Developer API Terms
Version: 1.0<br /> Effective Date: August 10, 2026
These Developer API Terms ("API Terms") form a binding agreement between you ("you," "your," or "Customer") and Human Beyond LLC, a Florida limited liability company operating MainBook ("MainBook," "we," "us," or "our").
These API Terms supplement the MainBook Terms of Service, Privacy Policy, Data Processing Agreement, Acceptable Use Policy, AI and Data Processing Disclosure, Disclaimer, and other policies incorporated into them (collectively, the "MainBook Terms").
These API Terms govern your access to and use of MainBook’s application programming interfaces, API documentation, API keys, connectors, Model Context Protocol servers or tools, and other programmatic integration surfaces that we make available (collectively, the "API Services").
BY AFFIRMATIVELY ACCEPTING THESE API TERMS, CREATING OR OBTAINING AN API KEY, OR USING THE API SERVICES, YOU REPRESENT THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THESE API TERMS. IF YOU ACT ON BEHALF OF AN ENTITY, YOU REPRESENT AND WARRANT THAT YOU HAVE AUTHORITY TO BIND THAT ENTITY.
1. Relationship to the MainBook Terms
The MainBook Terms apply to the API Services in addition to these API Terms. Capitalized terms not defined here have the meanings given in the Terms of Service.
Use of automated means in accordance with these API Terms and the API documentation is expressly permitted for purposes of the automated-access restrictions in the Terms of Service and Acceptable Use Policy.
If these API Terms conflict with another MainBook document, these API Terms control solely with respect to API-specific access and use, except that:
- the Data Processing Agreement controls with respect to Customer Personal Data;
- applicable Standard Contractual Clauses and other mandatory data-transfer provisions control to the extent required by law; and
- the Terms of Service control with respect to liability, indemnification, dispute resolution, governing law, and matters not specifically addressed here.
2. Permitted Use and Restrictions
Subject to your continuing compliance with the MainBook Terms, we grant you a limited, revocable, non-exclusive, non-transferable, and non-sublicensable right to use the API Services to:
- integrate MainBook conversion functionality into your internal systems;
- create features within applications or services operated by you for your authorized users or customers; and
- retrieve and use Output for your lawful business purposes.
You may not:
- resell, rent, sublicense, or provide raw or substantially unmodified access to the API Services;
- represent that your application, service, decisions, or Output are certified, endorsed, audited, or guaranteed by MainBook;
- use the API Services to operate a competing standalone document-conversion, OCR, extraction, or API service that provides raw or substantially unmodified access to the API Services;
- reverse engineer or attempt to discover MainBook’s models, prompts, algorithms, security controls, or internal systems;
- use the API Services or Output to train, fine-tune, evaluate, or improve a competing artificial-intelligence or machine-learning system;
- circumvent any rate limit, concurrency limit, access control, safety control, Account restriction, or Credit requirement; or
- use the API Services in any manner prohibited by the Acceptable Use Policy.
For clarity, a materially value-added customer-facing integration that otherwise complies with these API Terms remains permitted under this Section.
3. API Keys, Account Authority, and Security
3.1 Scope of an API key
An API key is a credential associated with your MainBook Account.
API KEYS IN VERSION 1 OF THE API ARE NOT LIMITED BY SCOPES AND DO NOT AUTOMATICALLY EXPIRE. AN ACTIVE KEY MAY LIST, READ, DOWNLOAD, AND DELETE ANY ELIGIBLE JOB AVAILABLE TO THE ACCOUNT, INCLUDING JOBS CREATED THROUGH THE MAINBOOK WEB APPLICATION OR THROUGH ANOTHER API KEY.
An active key may also create and start jobs, view the shared Account Credit balance, and reserve or consume Credits from that balance.
Bearer authentication does not permit the key to create or revoke other API keys or change Account settings. Nevertheless, you must treat every API key as a high-privilege, Account-wide data credential.
MainBook may treat every request authenticated with an active API key as authorized by you. You are responsible for activity performed with your keys, whether or not you personally initiated it, except to the extent caused solely by MainBook’s breach of its express obligations.
3.2 Key confidentiality
You must:
- keep each API key confidential;
- store keys only in secure server-side systems or appropriate secret-management tools;
- limit access to personnel, contractors, and service providers who require access for your authorized use and are bound by suitable confidentiality and security obligations;
- never embed a key in public source code, a public repository, browser-delivered client code, a distributable mobile application, or other material accessible to unauthorized persons;
- maintain reasonable administrative, technical, and organizational security safeguards; and
- monitor your integrations for unauthorized or unexpected activity.
You may not sell, publish, publicly share, or transfer an API key to another person or entity.
3.3 Compromise and revocation
If you know or reasonably suspect that a key has been exposed, lost, stolen, or used without authorization, you must promptly revoke it through your MainBook Account and notify us at hello@human-beyond.ai.
Revocation is irreversible and stops further authentication with that key. We may revoke, expire, rotate, restrict, or disable a key where reasonably necessary to protect the Service, comply with law, enforce the MainBook Terms, respond to a security incident, or prevent abuse.
The full API key is displayed only when created. MainBook stores a one-way cryptographic digest and a limited identifying prefix, not a recoverable copy of the full key.
4. Your Applications, Users, and Data
You are solely responsible for your applications, systems, personnel, customers, and end users, including:
- their access to and use of the API Services and Output;
- providing required notices and obtaining all rights, permissions, and consents necessary for documents and personal data submitted through the API Services;
- the security, legality, accuracy, and operation of your systems;
- your customer support and contractual relationship with your users;
- independently reviewing Output before displaying, sharing, or relying on it; and
- complying with all laws applicable to your business and use case.
You must not state or imply that MainBook reviewed, approved, certified, audited, or guaranteed your application, its decisions, or its Output.
Where you submit documents or data containing personal data of clients or other third parties:
- you act as controller or “business,” or, where applicable, as a processor acting for another controller;
- MainBook acts as your processor, service provider, or sub-processor;
- the Data Processing Agreement applies;
- you represent that you have a lawful basis and all authority required to submit and process the data;
- you are responsible for required notices and Data Subject requests; and
- requests authenticated with your active API key constitute your documented instructions to MainBook to perform the requested processing within the API Services and Data Processing Agreement.
MainBook does not acquire ownership of your documents or Output merely because they are processed through the API Services.
5. Technical Requirements and Usage Limits
You must follow the then-current API documentation, including supported methods, formats, request headers, authentication requirements, upload procedures, and error-handling instructions.
We may apply rate limits, concurrency limits, file-size limits, page limits, security restrictions, or other technical controls. Current limits are described in the API documentation and may differ by endpoint or Account.
You must honor HTTP 429 responses and any Retry-After header, use reasonable retry and backoff behavior, use idempotency controls where documented, and avoid polling more frequently than recommended.
A published limit does not create a guaranteed minimum capacity, reserved capacity, service-level agreement, or promise that the API Services will accept any particular volume.
6. Credits and Billing
The API Services use the same Credit balance as your MainBook Account. A request authenticated with your key may reserve or consume Credits.
A page count supplied when creating a job is an estimate used to reserve Credits. MainBook may determine the actual page count after upload and adjust the reservation or charge to reflect the number of pages actually processed.
You are responsible for using documented idempotency controls to reduce duplicate jobs caused by retries, timeouts, or integration errors.
Deleting a job or revoking a key does not reverse a completed Credit charge. Failed jobs receive the Credit treatment described in the Refund Policy.
7. Output and Validation Signals
7.1 Output may be incorrect
The API Services use OCR, machine-learning, and large-language-model technology. Output may be inaccurate, incomplete, duplicated, omitted, incorrectly signed, incorrectly dated, misclassified, fabricated, or otherwise defective.
YOU MUST INDEPENDENTLY VERIFY ALL OUTPUT AGAINST THE ORIGINAL SOURCE DOCUMENT BEFORE USING, SHARING, OR RELYING ON IT.
7.2 Validation is a diagnostic signal only
The API Services may return processing or validation fields including state, validation.passed, validation.reconcilable, and validation.mismatched_rows.
Depending on the field and current API version, a value may describe processing status or the result of limited automated mathematical or logical checks. The API documentation describes the current technical meaning of each field.
A SUCCESSFUL HTTP RESPONSE, A succeeded STATE, validation.passed: true, validation.reconcilable: true, ZERO REPORTED MISMATCHED ROWS, OR ANY SIMILAR RESULT IS NOT A REPRESENTATION, WARRANTY, CERTIFICATION, AUDIT, ATTESTATION, OR GUARANTEE THAT:
- the source document is genuine, complete, or unaltered;
- every transaction or field was detected or extracted;
- the Output is accurate, complete, reliable, or fit for a particular purpose;
- the Output reconciles under every applicable accounting method;
- no omission, duplication, sign inversion, date error, or hallucinated entry exists; or
- the Output complies with any accounting, tax, audit, lending, legal, regulatory, or professional requirement.
Automated checks can fail to detect errors and may return a favorable signal for incorrect Output. A null or unavailable field means only that the field is unavailable, inapplicable, or that the corresponding check was not performed.
7.3 High-stakes reliance
You may not use the API Services or Output as the sole basis for tax filings, accounting submissions, audit assertions, regulatory filings, lending or credit decisions, legal proceedings, or other decisions with legal or material consequences.
Any such use requires independent review of the original document and Output by an appropriately qualified human professional. MainBook is not a bank, accounting firm, auditor, tax preparer, financial advisor, attorney, credit bureau, or fiduciary.
8. Retention and Deletion
8.1 Standard retention
API jobs, uploaded source documents, and associated Output are scheduled for automatic deletion ninety (90) days after upload, subject to the Privacy Policy, the Data Processing Agreement, backup cycles, legal obligations, and documented exceptions.
MainBook is not required to preserve data for the full retention period. You are responsible for downloading and retaining any Output that you or your customers are legally required to preserve.
8.2 Early deletion through the API
The documented DELETE endpoint accepts deletion requests only for jobs in a terminal state. It does not cancel an in-progress job in API v1.
A successful 204 No Content response means that the job is immediately removed from normal Account and API access and marked for deletion. It does not mean that every physical copy has been synchronously or irreversibly erased at the time of the response.
Physical deletion from MainBook’s active object storage and primary database occurs through the scheduled daily cleanup process, normally by the next cleanup run and generally within approximately twenty-four (24) hours. If a storage or infrastructure operation fails, deletion may be retried during a later cleanup run.
8.3 Backups and retained records
Encrypted database backups may retain a recoverable residual copy for up to seven (7) days. Such backups are isolated from ordinary use and expire through the standard backup cycle.
Deleting a job does not require deletion of:
- billing, payment, tax, Credit-ledger, legal-acceptance, security, fraud-prevention, or audit records that MainBook is permitted or required to retain;
- deidentified or aggregated data that no longer identifies an individual;
- records subject to a legal hold or reasonably required to establish, exercise, or defend legal claims; or
- limited abuse, security, or compliance records retained by a third-party provider under its applicable terms and retention practices.
Where required, retained MainBook records are minimized, anonymized, or separated from the deleted job.
9. Availability, Support, and Changes
The API Services are provided “AS IS” and “AS AVAILABLE.”
Unless the parties enter into a separate signed agreement, no service-level agreement, uptime guarantee, response-time guarantee, support-response guarantee, dedicated capacity, or backwards-compatibility commitment applies.
We may modify, add, remove, deprecate, suspend, restrict, or discontinue an endpoint, field, model, feature, limit, or item of documentation. Where reasonably practicable, we will provide advance notice of a material backwards-incompatible change, but we may make immediate changes where required for security, legal compliance, vendor changes, abuse prevention, reliability, or protection of the Service.
You are responsible for monitoring the API documentation and adapting your integration.
10. Monitoring, Enforcement, and Suspension
We may process API usage metadata and diagnostic information as described in the Privacy Policy for authentication, billing, reliability, support, security, fraud prevention, and enforcement.
We may rate-limit, reject, suspend, or terminate API access or revoke keys immediately where we reasonably believe that:
- a key is compromised;
- your use threatens the security, integrity, availability, cost, or operation of the Service;
- you violated the MainBook Terms or applicable law;
- payment or Credit requirements are not satisfied;
- your Account is suspended or inactive; or
- restriction is required by a vendor, regulator, court, governmental authority, or applicable law.
We have no obligation to continue processing an in-flight request after suspension or termination.
11. Ownership, Disclaimers, and Liability
MainBook and its licensors retain all right, title, and interest in the API Services, documentation, software, interfaces, models, and related intellectual property.
As between you and MainBook, you retain ownership of your Content and Output, subject to the licenses and restrictions in the Terms of Service.
The warranty disclaimers, exclusions of damages, liability cap, and indemnification obligations in the Terms of Service apply fully to the API Services, API keys, validation signals, your applications, and Output.
Without limiting those provisions, MainBook is not liable for:
- decisions or actions taken by you, your application, your customers, or your users;
- inaccurate, incomplete, duplicated, or unavailable Output;
- reliance on a validation field or status;
- unauthorized activity caused by your failure to protect a key;
- duplicate requests caused by retry or idempotency behavior;
- incompatibility caused by a change to your system or a third-party system; or
- acts, omissions, outages, or changes of a third-party provider.
Subject to the procedures and limitations in the Terms of Service, you agree to indemnify, defend, and hold harmless the MainBook Indemnified Parties from third-party claims arising from your application, API use, Content, customers or users, violation of these API Terms, or failure to obtain required rights, notices, or consents.
12. Updates, Termination, and Contact
We may update these API Terms under the notice mechanism in the Terms of Service. The version and Effective Date above identify the terms in force.
Material changes take effect after the applicable notice period unless you affirmatively accept them earlier. Non-material clarifications, formatting changes, and factual corrections may take effect when posted.
You may stop using the API Services by revoking your API keys. Revocation does not affect obligations, charges, or liabilities incurred before revocation.
Sections that by their nature should survive termination will survive, including Sections 3, 4, 6–8, and 10–12.
Questions about these API Terms may be sent to:
Human Beyond LLC<br /> 1818 Hollywood Blvd<br /> Hollywood, FL 33020<br /> United States<br /> Email: hello@human-beyond.ai