Skip to document
OneVault
Terms of Service Privacy Policy Cookies & advertising Acceptable use Developer terms
Sign in

ONEVAULT LEGAL

OneVault Developer Terms

Version
2026-10-v1
Effective date
1 October 2026

Provider: OneVault LLC, a limited liability company in the United States

In short: These terms apply if you apply for developer access or offer "Sign in with OneVault" in your website or app. You must pass an authenticity review, integrate securely, request only the data you need, protect users' data, never sell it, honour disconnection and deletion, and tell us about security incidents within 72 hours. Access is free but not unlimited, is provided "as is", and can be suspended or revoked, including without notice for abuse.

Contents
  1. 1. Scope and acceptance
  2. 2. Definitions
  3. 3. Developer eligibility and authenticity review
  4. 4. Registering apps
  5. 5. Integration and security requirements
  6. 6. Credentials and secrets
  7. 7. User data: permitted use
  8. 8. Privacy policy and user-facing obligations
  9. 9. Disconnection, deletion and user requests
  10. 10. Security incidents
  11. 11. Audits and cooperation
  12. 12. Fair use, capacity and changes
  13. 13. Branding and publicity
  14. 14. Suspension and termination
  15. 15. Confidentiality
  16. 16. No warranty
  17. 17. Limitation of liability
  18. 18. Indemnification
  19. 19. Compliance with law, export controls and sanctions
  20. 20. Governing law and disputes
  21. 21. General
  22. 22. Contact

Contents

  1. 1. Scope and acceptance
  2. 2. Definitions
  3. 3. Developer eligibility and authenticity review
  4. 4. Registering apps
  5. 5. Integration and security requirements
  6. 6. Credentials and secrets
  7. 7. User data: permitted use
  8. 8. Privacy policy and user-facing obligations
  9. 9. Disconnection, deletion and user requests
  10. 10. Security incidents
  11. 11. Audits and cooperation
  12. 12. Fair use, capacity and changes
  13. 13. Branding and publicity
  14. 14. Suspension and termination
  15. 15. Confidentiality
  16. 16. No warranty
  17. 17. Limitation of liability
  18. 18. Indemnification
  19. 19. Compliance with law, export controls and sanctions
  20. 20. Governing law and disputes
  21. 21. General
  22. 22. Contact

1. Scope and acceptance

These Developer Terms ("Developer Terms") govern your application for developer access and your use of OneVault's developer area, OpenID Connect endpoints, client credentials, documentation, user information and related services (the "Developer Services") to offer sign-in with OneVault in a website, mobile app or other service ("App"). They supplement the OneVault Terms of Service and Acceptable Use Policy, which also apply to you. If these Developer Terms conflict with the Terms of Service regarding the Developer Services, these Developer Terms control.

You accept these Developer Terms when you submit a developer application, tick the agreement box, or use the Developer Services. If you act for a company or other organization, you confirm that you have authority to bind it, and "you" means that organization. You must be of legal age to form a binding contract, and the Developer Services are provided for business and professional use, not as a consumer service.

2. Definitions

  • "Developer" or "you" means the individual or organization that applies for or uses the Developer Services.
  • "User" means a person who holds a OneVault ID account.
  • "User Data" means any information about a User that you receive through the Developer Services, including the user identifier, username, name, email address and verification status, country, date of birth, gender, assurance level, and phone number and its verification status, to the extent your App requests it and the User approves it on the consent screen.
  • "Credentials" means client identifiers, client secrets, keys, tokens, authorization codes and any other credentials issued by or used with OneVault.
  • "Issuer" means the OneVault OpenID Connect issuer identifier, and "Subject" means the user identifier (sub claim) that OneVault issues for your App.

3. Developer eligibility and authenticity review

OneVault approves only authentic developers. When you apply, you must provide accurate and complete information, which may include your business or trading name, business address, website, official email address (which you must verify), official social media profiles, WhatsApp number and your role. You must keep this information current and tell us promptly of any change of ownership or control.

OneVault may, at its sole discretion: verify the information you provide; request additional evidence (such as registration documents, proof of address or proof of control of a domain or social profile); approve, reject or place any application on hold; and require re-verification at any time. We are not obliged to give reasons for rejecting an application. Approval is personal to you, does not transfer with an App or business without our consent, and is not an endorsement.

Providing false, misleading or incomplete information, or concealing the identity of the person or organization that controls an App, is grounds for immediate rejection, suspension or revocation.

4. Registering apps

Each App must be registered separately and may be subject to its own review. For each App you must provide an accurate name, description, logo, website, privacy policy URL, and the exact redirect URIs the App uses, and describe why each item of User Data is needed. You must not register an App that you do not own or control, that imitates another brand or OneVault, or whose purpose you misrepresent. Testing and production configurations must be kept separate. OneVault may approve, reject, limit the data available to, or require changes to any App.

5. Integration and security requirements

You must integrate securely and follow OneVault's current integration documentation, OpenID Connect and current OAuth 2.0 security best practices. In particular, you must:

  1. use the authorization code flow with PKCE (Proof Key for Code Exchange, using the S256 method) for every App, including server-side Apps;
  2. register exact redirect URIs and use only those URIs; wildcard, open or user-controlled redirect targets are not permitted, and production redirect URIs must use HTTPS (or a platform-approved scheme for native apps);
  3. validate every ID token and response, including issuer, audience, signature, expiry, nonce and state, using a maintained OpenID Connect library;
  4. identify users by the combination of issuer and subject (iss + sub), and never by email address, username, phone number or name, which can change or be reassigned;
  5. treat a verified email or phone number only as evidence that the User controlled it when it was verified, not as proof of legal identity;
  6. keep your own sessions, roles, permissions and authorization decisions; OneVault sign-in establishes who signed in, not what they may do in your App;
  7. protect against cross-site request forgery, token leakage, open redirects, clickjacking and injection; never place tokens or authorization codes in URLs you log or share;
  8. keep your software, dependencies and infrastructure patched and secure, and use industry-standard security measures appropriate to the sensitivity of User Data; and
  9. never frame, overlay, proxy, imitate or modify OneVault sign-in or consent pages, never collect OneVault passwords or codes, and never interfere with a User's consent decision.

6. Credentials and secrets

Credentials are OneVault's confidential information. You must: keep client secrets and keys only on secure servers or in an approved secret manager; never embed a client secret in browser code, mobile apps or other public clients; never commit Credentials to source code repositories or expose them in logs, tickets, chat, analytics or URLs; restrict access to people who need it; rotate Credentials immediately if they may have been exposed; and remove access for staff who leave. You are responsible for all activity carried out with your Credentials.

7. User data: permitted use

Request only what you need. You must request only the User Data that your App actually needs for the purpose you described and that the User can see on the consent screen. Phone number and its verification status, date of birth and gender may be requested only where genuinely needed. The consent screen lists every item your App requests and the User approves the request as a whole or declines to connect, so request only what your App cannot work without.

Use only for your App. You may use User Data only to provide, secure and support your App for that User, as described in your privacy policy and consistent with the consent the User gave.

You must not:

  • sell, rent, lease or trade User Data, or disclose it to data brokers, advertising networks or other third parties for their own purposes;
  • use User Data for cross-context behavioural advertising, or build profiles of Users across services;
  • combine pairwise identifiers or other User Data with data from other sources to re-identify Users or link their activity across apps, except with the User's clear consent and as permitted by law;
  • use User Data to make decisions about eligibility for credit, employment, housing, insurance or similar purposes;
  • use User Data to contact Users with unsolicited marketing without the consent required by law;
  • transfer User Data to another person as part of an asset sale without ensuring the recipient is bound by equivalent obligations and notifying OneVault; or
  • process User Data in breach of applicable data protection law.

You are an independent controller of the User Data you receive and are solely responsible for your processing of it, including having a lawful basis, providing required notices and honouring rights requests.

8. Privacy policy and user-facing obligations

You must publish, and link from your App and your OneVault App registration, a clear and accurate privacy policy that explains what User Data you collect, how you use and share it, how long you keep it, and how Users can access and delete it. You must also provide Users with a working support contact. You must identify your App accurately and must not suggest that OneVault operates, endorses or is responsible for your App.

9. Disconnection, deletion and user requests

When a User removes your App in OneVault's Connected apps, when a User deletes their OneVault account, or when OneVault notifies you of such events or of a revocation, you must: stop requesting or using OneVault tokens for that User; not attempt to regain access without the User signing in and consenting again; and handle the User's data in accordance with the User's request, your privacy policy and applicable law. You must provide a way for Users to request deletion of their account and data in your App, and honour valid deletion and other data rights requests within the time required by law. Where OneVault provides a revocation or account-event mechanism, you must implement it within a reasonable time after we make it available.

10. Security incidents

You must notify OneVault within 72 hours after becoming aware of any actual or reasonably suspected security incident that affects User Data, OneVault Credentials, tokens, or the security or integrity of OneVault sign-in (for example, leaked client secrets, compromised servers, or unauthorized access to User Data). Notify us through our contact form (choose "Developer integration" and the subject "Security incident"), and through any security contact channel we provide in the developer area. Your notice must describe the incident, the data and Users affected (as far as known), and the steps taken. You must promptly contain and remediate the incident, rotate affected Credentials, preserve relevant evidence, cooperate with OneVault's investigation, and comply with your own legal notification obligations to Users and authorities. You must not name OneVault in any public statement about an incident without our prior approval, except as required by law.

11. Audits and cooperation

On reasonable request, you must provide OneVault with information and evidence needed to confirm your compliance with these Developer Terms, including your security measures, data handling practices and responses to User complaints. Where we reasonably suspect a breach or a security risk, or where required by a regulator, you must cooperate with an investigation, which may include a review by OneVault or an independent assessor subject to reasonable confidentiality. OneVault may also run automated tests against your App's public integration (for example, checking redirect and token behaviour) and review public information about your App.

12. Fair use, capacity and changes

The Developer Services are currently provided free of charge. Free access does not mean unlimited capacity. OneVault may set and change rate limits, quotas and technical limits, and may throttle or suspend traffic that is excessive, abusive or harmful to the platform. We may introduce fees in the future with at least 30 days' notice; you will not be charged unless you agree.

We may change the Developer Services, endpoints, claims, scopes and documentation at any time. We will try to give reasonable notice of breaking changes that materially affect your integration, except where changes are needed for security, legal compliance or to prevent abuse, which may take effect immediately. We may update these Developer Terms by posting a new version; material changes will take effect at least 14 days after notice, and your continued use after that date means you accept them.

13. Branding and publicity

Subject to these Developer Terms and any brand guidelines we provide, OneVault grants you a limited, non-exclusive, non-transferable, revocable license to use the OneVault name and "Sign in with OneVault" button solely to identify the sign-in option in your approved App. You must not alter the marks, use them in a misleading way, register confusingly similar names or domains, or announce a partnership or endorsement without our prior written consent. OneVault may identify you and your App as using OneVault sign-in, and may list your App name and logo in User-facing screens such as Connected apps and consent screens.

14. Suspension and termination

OneVault may, at its discretion, suspend, restrict, limit the data available to, or revoke any App, Credential or developer account, in whole or in part:

  • immediately and without notice where we suspect abuse, fraud, misleading consent, a security risk or incident, unlawful activity, harm to Users, or a threat to the Services;
  • where you breach these Developer Terms or fail to remediate a problem when asked; or
  • where you fail to respond to our requests, your information is outdated or cannot be verified, or your App is inactive.

Where appropriate and safe, we will tell you the reason and any steps needed to restore access, but we are not obliged to reinstate you. You may stop using the Developer Services at any time. We may terminate these Developer Terms or discontinue the Developer Services on 30 days' notice, or immediately in the circumstances above. On termination you must stop using Credentials and OneVault marks, and your obligations regarding User Data already received (Sections 7 to 11), confidentiality, indemnity and liability survive. Suspension or termination cannot recall User Data already shared, and you remain responsible for it.

15. Confidentiality

Non-public information that OneVault gives you, including Credentials, non-public documentation, security information and review communications, is confidential. You must use it only to use the Developer Services, protect it with at least reasonable care, and not disclose it except to your personnel who need it and are bound by confidentiality, or as required by law.

16. No warranty

THE DEVELOPER SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTIES OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED BY LAW, ONEVAULT DISCLAIMS ALL WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT. ONEVAULT DOES NOT WARRANT THAT THE DEVELOPER SERVICES WILL BE UNINTERRUPTED, ERROR-FREE OR SECURE, THAT THEY WILL MEET YOUR REQUIREMENTS, THAT ANY SERVICE LEVEL WILL BE ACHIEVED, OR THAT ANY USER INFORMATION IS ACCURATE. NO SERVICE LEVEL AGREEMENT APPLIES UNLESS AGREED IN A SEPARATE SIGNED CONTRACT.

17. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW: (A) ONEVAULT AND ITS SUBSIDIARIES, AFFILIATES AND THEIR PERSONNEL WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, BUSINESS, GOODWILL, DATA OR USERS, ARISING OUT OF OR RELATING TO THE DEVELOPER SERVICES OR THESE DEVELOPER TERMS; AND (B) ONEVAULT'S TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THE DEVELOPER SERVICES OR THESE DEVELOPER TERMS WILL NOT EXCEED THE GREATER OF THE FEES YOU PAID TO ONEVAULT FOR THE DEVELOPER SERVICES IN THE 12 MONTHS BEFORE THE CLAIM AROSE OR ONE HUNDRED UNITED STATES DOLLARS (US$100). THESE LIMITATIONS DO NOT APPLY TO LIABILITY THAT CANNOT BE LIMITED UNDER APPLICABLE LAW.

18. Indemnification

You will defend, indemnify and hold harmless OneVault LLC, its subsidiaries and affiliates, and their officers, members, managers, employees and agents from and against all claims, demands, investigations, losses, liabilities, damages, fines, penalties, costs and expenses (including reasonable legal fees) arising out of or relating to: (a) your App and its products, services, content and operation; (b) your collection, use, disclosure, security or other processing of User Data; (c) any security incident affecting your systems or Credentials; (d) your breach of these Developer Terms, the Terms of Service or the Acceptable Use Policy; (e) your violation of any law or third-party right; or (f) any dispute between you and a User. OneVault may participate in the defence with counsel of its choice at its own cost, and you may not settle any claim that imposes an obligation or admission on OneVault without our written consent.

19. Compliance with law, export controls and sanctions

You must comply with all laws applicable to your App and your processing of User Data, including data protection, consumer protection, anti-spam, children's privacy, export control and sanctions laws. You represent that neither you nor any person that owns or controls you is located in a comprehensively sanctioned country or region or identified on any applicable sanctions or restricted-party list, and you must not make your App available through OneVault sign-in in violation of those laws. Your App must not be directed to children under 13, and if it is used by children you are solely responsible for complying with children's privacy laws.

20. Governing law and disputes

These Developer Terms are governed by the laws of the United States and of the State in which OneVault LLC is organized, without regard to conflict-of-law rules. Any dispute arising out of or relating to these Developer Terms or the Developer Services will be resolved exclusively in the state or federal courts located in that State, and each party consents to their jurisdiction, except that OneVault may seek injunctive relief in any competent court to protect its Services, Users, Credentials or intellectual property. If you are an individual developer who is a consumer under the law of your country, mandatory consumer protections of that law continue to apply.

21. General

You may not assign these Developer Terms without our prior written consent; we may assign them in connection with a merger, reorganization or sale of assets, or to an affiliate. These Developer Terms, together with the Terms of Service, Acceptable Use Policy and any separate signed agreement, are the entire agreement regarding the Developer Services. If a provision is unenforceable, it will be modified to the minimum extent necessary and the rest will remain in effect. Our failure to enforce a provision is not a waiver. Nothing creates a partnership, joint venture, agency or employment relationship. You are an independent controller of User Data, and nothing in these Developer Terms makes OneVault your processor.

22. Contact

For developer questions and security incident notices, use our contact form and choose "Developer integration". Legal notices must also be sent through the contact form (choose "Other question" and the subject "Legal notice"). On request, we will tell you the State in which OneVault LLC is organized and provide a postal address for service of formal legal process.

Back to top

OneVault

OneVault LLC ยท One secure identity

Terms of Service Privacy Policy Cookies & advertising Acceptable use Developer terms Security