Legal

Terms of service

Last updated August 12, 2026

Last updated August 12, 2026. Contact legal@oauth.work for the executed agreement. Some bracketed values remain placeholders until incorporation details are finalized.

These terms (the "Terms") govern access to and use of the OAUTH.WORK identity platform (the "Service"), operated by OAUTH.WORK ("we", "us"). By creating an account or using the Service you ("Customer") agree to these Terms. If you are agreeing on behalf of an organization, you represent that you have authority to bind it.

1. The Service

The Service is a multi-tenant identity platform providing OAuth 2.1 and OpenID Connect authorization, SAML 2.0 and SCIM 2.0 enterprise connectivity, WebAuthn authentication, delegated and sender-constrained tokens for software agents, and a W3C Verifiable Credentials issuance and revocation rail. We may improve or modify the Service over time; we will not materially reduce core functionality of a paid tier during a paid term without notice.

Standards and interoperability

The Service implements published open standards. We are not affiliated with, endorsed by, or acting on behalf of any standards body or specification author, and we make no representation that use of the Service constitutes certification against any specification.

2. Accounts and tenants

  • Customer is responsible for the accuracy of tenant configuration, for the users and credentials it provisions, and for all activity under its API keys and administrative accounts.
  • Customer must safeguard its API keys and signing material. We cannot recover a lost API key; a replacement must be minted.
  • Customer is responsible for obtaining any consents and providing any notices required for it to route its end users' personal data through the Service.

3. Acceptable use

Customer will not, and will not permit any third party to:

  • attempt to breach tenant isolation, access another tenant's data, or circumvent authorization controls;
  • probe, scan, or load-test the Service beyond documented rate limits without prior written arrangement;
  • use the Service to issue credentials or assertions that misrepresent identity, affiliation, or authority;
  • use the Service to process data in violation of applicable law, or in a manner that infringes third-party rights;
  • resell or provide the Service to third parties except as an integrated part of Customer's own product.

We may suspend access without prior notice where continued operation presents a security risk to the platform or to other customers. We will restore access promptly once the risk is resolved.

4. Fees and plans

  • Free — no charge, no availability commitment, and subject to change or discontinuation.
  • Pro — paid plan; contact us for billing.
  • Enterprise — paid plan with optional service level and priority support; contact us for billing.

Where fees apply, they are billed in advance and are non-refundable except as expressly stated. Pricing changes take effect at the start of the next billing period, with at least [30] days' notice. Customer is responsible for applicable taxes other than taxes on our income.

5. Availability and support

Service level commitments apply only to the Enterprise plan with the SLA option. Where applicable, we target [99.9]% monthly availability of the token, authorization, and discovery endpoints, measured excluding scheduled maintenance and factors outside our reasonable control. Customer's exclusive remedy for a missed target is a service credit of [SLA CREDIT SCHEDULE]. Free and Pro plans are provided without an availability commitment.

6. Data protection

Customer is the controller and we are the processor with respect to personal data Customer routes through the Service. Our processing commitments, sub-processor list, and transfer mechanisms are set out in the Data Processing Agreement, which is incorporated into these Terms. Our handling of data generally is described in the Privacy notice.

7. Security

We maintain technical and organizational measures appropriate to the risk, including per-tenant cryptographic key isolation with private keys envelope-encrypted at rest, sender-constrained access tokens, refresh-token reuse detection, and an append-only audit log. Details are published at Security. Report vulnerabilities to security@oauth.work; we will not pursue claims against good-faith research conducted within the scope described there.

8. Customer data and portability

Customer retains all rights in the data it stores in the Service. We use it only to provide and secure the Service. Customer may export its data at any time through the management API. On termination, Customer may export for [30] days, after which live records are deleted; residual copies in encrypted backups are purged on the backup retention cycle described in the Privacy notice.

9. Intellectual property

We retain all rights in the Service and its software. Customer retains all rights in its data and its own marks. Neither party may use the other's name or marks publicly without consent, except that we may identify Customer as a customer in a list of customers unless Customer opts out by writing to hello@oauth.work.

10. Warranties and disclaimers

Each party warrants it has authority to enter these Terms. Except as expressly stated, the Service is provided "as is" and we disclaim all other warranties, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted or error-free.

11. Limitation of liability

Neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits or revenue. Except for Customer's payment obligations, each party's total aggregate liability is limited to the fees paid or payable by Customer in the [12] months preceding the event giving rise to the claim. These limits do not apply to [EXCLUSIONS — e.g. breach of confidentiality, indemnification obligations, or liability that cannot be limited by law].

12. Indemnification

We will defend Customer against third-party claims that the Service infringes intellectual property rights, and Customer will defend us against third-party claims arising from Customer data or Customer's use of the Service in breach of these Terms. Each is conditioned on prompt notice, sole control of the defense, and reasonable cooperation.

13. Term and termination

These Terms run for as long as Customer uses the Service. Either party may terminate for convenience at the end of a billing period, or immediately for material breach that remains uncured [30] days after written notice. Sections that by their nature should survive termination will survive.

14. Changes to these Terms

We may update these Terms. For material changes we will give at least [30] days' notice by email or in the console before they take effect. Continued use after that date constitutes acceptance.

15. General

These Terms are governed by the laws of [GOVERNING LAW], excluding conflict-of-laws rules, and the parties submit to the exclusive jurisdiction of the courts of [VENUE]. If a provision is unenforceable, the rest remains in effect. Neither party may assign these Terms without consent, except in connection with a merger or sale of substantially all assets. These Terms, with the DPA, are the entire agreement between the parties on this subject.

Questions: hello@oauth.work.