaze.com within 60 days of a charge you believe is wrong. A chargeback opened without contacting us first may lead us to suspend the billing account until it is resolved.
10. Portability and export
The commitment. While your account is in good standing, and for 30 days after termination other than for abuse (or, if we discontinue the Service, until it shuts down), you can export, self-service and free of charge, (a) your Producer Content and (b) the End-User Records of each of your projects. Nothing in this Section transfers ownership of data; it gives you access to it and transfers responsibility for it.
Formats. At minimum: your API definition in OpenAPI; End-User Records in SCIM 2.0 and documented JSON; your configuration in documented JSON; and, on explicit opt-in by a team member with the right role, the secrets you supplied. We may also provide convenience artifacts for third-party systems, for example a Kong-compatible bundle. Export formats may change with 30 days’ notice, without reducing what is exportable.
The Export Report is the statement of fidelity. No export can perfectly reproduce the Service’s behaviour on other software. Every export includes a machine-readable report stating, per item, whether it was exported exactly, approximately, lossily or skipped. Items marked approximate, lossy or skipped are disclosed limitations, not defects. We warrant only that the bundle conforms to the documented formats and that the report accurately describes the bundle. We make no warranty that any exported configuration, plugin, script or artifact will work on, or behave the same in, any third-party system. Convenience artifacts are provided “as is” and are not covered by support.
What is never exported: credentials of authentication applications shared across APIblaze customers (including our managed GitHub application); values visible only to your End Users (exported as counts and identifiers); session state, issued tokens and cached provider tokens; the private token-signing key of your application clients (your bundle contains the public keys, which is all a gateway needs to verify tokens until they expire); our software, keys and infrastructure credentials; analytics, traffic captures and abuse-protection state; and platform features with no meaning outside the Service, such as Credits and hosted-portal state.
Keys and secrets. End-User API keys are stored as irreversible hashes, and a key issued with an expiry date is additionally held in full, in encrypted storage, until it expires so that it can be revealed again; exports contain, at your choice, hashes plus compatibility tooling, or newly minted replacement keys; continuity of existing keys on another system depends on you deploying that tooling. Each export of secrets is recorded in your audit log, and the bundle is available for one hour. On download you become solely responsible for the security of exported secrets and for the End-User Records in the bundle, under Section 6.
Migration conduct. When you tell End Users about a migration you will not use our name, logos or branding, will not state or imply that we require or endorse it, and will not ask End Users for their API keys, tokens, passwords or payment details. We may refuse, delay or limit an export where we reasonably believe it is sought to facilitate fraud, phishing or unlawful processing, and will say why.
11. Suspension, termination and appeal
- By you. Delete a proxy, a tenant, a team, or your account at any time from the dashboard. Account deletion requires that you are the only member of every team you own; other teams must be handed over or deleted first. Deletion runs as a cascade described in the Privacy Policy.
- By us. We may suspend or terminate access, or disable specific proxies, portals, domains, recipes or keys, if you materially breach these Terms, if we reasonably believe your use creates a legal, security or abuse risk to us, our providers, other customers or End Users, if we are required to by law, or if we discontinue the Service (see “Discontinuation” below). Where practicable we will notify you first and give you a chance to fix the problem; where the risk is immediate we act first and notify you after.
- Appeal. A suspended account is shown the reason and an appeal link. We review appeals and aim to answer within 10 business days.
- Discontinuation. If we decide to discontinue the Service, we will tell you by email and on the dashboard as early as we reasonably can, aiming for at least 60 days before it shuts down. Until then the Service keeps running and you can use your Credits and export your data under Section 10. After shutdown we delete Producer Content and End-User Records, subject to the retention periods in the Privacy Policy. Unused Credits are not refundable except where applicable law requires a refund.
- Effect. On termination your proxies stop serving. You keep export access for 30 days unless terminated for abuse, or, on discontinuation, until the Service shuts down. After that window we delete your Producer Content and End-User Records, subject to the retention periods and carve-outs in the Privacy Policy. Sections 6, 9, 10, 12 and 15 to 20 survive.
12. Availability and support
We aim for high availability but do not offer a service-level agreement at this stage, and the Service may be unavailable for maintenance, because of our providers, or for reasons outside our control. We provide support by email at support@apiblaze.com on a reasonable-efforts basis. Do not run life-critical or safety-critical systems through the Service.
13. Security
We protect the Service as described in the Privacy Policy. You are responsible for the security of your origin, your application clients, your custom domains, the credentials you store with us, and the machines you connect through the development tunnel. Report vulnerabilities to security@apiblaze.com; we will not take legal action against good-faith research that respects other customers’ data and does not disrupt the Service.
14. Third-party services
The Service depends on third parties: identity providers you connect (GitHub, Google, Microsoft, Facebook, Auth0, other OpenID Connect issuers), GitHub for repository import, Stripe for payment, the model providers behind the AI features, and the infrastructure providers listed in the Privacy Policy. Their terms govern your relationship with them, and we are not responsible for their acts, outages or changes. Kong and other third-party names are the marks of their owners; we are not affiliated with or endorsed by them.
15. Intellectual property and feedback
The Service, its software, documentation and marks are owned by APIblaze and its licensors. Apart from the rights expressly granted here you receive no licence to them. If you send us feedback or suggestions we may use them without obligation to you. The APIblaze command-line tools and SDKs are licensed under the open-source licences that accompany them.
16. Disclaimer of warranties
THE SERVICE, THE AI FEATURES, EXPORT BUNDLES AND CONVENIENCE ARTIFACTS ARE PROVIDED “AS IS” AND “AS AVAILABLE”. TO THE FULLEST EXTENT PERMITTED BY LAW, APIBLAZE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE OR SECURE.
17. Limitation of liability
TO THE FULLEST EXTENT PERMITTED BY LAW: (A) APIBLAZE WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, DATA OR GOODWILL, EVEN IF ADVISED OF THEIR POSSIBILITY; (B) APIBLAZE’S TOTAL LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS WILL NOT EXCEED THE GREATER OF THE AMOUNTS YOU PAID US IN THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM AND US $100; AND (C) APIBLAZE IS NOT LIABLE FOR BEHAVIOUR DIFFERENCES ON THIRD-PARTY SYSTEMS DISCLOSED IN AN EXPORT REPORT, FOR YOUR HANDLING OF EXPORTED SECRETS OR PERSONAL DATA, OR FOR THIRD-PARTY SYSTEM CHANGES. NOTHING IN THESE TERMS LIMITS LIABILITY THAT CANNOT BE LIMITED BY LAW.
Who is responsible. These Terms are a contract with APIblaze LLC only. Any claim arising out of or relating to the Service or these Terms may be brought only against APIblaze LLC, and not personally against any of its members, managers, officers, employees or contractors.
18. Indemnity
You will defend and indemnify APIblaze and its members, officers and contractors against third-party claims, and the resulting damages, costs and reasonable legal fees, arising from your Producer Content, your API and origin, your End Users’ data and your processing of it, your portals and domains, or your breach of these Terms or the law. We will notify you promptly of any such claim and let you control the defence, provided you do not settle in a way that admits fault on our part without our consent.
19. Governing law and disputes
These Terms are governed by the laws of the State of Michigan and the federal laws of the United States, without regard to conflict-of-law rules. The state and federal courts located in Oakland County, Michigan have exclusive jurisdiction, and each party consents to it, except that either party may seek injunctive relief in any competent court to protect its intellectual property or confidential information. Before filing a claim, the parties will try in good faith to resolve the dispute by email for 30 days.
20. General
- These Terms, the Privacy Policy, the pricing page and any order or written amendment signed by both parties are the entire agreement and replace all earlier ones. If a term is unenforceable, the rest stands.
- You may not assign these Terms without our consent; we may assign them to a successor of the Service. Neither party is liable for delay or failure caused by events beyond its reasonable control.
- Notices to you go to the email of your account or team owner; notices to us go to legal@apiblaze.com. No waiver is implied from a failure to enforce.
- You will comply with export-control and sanctions laws and will not use the Service if you are on a sanctions list or in an embargoed territory.
21. Changes to these Terms
We may change these Terms. For a material change we will give at least 30 days’ notice by email or in the dashboard and update the version at the top of this page; the change takes effect at the end of the notice period, or at once if it is required by law or reduces our rights. Your continued use after that date is acceptance, and we record the version you continued under. If you do not agree, stop using the Service and export your data under Section 10.
22. Contact
Legal: legal@apiblaze.com
Privacy: privacy@apiblaze.com
Security: security@apiblaze.com
Report abuse: report@apiblaze.com
Billing: billing@apiblaze.com
Support: support@apiblaze.com
Address: APIblaze LLC, Birmingham, Michigan, United States