Skip to main content

API terms

Last updated: January 1, 2026

These API Terms apply to use of the Offsoo External API ("API"). They supplement the Terms and Conditions and apply to Customers and Users who use API access.

Access and API keys

API access is included with every subscription unless agreed otherwise. The Customer is responsible for managing API keys and tokens securely, including limiting access within their own organisation. The Customer can create tokens, limit their scope, set an expiry date and revoke tokens from the settings within Offsoo.

Rate limits and fair use

Offsoo applies a default limit of 120 requests per minute per API key. Offsoo may adjust this limit to safeguard stability and security. Bulk export is permitted within the applicable rate limits and fair use. The Customer is responsible for designing integrations efficiently (pagination and caching) and for avoiding overload. Circumventing rate limits, scraping beyond those limits and abuse of the API are prohibited.

Versions and changes

Offsoo may change, add or deprecate endpoints. Offsoo supports a major API version (for example /external/v1) for at least 12 months after a new major version is released, unless a change is necessary for security or to meet a legal obligation.

Responsibility and security

The Customer is responsible for implementing and securing their own integrations correctly, including:

  • storing tokens securely;
  • limiting scopes;
  • rotating or revoking tokens on (suspected) compromise;
  • logging and monitoring on the customer's side.

Offsoo is not liable for damage arising from incorrect or insecure use of the API by the Customer or by third parties who gain access through the Customer.

Suspension

Offsoo may (temporarily) limit or block API access in the event of:

  • abuse or (threatened) security incidents;
  • persistent breaches of the rate limits;
  • non-payment or termination of the Agreement.

Contact

For questions about this page, contact us at .