PlayerVault Seller API Terms
Last updated September 21, 2026
Effective September 21, 2026 · Version seller-api-2026-09-21-v1
These API Terms supplement the Terms and Seller Terms. Using or retaining an API key constitutes acceptance by the approved Seller Account to which it is issued.
1. Limited permission
PlayerVault grants a limited, revocable, non-exclusive, non-transferable permission to use documented Seller API endpoints only for the approved Seller’s own legitimate listing, inventory, Order, and webhook operations. No ownership or broader license is transferred.
2. Keys and responsibility
- Keep keys secret, server-side, encrypted at rest, scoped to least privilege, and inaccessible in public code, client apps, logs, tickets, or chat.
- Do not sell, share, sublicense, or use another Seller’s key. Authorized personnel/service-provider access remains Seller’s responsibility.
- Rotate or revoke a suspected compromised key immediately and notify Support. Seller is responsible for authorized API activity and for failing to take reasonable key-security measures.
- API-created Listings and inventory carry the same accuracy, ownership, delivery, fee, and evidence obligations as website-created content.
3. Rate limits and fair use
Follow documented request, daily listing, bulk-size, payload, idempotency, and webhook limits. Do not evade limits through multiple keys/Accounts, parallel abuse, scraping, or retry storms. PlayerVault may throttle, queue, reject, or temporarily block traffic to protect availability and integrity.
4. Webhooks
Use HTTPS destinations you control, protect webhook secrets, verify PlayerVault’s timestamped signature against the exact raw body, reject stale requests, compare signatures safely, deduplicate event IDs, and design for retries/out-of-order delivery. Do not place prohibited secrets or sensitive Buyer information in webhook descriptions or URLs.
5. Prohibited uses
- unauthorized access, vulnerability exploitation, malware, denial of service, scraping unrelated data, or reverse engineering except where law permits;
- creating prohibited/misleading inventory, manipulating price/search/reviews, self-dealing, credential harvesting, or off-platform solicitation;
- collecting, combining, or retaining Buyer data beyond Order fulfillment, security, records, and lawful obligations;
- using the API to evade suspension, verification, sanctions, policy, or marketplace controls.
6. Availability and changes
The API is “as is” and may experience outages, maintenance, errors, or changed limits. PlayerVault does not guarantee availability or permanent compatibility. Where feasible, we will use reasonable efforts to document material changes and preserve backwards compatibility or provide migration notice, but urgent security/compliance changes may be immediate.
7. Monitoring and revocation
PlayerVault may log API key ID, Seller, endpoint, timestamp, IP/user agent, request outcome, rate-limit events, and security signals as described in Privacy Policy. We may suspend or revoke keys for compromise, abuse, Seller standing, excessive errors, risk, legal compliance, or service retirement. Revocation does not erase obligations from API activity.
8. Support and precedence
Public developer documentation describes current mechanics but does not override these terms or an Order snapshot. Seller Terms control sales/payouts; these API Terms control API-specific matters; Terms control otherwise. Contact Support for compromise or access issues.