Terms of use
What is allowed through the API, how the data processing agreement applies and when Bodo suspends a key. The consent dialog for “API on” in Bodo links here.
Draft for the previewThis version applies to the preview. Bodo releases the binding wording before the API becomes stable; we announce any change in the changelog.
Acceptable use
- Access only within the rights of the principal and the scope.
- Do not pass keys on, do not put them in code or repositories.
- Production integrations through service accounts, not through personal keys.
- Apps of other vendors only through OAuth with the user’s consent, never with a handed-over key.
- Do not work around limits, for example with many keys for one purpose.
Data protection and DPA
- The organization stays the controller, Bodo processes on its behalf. The existing data processing agreement covers the API too.
- The request log holds no bodies and no record ids. The full IP stays 7 days, after that only the network.
- Raw log 90 days, aggregates 13 months. The organization can shorten both.
When Bodo suspends
| Occasion | Consequence |
|---|---|
Key found in public (report to POST /v1/secret-scanning/report) | revoked at once, email, bell, record history |
| Firing on after a 429 | locked for 5 minutes |
| Delete budget reached | deleting paused |
| Personal key unused for 90 days | paused, email and bell 7 days before, re-enable with one click |
| Service account key unused beyond its account’s threshold (90 to 400 days, default 400) | paused, email and bell 7 days before, re-enable with one click |
| Webhook endpoint answers no 2xx for 3 days | endpoint disabled, email to the owner |
| Organization switches the API off | all keys, webhooks and app tokens off |
| Operator pulls the emergency stop | every call 503 API_PAUSED |