Developer & MCP Platform Terms
Last updated: September 12, 2026
These Developer & Model Context Protocol (MCP) Terms ("Developer Terms") govern your access to and integration with Krafto's REST APIs, SDKs, Webhooks, and official Model Context Protocol (MCP) server endpoints operated by Krafto Digital Technologies Private Limited ("Krafto", "we", "us").
1. API Keys, MCP Tokens & Security Authentication
To access Krafto's developer ecosystem or connect AI coding assistants (such as Claude, Cursor, Windsurf, or custom agent runtimes):
- You must generate an authenticated API Key or scoped MCP Token through your Developer Dashboard or MCP Hub;
- You are strictly prohibited from exposing API keys or tokens in public repositories, client-side browser bundles, or unauthenticated proxies;
- You must immediately revoke and regenerate any credential that has been compromised;
- Krafto reserves the right to automatically revoke credentials exhibiting abnormal or abusive traffic patterns.
2. Rate Limits, Quotas & Fair Usage
API and MCP tool calls are subject to rate limiting based on your account tier and subscription status. You agree not to bypass, spoof, or circumvent rate limits through distributed IP rotation, multi-account orchestrations, or rapid hammering. Attempts to denial-of-service the platform will result in permanent IP and account blacklisting.
3. Autonomous AI & Agentic Execution Disclaimer
KRAFTO PROVIDES MCP TOOLS, CATALOG SEARCH SCHEMAS, AND DIGITAL ASSET ENTITLEMENTS FOR CONSUMPTION BY AI AGENTS. KRAFTO DOES NOT CONTROL, DIRECT, OR ASSUME LIABILITY FOR THE ACTIONS, REASONING, SCRIPT EXECUTION, CODE GENERATION, OR FINANCIAL TRANSACTIONS INITIATED AUTONOMOUSLY BY THIRD-PARTY AI MODELS (INCLUDING ANTHROPIC CLAUDE, OPENAI CHATGPT, GOOGLE GEMINI, OR LOCAL LLMS). YOU BEAR FULL RESPONSIBILITY FOR CONFIGURING REASONABLE HUMAN-IN-THE-LOOP SAFEGUARDS AND VERIFYING AI ACTIONS.
4. Prohibited Developer Activities
You agree NOT to:
- Use Krafto APIs or MCP endpoints to conduct automated bulk extraction or mass-mirroring of the entire catalog for competing marketplace creation;
- Interfere with or disrupt the integrity, latency, or server infrastructure of the API cluster;
- Impersonate another developer, vendor, or authorized entity through API headers;
- Transmit malicious payloads, exploit vulnerabilities, or inject unauthorized SQL/NoSQL payloads.
5. Webhook Reliability & Delivery
Krafto provides real-time webhooks for events such as order completion, license provisioning, and vendor updates. Developers must provide high-availability HTTPS endpoints capable of responding with standard 200 HTTP status codes. Unresponsive endpoints will be deactivated after repeated delivery failures.
6. SLA & Service Availability
While Krafto strives for 99.9% uptime, developer APIs and MCP servers are provided "as is" without guarantees of uninterrupted availability. Scheduled maintenance windows and API version deprecation schedules will be communicated via the Changelog.
7. Developer Support & Integration Inquiries
For technical assistance, SDK bug reports, or custom enterprise rate quotas, consult the Developer Documentation or email developers@krafto.app.