Skip to content

Terms of use

Terms of use

What is allowed through the API, how the data processing agreement applies and when Bodo suspends a key. The consent dialog for “API on” in Bodo links here.
Draft for the previewThis version applies to the preview. Bodo releases the binding wording before the API becomes stable; we announce any change in the changelog.

Acceptable use

  • Access only within the rights of the principal and the scope.
  • Do not pass keys on, do not put them in code or repositories.
  • Production integrations through service accounts, not through personal keys.
  • Apps of other vendors only through OAuth with the user’s consent, never with a handed-over key.
  • Do not work around limits, for example with many keys for one purpose.

Data protection and DPA

  • The organization stays the controller, Bodo processes on its behalf. The existing data processing agreement covers the API too.
  • The request log holds no bodies and no record ids. The full IP stays 7 days, after that only the network.
  • Raw log 90 days, aggregates 13 months. The organization can shorten both.

When Bodo suspends

OccasionConsequence
Key found in public (report to POST /v1/secret-scanning/report)revoked at once, email, bell, record history
Firing on after a 429locked for 5 minutes
Delete budget reacheddeleting paused
Personal key unused for 90 dayspaused, email and bell 7 days before, re-enable with one click
Service account key unused beyond its account’s threshold (90 to 400 days, default 400)paused, email and bell 7 days before, re-enable with one click
Webhook endpoint answers no 2xx for 3 daysendpoint disabled, email to the owner
Organization switches the API offall keys, webhooks and app tokens off
Operator pulls the emergency stopevery call 503 API_PAUSED