Access
Keystone API licence
The terms under which the Keystone API and MCP server may be used: who may use them, what for, and what Keystone commits to in return.
This is the licence for programmatic access to Keystone: the HTTP API documented on this site and the Keystone MCP server. It is a commercial licence attached to a Keystone Enterprise subscription. It is written to be read; the defined terms are kept to the few that matter.
Definitions
- Keystone is the operator of the platform, the entity named in the Terms of Service.
- Subscriber is the business holding the Enterprise subscription, and the people it authorizes to act for it.
- The API means every endpoint under
sor.keystone.appandauth.keystone.appdocumented here, the Keystone MCP server atmcp.keystone.app, their documentation, and their OpenAPI contracts. - Credentials are site API keys, console tokens, MCP access tokens, and anything else that authenticates a call.
- Business Data is the information about the Subscriber's businesses that the API reads or changes.
- Integration is any software the Subscriber builds or runs that calls the API, including an MCP client configured against the server.
1. What you may do
Keystone grants the Subscriber a non-exclusive, non-transferable, revocable licence, for the term of the Enterprise subscription, to:
- call the API with Credentials issued to the Subscriber;
- build and operate Integrations that read and change Business Data for the Subscriber's own businesses, or for businesses the Subscriber manages on Keystone with their permission;
- connect MCP clients of the Subscriber's choice to the MCP server for users Keystone has granted access;
- copy and use the documentation and OpenAPI contracts on this site for the purpose of building those Integrations.
2. What you may not do
The Subscriber will not, and will not let anyone else:
- share a Credential outside the people it was issued to, or embed a Credential where a third party can read it (a public repository, a browser bundle, a mobile app);
- use the API to read or change a business the Subscriber could not open in the console;
- resell, sublicense, rent, or offer the API, the MCP server, or access to them as a service to others, or build a product whose purpose is to substitute for Keystone;
- collect Business Data across businesses to build a dataset, train a model, or profile Keystone's customers;
- circumvent authentication, rate limits, the review step on a staged changeset, compare-and-swap on a field, or any other control the API applies;
- probe, scan, or load-test the API without Keystone's written agreement, or send traffic designed to degrade it;
- use the API in a way that breaks the law, a platform's terms the Subscriber's business is published to, or the Keystone Terms of Service;
- remove Keystone's notices from, or misrepresent the source of, the documentation or contracts.
3. Credentials
Credentials are confidential and are the Subscriber's responsibility. A Credential issued to a person is for that person. Tell developer support at once if a Credential is lost or exposed, and Keystone will revoke and reissue it. The Subscriber is responsible for every call made with its Credentials until it reports them exposed.
4. Business Data
Business Data belongs to the Subscriber. Keystone processes it to operate the platform and the API as described in the Privacy Policy, and does not use a Subscriber's Business Data to train models that serve other customers.
An Integration acts on the Subscriber's behalf. A change an Integration stages and applies is the Subscriber's change, exactly as if made in the console, and lands in the console's Change History where it can be undone. Keystone is not responsible for the content an Integration publishes; the Subscriber is responsible for reviewing it.
Where an Integration sends Keystone personal data about the Subscriber's own customers (a contact, a form submission), the Subscriber confirms it has the right to do so.
5. Changes to the API
The API is versioned at /api/v1/. Within a version Keystone may add endpoints, fields, enum values, and tools without notice; an Integration should tolerate fields it does not recognize. A change that removes or renames something, or changes a response's meaning, is a breaking change. Keystone will announce a breaking change in the changelog at least 90 days before it takes effect, and will keep the old behaviour available through that period, except where a security or legal issue makes that impossible.
The MCP server's tool set follows the same rule. The server's protocol version follows the Model Context Protocol; older protocol versions are served for as long as the clients that need them are in use.
6. Availability and support
Keystone operates the API as part of the Enterprise service. Service levels, if any, are those in the Subscriber's Enterprise agreement; this licence adds none. Rate limits apply per Credential and are returned in the response when exceeded. Developer support is by email at developers@keystone.app during Keystone's business hours.
7. Intellectual property
Keystone owns the API, the MCP server, the documentation, the contracts, and the Keystone marks. This licence grants no rights to them beyond what section 1 says. The Subscriber owns its Integrations. If the Subscriber sends Keystone feedback, Keystone may use it without obligation.
The Subscriber may say that an Integration "works with Keystone" and may use the Keystone name to describe that fact. It may not use Keystone's logo or marks in a way that suggests Keystone built, endorses, or operates the Integration without Keystone's written agreement.
8. Term and ending
This licence runs for the term of the Enterprise subscription and ends with it. Keystone may suspend or revoke a Credential, or the Subscriber's access as a whole, where it reasonably believes this licence or the Terms of Service have been breached, or to protect the platform or its customers; it will say why and, where it can, give notice first. The Subscriber may stop using the API at any time by telling developer support to revoke its Credentials.
When the licence ends, the Subscriber stops calling the API and destroys Credentials. Business Data remains the Subscriber's and remains in the console under the Terms of Service. Sections 2, 4, 7, 9, and 10 survive.
9. Warranties and liability
The API is provided as described in the Enterprise agreement and the Terms of Service. Beyond those, it is provided as is, and Keystone disclaims implied warranties of merchantability, fitness for a purpose, and non-infringement to the extent the law allows. Keystone is not liable for an Integration, for what it publishes, or for a third-party MCP client. The limits of liability in the Terms of Service apply to this licence.
The Subscriber will defend and indemnify Keystone against claims arising from its Integrations, its use of Credentials, or its breach of this licence.
10. General
This licence is governed by the law and venue named in the Terms of Service. Keystone may update this page; a change that reduces the Subscriber's rights is announced in the changelog and takes effect 30 days later, and continuing to call the API after that date is acceptance. Notices to Keystone go to developers@keystone.app; notices to the Subscriber go to the contacts on its Enterprise account.