SYNC
DEVELOPER LEGAL

API Terms

These additional terms apply to YugiCore API projects, API keys, webhooks and developer data.

Effective: October 3, 2026 · Last updated: October 3, 2026

1. Agreement and priority

These API Terms supplement the YugiSMP Terms of Service. By requesting, receiving or using API access, you agree to both. If they conflict about API use, these API Terms control.

2. Approval is required

Submitting an application does not grant access. YugiSMP may approve, reject, limit, suspend or revoke a project or scope at its discretion. Approval applies only to the project and use case described in the application. Material changes in ownership, purpose or data use require a new review.

3. API keys and security

  • Keep API keys and webhook secrets confidential and use them only from trusted server-side environments.
  • Never place a secret key in public source code, browser code, mobile packages, URLs, screenshots or public logs.
  • Use a separate key for each approved project and environment when available.
  • Notify YugiSMP immediately and revoke or regenerate a key if compromise is suspected.
  • You are responsible for requests made with your credentials until the credentials are revoked.

YugiSMP stores a secure hash of each API key and displays the complete key only when it is created.

4. Scopes and access controls

Use only approved endpoints, tables and scopes. Do not bypass or attempt to expand permissions, infer restricted data, access another developer’s project or use server credentials intended for YugiSMP infrastructure. Write, administrative and sensitive scopes may require additional review.

5. Acceptable use

You may use API data only for the approved project and purpose. You must not use the API for surveillance, harassment, discrimination, spam, resale of raw data, creation of unauthorized player dossiers, cheating, ban evasion, security attacks or any unlawful purpose. You must not falsely claim that your project is official or endorsed.

6. Player data and privacy

Collect the minimum data your project needs. Provide users with an accurate privacy notice when your project stores or combines YugiSMP data. Honor applicable access and deletion requests. Do not retain data longer than necessary, combine it with sensitive data for profiling, or attempt to identify players beyond information intentionally supplied by YugiSMP. If YugiSMP requests deletion or correction of data, act promptly.

7. Caching

Reasonable caching is allowed to improve performance, but cached data must not be presented as live when it is stale. Refresh player and server data at reasonable intervals, delete data when no longer needed and do not use caching to evade rate limits. YugiSMP may specify endpoint-specific cache limits in the documentation.

8. Rate limits and fair use

Follow the rate limit returned by the API and use pagination. Do not distribute requests across keys, projects or addresses to evade limits. Use backoff for errors and retries. YugiSMP may adjust limits based on capacity, abuse risk and project needs.

9. Webhooks

Verify webhook signatures before trusting a payload. Keep webhook secrets confidential, use HTTPS, acknowledge deliveries promptly and make handlers idempotent. Do not intentionally trigger excessive retries. Delivery is not guaranteed, and your project should tolerate delayed, duplicated or missing events.

10. Attribution and branding

If your project publicly displays substantial YugiSMP data, identify YugiCore or YugiSMP as the source where practical. You may make truthful statements that your project uses the YugiCore API, but you may not use YugiSMP logos or branding in a way that suggests ownership, sponsorship or endorsement without permission.

11. Monitoring and audit

YugiSMP may log requests, review usage and contact you about compliance, security or performance. You must provide accurate application information and reasonably cooperate with investigations. We may require changes, key rotation, reduced retention or a security fix as a condition of continued access.

12. Suspension and revocation

Access may be limited or revoked immediately for security threats, abuse, misleading application information, noncompliance, excessive load, legal requirements or risk to players. When practical, we may provide notice and an opportunity to correct the issue. After termination, stop API calls and delete data you are no longer authorized or legally required to retain.

13. API changes and support

Endpoints, schemas, limits and features may change. Versioned endpoints are intended to reduce disruption, but no compatibility period is guaranteed unless documentation states one. APIs are provided without guaranteed uptime or support. Do not build safety-critical systems that depend on them.

14. No resale or sublicensing

You may not sell, rent, transfer or sublicense API credentials or sell access to the raw API. A commercial project requires explicit written approval. You remain responsible for contractors and service providers that process API data for your approved project.

15. Contact

Developer and compliance questions can be submitted through the developer application area or the official YugiSMP support channel.