Developer service terms

QFOXAI API Terms

Rules for OpenAI-compatible endpoints, protected API keys, public model aliases, limits, downstream applications, safety, and customer responsibilities.

EffectiveJuly 17, 2026
InterfaceOpenAI-compatible where documented
CredentialsServer-side bearer keys
Support evidenceQFOXAI request ID
Additional provider notice:
QFOXAI API access is provided through customer-owned API keys and public model aliases. Customers are responsible for client configuration, request content, downstream applications, and compliance with applicable laws. API usage may be subject to monthly quota, token quota, request-per-minute limits, token-per-minute limits, safety filtering, and model availability.
01

Authorized API use

You may integrate documented QFOXAI endpoints into applications you own or are authorized to operate. API access does not grant access to private infrastructure, internal model identities, provider credentials, source code, or confidential routing information. Do not represent yourself as QFOXAI unless a written agreement permits it.

02

Keys and authentication

Keep full API secrets in protected server-side configuration. Do not expose them in browsers, public repositories, mobile packages, screenshots, client logs, or support messages. Rotate suspected keys immediately. QFOXAI may accept documented bearer or alternate key headers, but the customer remains responsible for client configuration, IP allowlists, expiry, and key-level limits.

03

Quotas, tokens, speed, and billing

Requests may be controlled by package status, monthly or rolling request limits, input and output tokens, per-request caps, per-minute limits, model access, key-level limits, spend controls, and temporary adjustments. Usage records generated by QFOXAI are the authoritative records for package enforcement unless a confirmed metering error is found. Retries, image tasks, embeddings, files, or other endpoints may have different usage rules.

04

Public model aliases and routing

Customers and end users should use only public QFOXAI model aliases returned by documented endpoints. An alias may route to, balance across, or fall back between available services according to platform settings, package access, capability, health, and capacity. Internal model and infrastructure details are confidential and may change without altering the public alias.

05

Client behavior and resilience

Your application should use reasonable timeouts, bounded retries with backoff, idempotency where documented, request validation, secure logging, and clear handling for 4xx, 429, and 5xx responses. Do not retry indefinitely or create traffic storms. Preserve the QFOXAI request ID when reporting an error and avoid logging full prompts or secrets unnecessarily.

06

Downstream users and notices

You are responsible for your application's users, permissions, content, safety controls, privacy notices, consent, retention, and legal compliance. Do not use the API to conceal AI involvement where disclosure is legally required or materially necessary to avoid deception. Provide human review and escalation for high-impact or safety-sensitive workflows.

07

Content and output

You must have authority to submit input and process personal data. AI output can be wrong, non-unique, or affected by incomplete context. Validate output before acting on it, especially in production code, financial, medical, legal, security, employment, or other high-impact situations. The content and intellectual-property provisions in the Terms of Service also apply.

08

Prohibited API activity

Do not bypass limits or model permissions; share or sell unauthorized keys; scan private infrastructure; scrape confidential data; generate abusive traffic; evade safety controls; interfere with other customers; or use the API for content prohibited by the Acceptable Use Policy. The API Abuse Policy explains protective actions in more detail.

09

Monitoring, changes, and suspension

QFOXAI may monitor operational metadata and limited security signals to meter usage, diagnose failures, and prevent abuse. Endpoints, parameters, models, limits, or preview features may change. QFOXAI may throttle, reject, revoke, or suspend access for security, abuse, unpaid balances, legal obligations, or material policy violations. Where practical, documented deprecations will include migration guidance.

10

Support

Before contacting support, record the UTC time, endpoint, public model alias, HTTP status, and QFOXAI request ID. Never send the full API secret. API questions can be sent to support@qfoxai.com, and commercial integration questions to hello@qfoxai.com.