Legal
Terms of Service
These terms govern your access to and use of ApiVault, including the web dashboard, CLI, and MCP server.
Last updated: August 12, 2026
Acceptance of terms
By creating an account or using ApiVault in any way, you agree to these Terms of Service and our Privacy Policy. If you are using ApiVault on behalf of an organization, you represent that you have authority to bind that organization to these terms.
If you do not agree to these terms, you may not access or use the service.
The service
ApiVault provides encrypted storage and management of API keys and similar secrets for developers and teams. The service is available through a web application, a command-line client (apivault), and an MCP integration for supported AI tools.
We may add, change, or discontinue features at any time. We will make reasonable efforts to avoid breaking changes to documented APIs and CLI commands without notice, but the service is provided on an evolving basis.
Your account
You are responsible for maintaining the confidentiality of your account credentials, vault passphrase (if using custom encryption mode), CLI tokens, and MFA devices. You are responsible for all activity that occurs under your account.
You must provide accurate account information and keep it up to date. Notify us promptly at support@apivault.app if you suspect unauthorized access to your account.
You must be at least 13 years old to use ApiVault. If you are under the age of majority in your jurisdiction, you may use the service only with consent of a parent or legal guardian.
Acceptable use
You agree not to:
- Use ApiVault for any unlawful purpose or in violation of applicable laws
- Attempt to gain unauthorized access to other users' accounts or data
- Probe, scan, or test the vulnerability of the service without authorization
- Interfere with or disrupt the integrity or performance of the service
- Upload malware, spam, or content that infringes third-party rights
- Resell or sublicense the service without our written permission
- Circumvent rate limits, authentication, or encryption controls
We may suspend or terminate accounts that violate these rules or pose a security risk to ApiVault or other users.
Your secrets and vault key
You retain ownership of the secrets and content you store in ApiVault. You grant us a limited license to host, encrypt, transmit, and display that content solely to provide the service at your direction.
In custom encryption mode, your vault passphrase is known only to you. If you lose it, encrypted secrets cannot be recovered — this is by design. ApiVault is not responsible for data loss resulting from a forgotten vault passphrase, compromised credentials, or failure to maintain backups of critical secrets.
You are solely responsible for the legality and appropriateness of the secrets you store and for complying with the terms of the third-party services whose keys you manage.
CLI and MCP integrations
When you authorize the CLI or an MCP client, you grant that application access to your vault according to the scopes and permissions you approve. Review connected devices regularly in Settings and revoke access you no longer trust.
Third-party tools (such as Cursor, Claude Desktop, or your terminal environment) are governed by their own terms. ApiVault is not responsible for how those tools handle secrets after you reveal or export them.
Availability and support
We strive to keep ApiVault available and secure, but we do not guarantee uninterrupted or error-free operation. Scheduled maintenance, outages, and force majeure events may affect availability. Support is provided on a reasonable-effort basis via support@apivault.app.
Intellectual property
ApiVault, including its software, design, documentation, and branding, is owned by us and protected by intellectual property laws. These terms do not grant you any rights to our trademarks or proprietary materials except as needed to use the service as intended.
The CLI is provided under its open-source license where applicable. Use of open-source components is subject to the terms of their respective licenses.
Disclaimer of warranties
THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT THE SERVICE WILL BE SECURE, UNINTERRUPTED, OR FREE OF ERRORS.
Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, APIVAULT AND ITS OPERATORS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, DATA, GOODWILL, OR BUSINESS OPPORTUNITIES, ARISING FROM YOUR USE OF OR INABILITY TO USE THE SERVICE.
OUR TOTAL LIABILITY FOR ANY CLAIM ARISING OUT OF THESE TERMS OR THE SERVICE WILL NOT EXCEED THE GREATER OF (A) THE AMOUNT YOU PAID US IN THE TWELVE MONTHS BEFORE THE CLAIM, OR (B) ONE HUNDRED U.S. DOLLARS (USD $100).
Some jurisdictions do not allow certain limitations of liability, so some of the above may not apply to you.
Indemnification
You agree to indemnify and hold harmless ApiVault and its operators from any claims, damages, losses, and expenses (including reasonable legal fees) arising from your use of the service, your stored content, or your violation of these terms.
Termination
You may stop using ApiVault and delete your account at any time. We may suspend or terminate your access if you breach these terms, if required by law, or if continued provision of the service becomes impractical.
Upon termination, your right to use the service ends. Provisions that by their nature should survive — including disclaimers, limitations of liability, and indemnification — will remain in effect.
Changes to these terms
We may revise these Terms of Service from time to time. Material changes will be reflected by updating the date at the top of this page. Continued use of ApiVault after changes take effect constitutes acceptance of the revised terms.
General
These terms constitute the entire agreement between you and ApiVault regarding the service. If any provision is found unenforceable, the remaining provisions remain in full force. Our failure to enforce a provision is not a waiver of that provision.
Questions about these terms? Contact support@apivault.app.