API Terms
These Paymenture API Terms ("API Terms") govern access to and use of the Paymenture application programming interfaces, developer tools, SDKs, webhooks, integrations, credentials, sandbox environments, and related technical services (collectively, the "APIs").
These API Terms are incorporated into and form part of the applicable Paymenture Terms of Service.
BY ACCESSING, INTEGRATING WITH, OR USING THE APIS, YOU AGREE TO BE BOUND BY THESE API TERMS.
API Access & License
1.1 Limited License
Subject to compliance with these API Terms and all applicable Paymenture agreements and policies, Paymenture grants you a limited, non-exclusive, non-transferable, revocable license to access and use the APIs solely:
- for authorized business purposes;
- in connection with approved Paymenture Services; and
- in accordance with Paymenture documentation and technical
requirements.
1.2 Ownership
Paymenture and its licensors retain all rights, title, and interest in and to:
- the APIs;
- software;
- SDKs;
- technical documentation;
- developer portals;
- specifications;
- trademarks;
- data structures; and
- related intellectual property.
No ownership rights are transferred to you.
1.3 Sandbox & Test Environments
Paymenture may provide sandbox, staging, or testing environments for development purposes.
Sandbox environments:
- may contain simulated data;
- may not reflect production functionality;
- may be modified or discontinued at any time; and
- are provided without warranties.
API Credentials & Security
2.1 API Credentials
Paymenture may issue:
- API keys;
- client credentials;
- authentication tokens;
- OAuth credentials;
- webhook secrets; or
- other access credentials.
You are solely responsible for:
- safeguarding credentials;
- restricting unauthorized access;
- securing infrastructure;
- protecting API keys;
- protecting authentication tokens; and
- maintaining appropriate access controls.
2.2 Security Procedures
You agree to maintain commercially reasonable security procedures designed to:
- prevent unauthorized access;
- secure credentials and authentication methods;
- prevent fraud and misuse;
- monitor API access;
- secure transmitted data; and
- protect systems and users.
2.3 Compromised Credentials
You must immediately notify Paymenture if:
- API credentials are compromised;
- unauthorized access is suspected;
- fraudulent activity is detected;
- webhook endpoints are compromised; or
- security incidents occur.
Paymenture may immediately suspend or rotate credentials where reasonably necessary to protect the APIs, Services, or users.
Permitted Use
3.1 Authorized Use
You may only use the APIs:
- in compliance with applicable law;
- in compliance with Paymenture policies;
- for authorized business purposes; and
- in accordance with Paymenture documentation.
3.2 Prohibited Use
You may not:
- use the APIs for unlawful activity;
- facilitate fraud;
- facilitate sanctions evasion;
- facilitate unauthorized money transmission;
- interfere with platform security;
- scrape or extract unauthorized data;
- reverse engineer the APIs;
- bypass authentication controls;
- overload systems;
- conduct denial-of-service attacks;
- introduce malicious code;
- resell API access without authorization; or
- use the APIs in a manner that creates legal, compliance,
cybersecurity, operational, or reputational risk.
3.3 Compliance Obligations
You are responsible for ensuring that your API integrations comply with:
- AML obligations;
- sanctions laws;
- privacy laws;
- card network rules;
- cybersecurity requirements;
- blockchain compliance requirements; and
- applicable regulations.
API Monitoring & Rate Limits
4.1 Monitoring
Paymenture may monitor:
- API usage;
- request volume;
- transaction activity;
- integration behavior;
- security indicators;
- authentication events;
- webhook activity;
- blockchain-related activity; and
- behavioral patterns.
4.2 Rate Limits
Paymenture may impose:
- rate limits;
- throughput limits;
- transaction limits;
- velocity controls;
- authentication restrictions; or
- geographic restrictions.
Paymenture may modify limits at any time.
4.3 Suspension Rights
Paymenture may suspend, throttle, restrict, or terminate API access where reasonably necessary to:
- protect system integrity;
- prevent fraud;
- address cybersecurity risks;
- comply with law;
- comply with sanctions obligations;
- investigate suspicious activity; or
- mitigate operational or reputational risk.
Webhooks & Data Processing
5.1 Webhooks
Paymenture may provide webhook functionality for event notifications and transaction updates.
You are responsible for:
- securing webhook endpoints;
- validating webhook signatures;
- monitoring webhook delivery;
- maintaining endpoint availability; and
- protecting transmitted data.
5.2 Data Processing
Use of the APIs may involve access to:
- transaction data;
- personal information;
- wallet information;
- blockchain data;
- payment information; or
- compliance-related information.
You agree to:
- process such data lawfully;
- maintain appropriate privacy protections;
- comply with applicable privacy laws;
- implement appropriate safeguards; and
- avoid unauthorized disclosure or misuse.
5.3 Blockchain Data
API functionality involving digital assets or blockchain activity may expose:
- wallet addresses;
- transaction hashes;
- blockchain metadata;
- counterparties; or
- blockchain analytics indicators.
Blockchain transactions may be publicly visible and irreversible.
Digital Asset & Payment Functionality
Certain APIs may permit:
- digital asset transfers;
- stablecoin settlement;
- wallet integrations;
- payout orchestration;
- card provisioning;
- virtual account functionality;
- FX functionality; or
- blockchain-based settlement.
Such functionality is subject to:
- the Digital Asset & Blockchain Terms;
- Wallet & Virtual Account Terms;
- Cardholder Terms;
- sanctions screening;
- Travel Rule obligations;
- blockchain analytics monitoring; and
- applicable law.
Paymenture may restrict or discontinue API functionality at any time.
Third-Party Dependencies
API functionality may depend on:
- sponsor banks;
- payment processors;
- card issuers;
- blockchain networks;
- cloud providers;
- VASPs;
- payment networks;
- liquidity providers;
- compliance vendors; and
- telecommunications providers.
Paymenture does not guarantee:
- uninterrupted API availability;
- transaction completion;
- response times;
- exchange rates;
- blockchain confirmation speed;
- provider continuity; or
- system uptime.
Compliance & Regulatory Cooperation
Paymenture may:
- conduct sanctions screening;
- monitor transaction activity;
- conduct blockchain analytics;
- investigate suspicious activity;
- cooperate with regulators and law enforcement;
- freeze or reject transactions;
- restrict integrations;
- suspend API access; or
- disclose information where required by law.
You agree to cooperate with Paymenture in connection with:
- compliance reviews;
- investigations;
- sanctions screening;
- fraud investigations;
- cybersecurity incidents; or
- regulatory obligations.
Disclaimers & Limitation of Liability
9.1 No Warranty
THE APIS ARE PROVIDED "AS IS" AND "AS AVAILABLE." PAYMENTURE DISCLAIMS ALL WARRANTIES TO THE MAXIMUM EXTENT PERMITTED BY LAW.
9.2 Third-Party Dependency Disclaimer
Paymenture shall not be liable for delays, interruptions, failures, restrictions, freezes, or outages caused by:
- banks;
- blockchain networks;
- Service Providers;
- payment networks;
- cloud infrastructure failures;
- sanctions actions;
- cybersecurity incidents;
- blockchain congestion;
- stablecoin depegging;
- liquidity failures; or
- force majeure events.
9.3 Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, PAYMENTURE SHALL NOT BE LIABLE FOR:
- INDIRECT DAMAGES;
- CONSEQUENTIAL DAMAGES;
- LOST PROFITS;
- DATA LOSS;
- API OUTAGES;
- NETWORK FAILURES;
- BLOCKCHAIN FAILURES;
- CYBERSECURITY INCIDENTS; OR
- THIRD-PARTY ACTIONS.
Indemnification
You agree to indemnify, defend, and hold harmless Paymenture and its affiliates, officers, directors, employees, contractors, licensors, and Service Providers from and against any claims, liabilities, losses, damages, costs, penalties, fines, or expenses arising from:
- your API integrations;
- your systems or infrastructure;
- your violation of law;
- your breach of these API Terms;
- fraud or misconduct;
- data misuse;
- cybersecurity failures;
- sanctions violations; or
- unauthorized API activity.
Termination of API Access
Paymenture may suspend or terminate API access immediately where:
- required by law;
- suspicious activity is detected;
- sanctions concerns arise;
- fraud risk exists;
- cybersecurity concerns exist;
- Paymenture determines unacceptable risk exists; or
- you violate these API Terms or other applicable agreements.
Upon termination, you must immediately cease use of the APIs and destroy or return confidential Paymenture materials where requested.
Changes to API Functionality
Paymenture may modify, discontinue, deprecate, or replace:
- APIs;
- endpoints;
- authentication methods;
- documentation;
- supported functionality;
- supported blockchains;
- supported currencies; or
- supported integrations
at any time.
Where reasonably practicable, Paymenture may provide advance notice of material API changes.
Contact Information
355 South 520 West, Suite 100
Lindon, Utah 84042
United States
Developer Support: developers@paymenture.com
Support: support@paymenture.com
Compliance: compliance@paymenture.com
Legal: legal@paymenture.com