The agreement between you and us when you use the onelinktoken API, MCP server, or dashboard.
Effective date: [Effective date] · Version: draft
Draft for legal review — not legal advice
This document is a working draft prepared for review by qualified counsel. It is not legal advice
and is not yet an enforceable agreement. Bracketed values such as
[Governing law jurisdiction] and [Liability cap]
must be completed, and the whole document reviewed, before publication.
These terms are between [Legal entity name] of [Registered address] (“we”, “us”) and the person or organisation that opens an onelinktoken account (“you”). By creating an account, calling the API, or connecting the MCP server, you accept them. If you are accepting on behalf of an organisation, you confirm you have authority to bind it.
A separately signed agreement, order form, or data processing agreement takes precedence over these terms to the extent of any conflict.
onelinktoken issues, delivers, validates, and revokes one-time credentials — magic links, one-time passwords, and bearer tokens — over a REST API, an MCP server, and webhook callbacks. We store a SHA-256 hash of each token value rather than the value itself, so a token can be validated but never read back out of our systems.
onelinktoken is not an identity provider, a user directory, or a system of record for your users. You remain responsible for deciding who is entitled to a token, what a redeemed token grants access to, and for enforcing that decision in your own application.
You may not use onelinktoken to:
Send phishing links, impersonate another organisation, or issue tokens to recipients who did not ask to hear from you.
Use magic-link or OTP delivery as a bulk marketing channel, or send to addresses you have no lawful basis to contact.
Violate applicable law, export controls or sanctions, or infringe anyone's rights.
Probe, load-test, or circumvent rate limits and quotas without written permission, or interfere with other tenants.
Repackage the API or MCP server as a competing token service without a written reseller agreement.
Send categories of sensitive or regulated data through the service without the agreement in place that covers it. Ask us first.
We may suspend an account or a single tenant immediately where continued use presents a security, legal, or abuse risk. Where the circumstances allow, we will tell you first and give you a chance to fix it.
The free plan is offered as-is and may be changed or withdrawn with reasonable notice.
You own the data you send us. You grant us only the licence needed to operate the service for you. How we handle personal data is set out in the Privacy Policy; where we act as your processor, a data processing agreement governs.
On termination we delete or return your data in line with the retention periods in the Privacy Policy. Because we store only token hashes, we cannot export the original token values to you — by design.
We work to keep the service available and will give advance notice of planned maintenance where we can. Any binding uptime commitment, service credit, or support response target applies only if it is set out in a signed order form or service level schedule: [SLA / service credit terms — confirm what, if anything, is contractually committed].
The service depends on third parties, including Stripe for payments, Resend for email delivery, and Keycloak at auth.pnebula.com for sign-in. Their own terms apply to their part of the flow, and we are not responsible for their acts or omissions beyond our duty to select and manage subprocessors reasonably.
We provide the service with reasonable skill and care. Beyond that, and to the fullest extent permitted by law, the service is provided as is without further warranty of any kind, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the service will be uninterrupted or error-free, and we make no representation in these terms about any certification, audit, or regulatory status.
Nothing in this section limits rights that cannot be limited under the law that applies to you.
To the fullest extent permitted by law, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, goodwill, or data. Our total aggregate liability arising out of or relating to the service is limited to [Liability cap].
These limits do not apply to death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot lawfully be limited.
You will defend and indemnify us against third-party claims arising from your use of the service in breach of these terms, including claims that content or recipients you supplied caused harm. [Confirm whether a reciprocal IP indemnity from us is offered.]
These terms run for as long as you have an account. Either party may terminate for material breach that is not fixed within [Cure period] of written notice. You may close your account at any time. We may terminate a free account on [Notice period] notice. Sections that should survive termination — confidentiality, liability, fees already due, and governing law — do so.
We may update these terms. We will post the new version here with a new effective date, and for material changes we will give existing customers at least [Notice period] notice. Continuing to use the service after a change takes effect means you accept it.
These terms are governed by the laws of [Governing law jurisdiction], and the courts of [Venue / courts] have exclusive jurisdiction, without prejudice to any mandatory consumer protections in your own country. [Confirm whether arbitration or a class-action waiver is intended — none is included in this draft.]
These terms, plus any order form and DPA, are the entire agreement between us. Neither party may assign without the other's consent, except to a successor of its business. If a provision is unenforceable, the rest stands. Failure to enforce a right is not a waiver of it.
Product questions belong on Support; data questions on the Privacy Policy.