Developer Terms
The terms that govern the Ionhour developer platform — credentials and security, scopes and data, acceptable use, and the app review and distribution process.
Version 2025-01
The developer platform is in beta and these terms may be updated as it matures. Creating an app in the Developer Console records your acceptance of the version in effect at that time; material changes will be announced and may require re-acceptance.
These Developer Terms ("Terms") govern your registration and operation of OAuth applications ("Apps") on the Ionhour platform. They supplement — and do not replace — Ionhour's general Terms of Service and Privacy Policy. By creating an App you agree to be bound by these Terms.
1. Your App and your responsibilities
- You are responsible for your App: its behavior, its infrastructure, its security, and the accuracy of the information you provide about it (name, vendor, support contact, privacy policy, terms of service).
- You must provide working, reachable privacy-policy and terms-of-service pages before distributing your App, and keep them current.
- You must provide a support contact that responds to users of your App.
2. Credentials and security
- Keep client secrets and webhook signing secrets confidential. Do not embed secrets in client-side code, public repositories, or distributed binaries. Public clients must use PKCE.
- Rotate credentials promptly if you suspect exposure, and notify Ionhour of any security incident affecting Ionhour customer data without undue delay.
- You may not share, sell, or transfer your App's credentials or an installation's tokens to third parties.
3. Scopes and data
- Request only the scopes your App genuinely needs. Ionhour may reject or unpublish Apps whose requested scopes are disproportionate to their function.
- Data obtained through the API or webhooks may be used only to provide your App's stated functionality to the workspace that granted access. You may not use it for advertising, profiling, resale, or training purposes unrelated to that functionality.
- When an installation is revoked or your App is deleted, you must delete the associated workspace data you hold within 30 days, except where retention is required by law.
- If your App stores personal data, your declaration in the distribution controls must say so, and your privacy policy must describe what you store and why.
4. Review and distribution
- Draft Apps may only be installed into workspaces you are a member of. Public distribution requires review and approval by Ionhour.
- Ionhour may approve, reject, request changes to, suspend, or unpublish any App at its discretion, including for security, privacy, quality, or brand concerns.
- Changes to a published App's scopes or event subscriptions take effect only after re-review.
5. Acceptable use
You may not use the platform to build Apps that: circumvent scope or role restrictions; probe, scan, or overload Ionhour systems beyond documented rate limits; misrepresent their identity or vendor; or violate applicable law or the rights of others.
6. Availability and changes
The developer platform, its APIs, and event schemas may evolve. Ionhour will use reasonable efforts to announce breaking changes in advance but does not guarantee uninterrupted availability of the platform or of webhook delivery.
7. Disclaimer and liability
The developer platform is provided "as is". To the maximum extent permitted by law, Ionhour disclaims all warranties and limits its aggregate liability arising out of these Terms to the amount paid by you to Ionhour in the twelve months preceding the claim.
8. Termination
You may delete your Apps at any time. Ionhour may suspend or terminate your access to the developer platform for breach of these Terms. Sections 3, 5, 7, and this section survive termination.
Questions about these Terms: support@ionhour.com.