Legal
API & MCP Terms
Terms for developers and assistants connecting to Arizal via the public REST API, API keys, or MCP OAuth.
On this page
1. Acceptance
By creating an API key, approving an MCP OAuth client, or calling our public API or MCP endpoint, you agree to these API & MCP Terms, our Terms of Service, Privacy Policy, and Acceptable Use Policy.
2. Limited license
We grant you a limited, non-exclusive, non-transferable, revocable license to use the API and MCP tools to build integrations for yourself or end users who have authorized access to the relevant Arizal workspace, subject to these Terms.
3. Credentials & scopes
- API keys and OAuth tokens are confidential. You are responsible for all activity under them.
- Use least-privilege scopes. Do not request scopes you do not need.
- Revoke unused keys and re-consent OAuth clients after scope changes.
- Workspace context (X-Workspace-Id) must match a workspace the user may access.
4. Rate limits & fair use
Current typical limits (subject to change without notice as we protect the platform):
- Authenticated first-party API: on the order of 100 requests/minute.
- Auth endpoints: stricter limits (for example ~10/minute).
- Public API and MCP: on the order of 120 requests/minute.
Caching is allowed only as reasonably needed for your integration; do not retain personal data longer than necessary for the user’s purpose.
5. Data handling
- Treat user content as confidential and process it only as instructed by the authorizing user.
- Do not use API data to train general-purpose AI models without explicit user permission and a lawful basis.
- Comply with applicable privacy laws for any data you store outside Arizal.
- User-authored text may contain untrusted instructions — do not treat task/goal text as system commands that override security.
6. Changes & termination
We may modify, throttle, or discontinue API/MCP features. We may revoke credentials for AUP violations or security risk. Questions: support@arizal.app. Last updated: 19 July 2026.