Terms of Service
Effective October 6, 2026 · Last updated October 6, 2026
These Terms of Service govern your use of AnyOAuth’s website, dashboard, and hosted sign-in services. By creating an account or using the service, you agree to these terms. If you use AnyOAuth for an organization, you confirm that you are authorized to agree on its behalf.
The service
AnyOAuth connects applications to supported identity providers through a consistent sign-in and profile API. It issues short-lived AnyOAuth profile tokens; it does not provide customer applications with provider access tokens or access to provider inboxes, repositories, files, or other unrelated APIs.
Your application owns its user records, permissions, and sessions. Provider availability, identity fields, and sign-in behavior depend on the provider, its policies, and the configuration of the service. A listed or planned integration is not a guarantee that it is currently available.
Your account and credentials
You must have legal capacity to enter this agreement and provide accurate account information. Keep your provider account and application credentials secure. Keep client secrets on your backend, restrict access to your dashboard, and notify us promptly at hello@anyoauth.com if you suspect unauthorized use.
You are responsible for activity under your account and projects, including activity by people you authorize. Do not share credentials publicly or place client secrets in browser or mobile application bundles.
Your application responsibilities
You are responsible for implementing the documented flow, verifying callback state, protecting PKCE verifiers, registering exact callback URLs, and securing your own application sessions. Revoking an AnyOAuth token does not end sessions your application has already created.
You must provide appropriate notices to your users, have a lawful basis for processing their information, obtain consent where required, and comply with applicable laws and identity-provider terms. Use profile information only for authorized purposes. You are responsible for data copied into your application and for handling requests concerning that data.
Acceptable use
- Do not use AnyOAuth for unlawful, fraudulent, deceptive, or abusive activity, or to impersonate someone without authorization.
- Do not collect passwords through imitation provider pages, steal credentials, or misrepresent what users are authorizing.
- Do not bypass security controls, project boundaries, rate limits, or access restrictions, or attempt to access another customer’s information.
- Do not interfere with the service, introduce malicious code, or make requests intended to overwhelm its infrastructure.
- Do not sell or misuse identity information, infringe others’ rights, or use the service in violation of provider policies.
Report security issues privately to hello@anyoauth.com. Obtain authorization before conducting tests that could affect other customers or the availability of the service.
Privacy and data
Our Privacy Policy explains the information we process and your choices. You retain your rights in your application data. You authorize us to process information and share the identity profile with the intended application as needed to provide sign-in, operate and secure the service, and comply with legal obligations.
If your use requires a separate data-processing agreement or specific processing-location commitments, contact us before submitting that data. These terms do not represent a certification or guarantee that your application satisfies any particular regulatory framework.
Fees and service limits
Any applicable fees, usage limits, and payment terms will be disclosed when you select a paid offering or enter a separate agreement. These terms do not themselves impose a subscription fee. We may apply reasonable rate limits and usage restrictions to protect service reliability.
Third-party services and SDKs
Identity providers and other third-party services operate independently and have their own terms and privacy policies. We do not control their availability, account decisions, or changes to their APIs. We may change or discontinue an integration when a provider changes its requirements or access.
AnyOAuth retains its rights in the hosted service, website, branding, and documentation. SDKs and other software distributed with a separate license are governed by that license. You may use the service and documentation for your authorized integrations under these terms.
Suspension and termination
You may stop using the service at any time, delete projects in the dashboard, or contact us to request account deletion. Export or retain information your application needs before deleting a project.
We may restrict, suspend, or terminate access for a material violation of these terms, security threats, abuse, nonpayment of agreed fees, or legal requirements. Where practical and appropriate, we will provide notice and an opportunity to resolve the issue. Immediate action may be necessary to protect users or the service.
After termination, you must stop using the affected credentials and integrations. Information is handled as described in our Privacy Policy. Provisions concerning accrued obligations, intellectual property, disclaimers, and liability continue where relevant.
Availability and disclaimers
Unless we agree otherwise in writing, the service is provided “as is” and “as available,” to the extent permitted by law. We do not guarantee uninterrupted availability, error-free operation, or suitability for a particular purpose. No service-level agreement applies unless separately agreed.
Social sign-in does not guarantee that an identity provider used multifactor or phishing-resistant authentication. You must assess whether the integration is appropriate for your application and protect the permissions and sessions you issue.
Limitation of liability
To the extent permitted by law, AnyOAuth is not liable for indirect, incidental, special, or consequential losses, including lost profits, business interruption, or loss of data. To the same extent, our aggregate liability arising from the service is limited to the fees you paid us for the service in the 12 months before the event giving rise to the claim.
Nothing in these terms excludes liability that cannot legally be excluded or limits mandatory rights you have under applicable law.
Changes and resolving questions
We may update the service and these terms. We will update the effective date and provide notice of material changes where required. Continuing to use the service after updated terms take effect constitutes acceptance, subject to applicable law.
If you have a concern or dispute, contact us first so we can try to resolve it. Any separate written agreement with us controls where it expressly conflicts with these terms.
Contact
Questions about this policy or the service? Contact AnyOAuth at hello@anyoauth.com.