API Terms
1.Application and acceptance
These API Terms govern all programmatic access to the Platform by brokers, customs house agents, enterprises, platforms, and their systems, including embedding the ScripX quote or settlement interface. They supplement, and are incorporated into, the Terms of Service; capitalised terms have the meanings given there, including "Platform", "User Instruction", "Government Portal", "Scrip", and "Credentials". Requesting, holding, or using an API key constitutes acceptance of these API Terms by the account holder and by each connected entity on whose behalf calls are made, and the Company keeps records of key issuance and use.
2.API keys and attribution
API keys are shown once at creation, are not stored by the Company in readable form, are non-transferable, and are the account holder's sole responsibility to safeguard, to restrict to its own systems, and to have reissued without delay if compromised. Replacement keys are issued on request through support, and the Company may itself require or perform reissue where security warrants. Every call made with an account's key is conclusively a User Instruction of the account holder or of the connected entity to which the call relates, whoever in fact made it, and any offer, transfer, or duty cover resulting from such calls is attributed accordingly under Section 5 of the Terms of Service. Suspected key compromise must be reported without delay to amin@eximfiles.io, and keys must not be embedded in client-side code, shared repositories, or third-party tools outside the account holder's control.
3.Rate limits and fair use
Published per-endpoint rate limits form part of these API Terms, as do published fair-use allowances, such as monthly trade volumes and entity counts stated at scripxhq.com/pricing. The Company may throttle, queue, or reject traffic exceeding them, and may apply protective limits where traffic patterns degrade the Platform or any Government Portal. Circumventing limits, including by key rotation or distributed calling, is a material breach.
4.Environments; production access
Sandbox is the default environment; nothing submitted to it is legally binding, no scrip moves and no funds settle, and sandbox artefacts must not be represented as real trades. Production access requires a signed non-disclosure and production agreement, may carry fees stated there, and may be conditioned on technical review. Every trade records the environment that produced it, and the account holder shall preserve that distinction in its own systems and toward its end customers.
5.End-customer mandates
Programmatic offers, transfers, and duty covers are permitted only for entities that have themselves granted the Section 5 mandate in the Terms of Service and executed their own Power of Attorney at their own connection step. A broker or platform integrating the API shall: ensure and be able to evidence that mandate for every connected entity before any call is made for it; prevent calls for entities whose mandate is absent, revoked, or suspended; pass through to its end customers terms no less protective of the Company than the Terms of Service; and remain jointly and severally responsible with each end customer for compliance, as set out in Section 10 of the Terms of Service.
6.Data transmitted through the API
Data submitted or retrieved through the API is User Content under the Terms of Service and personal data within it is handled under the Privacy Policy. The account holder warrants that all notices and consents required by law, including the DPDP Act, have been given and obtained before personal data of end customers or their personnel is transmitted to the Company, and that it will keep records sufficient to evidence this. The Company also records technical usage of the API, such as call volumes, endpoints, environments, and outcomes, to operate, secure, bill for, and improve the Platform, and may present that usage to the account holder in its console.
7.Prohibited integrations
The account holder shall not use the API to:
- misrepresent its identity, its authority, or the origin of an instruction;
- list a scrip, or approve a duty cover, for any entity without a subsisting mandate, or contrary to an entity's instruction;
- access, probe, or automate any Government Portal other than through the Platform's intended operation;
- build a service that resells raw access to the API without a written platform agreement;
- publish benchmarks or performance measurements of the API without the Company's prior written consent; or
- test the Platform's security other than through coordinated disclosure to amin@eximfiles.io.
8.Versioning, changes, suspension
The Company may evolve the API, and will use reasonable efforts to give notice of breaking changes through the documentation or by email before they take effect. The Company may suspend keys or endpoints immediately where necessary for security, legal risk, Government Portal instability, or protection of other users, with notice where practicable. Unless a signed agreement states otherwise, the API is provided without service-level commitments, and maintenance and emergency interventions may occur without notice. Sandbox environments and their artefacts may be reset, altered, or purged at any time, and the account holder shall not rely on their persistence.
9.Order of precedence
If documents conflict, the order of precedence is: (1) a signed production or platform agreement; (2) these API Terms; (3) the Terms of Service; (4) the technical documentation. The Terms of Service otherwise apply in full to all API use, including its limitation of liability, indemnity, governing law, arbitration, and grievance provisions.