Last updated August 12, 2026
Last updated August 12, 2026. Contact legal@oauth.work for the executed agreement. Some bracketed values remain placeholders until incorporation details are finalized.
These terms (the "Terms") govern access to and use of the OAUTH.WORK identity platform (the "Service"), operated by OAUTH.WORK ("we", "us"). By creating an account or using the Service you ("Customer") agree to these Terms. If you are agreeing on behalf of an organization, you represent that you have authority to bind it.
The Service is a multi-tenant identity platform providing OAuth 2.1 and OpenID Connect authorization, SAML 2.0 and SCIM 2.0 enterprise connectivity, WebAuthn authentication, delegated and sender-constrained tokens for software agents, and a W3C Verifiable Credentials issuance and revocation rail. We may improve or modify the Service over time; we will not materially reduce core functionality of a paid tier during a paid term without notice.
The Service implements published open standards. We are not affiliated with, endorsed by, or acting on behalf of any standards body or specification author, and we make no representation that use of the Service constitutes certification against any specification.
Customer will not, and will not permit any third party to:
We may suspend access without prior notice where continued operation presents a security risk to the platform or to other customers. We will restore access promptly once the risk is resolved.
Where fees apply, they are billed in advance and are non-refundable except as expressly stated. Pricing changes take effect at the start of the next billing period, with at least [30] days' notice. Customer is responsible for applicable taxes other than taxes on our income.
Service level commitments apply only to the Enterprise plan with the SLA option. Where applicable, we target [99.9]% monthly availability of the token, authorization, and discovery endpoints, measured excluding scheduled maintenance and factors outside our reasonable control. Customer's exclusive remedy for a missed target is a service credit of [SLA CREDIT SCHEDULE]. Free and Pro plans are provided without an availability commitment.
Customer is the controller and we are the processor with respect to personal data Customer routes through the Service. Our processing commitments, sub-processor list, and transfer mechanisms are set out in the Data Processing Agreement, which is incorporated into these Terms. Our handling of data generally is described in the Privacy notice.
We maintain technical and organizational measures appropriate to the risk, including per-tenant cryptographic key isolation with private keys envelope-encrypted at rest, sender-constrained access tokens, refresh-token reuse detection, and an append-only audit log. Details are published at Security. Report vulnerabilities to security@oauth.work; we will not pursue claims against good-faith research conducted within the scope described there.
Customer retains all rights in the data it stores in the Service. We use it only to provide and secure the Service. Customer may export its data at any time through the management API. On termination, Customer may export for [30] days, after which live records are deleted; residual copies in encrypted backups are purged on the backup retention cycle described in the Privacy notice.
We retain all rights in the Service and its software. Customer retains all rights in its data and its own marks. Neither party may use the other's name or marks publicly without consent, except that we may identify Customer as a customer in a list of customers unless Customer opts out by writing to hello@oauth.work.
Each party warrants it has authority to enter these Terms. Except as expressly stated, the Service is provided "as is" and we disclaim all other warranties, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted or error-free.
Neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits or revenue. Except for Customer's payment obligations, each party's total aggregate liability is limited to the fees paid or payable by Customer in the [12] months preceding the event giving rise to the claim. These limits do not apply to [EXCLUSIONS — e.g. breach of confidentiality, indemnification obligations, or liability that cannot be limited by law].
We will defend Customer against third-party claims that the Service infringes intellectual property rights, and Customer will defend us against third-party claims arising from Customer data or Customer's use of the Service in breach of these Terms. Each is conditioned on prompt notice, sole control of the defense, and reasonable cooperation.
These Terms run for as long as Customer uses the Service. Either party may terminate for convenience at the end of a billing period, or immediately for material breach that remains uncured [30] days after written notice. Sections that by their nature should survive termination will survive.
We may update these Terms. For material changes we will give at least [30] days' notice by email or in the console before they take effect. Continued use after that date constitutes acceptance.
These Terms are governed by the laws of [GOVERNING LAW], excluding conflict-of-laws rules, and the parties submit to the exclusive jurisdiction of the courts of [VENUE]. If a provision is unenforceable, the rest remains in effect. Neither party may assign these Terms without consent, except in connection with a merger or sale of substantially all assets. These Terms, with the DPA, are the entire agreement between the parties on this subject.
Questions: hello@oauth.work.