# API terms and attribution

Developer access is governed by Section 21 of the [Terms of Service](https://support.unvault.com/policies/terms-of-service). In short:

- Keys are per application and confidential; stay within the published rate limits and do not use multiple keys to evade them.
- API data may be displayed in your application, but you may not resell raw Unvault data, misrepresent its source, copy the data set wholesale to build a competing service, or use the API for anything that violates Sections 16 or 17 of the Terms.
- Unvault may revoke keys and change or discontinue APIs, with reasonable notice where practical.
- Report vulnerabilities to [security@unvault.com](mailto:security@unvault.com) and do not exploit them.

## Attribution

Applications that display data obtained from the API must identify Unvault as the source: link items and collections back to their unvault.com pages and use the plain-text name or an unmodified Unvault logo obtained from us, as Section 6 of the [Trademark Policy](https://support.unvault.com/policies/trademark-policy) allows. Do not use Unvault Marks in your product name, domain or handle.
