Skip to content
Legasus
TERMS

API & MCP Developer Terms

The terms for approved API, MCP, webhook, and other programmatic access to Legasus, including credentials, scopes, rate limits, and security.

Effective: Effective April 1, 2026Version: Version 4Jurisdiction: Illinois, USAContact: support@legasus.ai

API and MCP access is case-by-case and not generally public.

These API & MCP Developer Terms (“Developer Terms”) apply when AIDAN LLC d/b/a Legasus grants Customer access to a Legasus application programming interface (“API”), Model Context Protocol interface (“MCP”), developer credential, service account, webhook, integration interface, or other programmatic access method (collectively, “Developer Access”).

These Developer Terms supplement the Master Subscription Agreement. If there is a conflict concerning Developer Access, these Developer Terms control unless an Order Form expressly states otherwise.

1. Limited Access Grant

Subject to the Terms, Legasus grants Customer a limited, revocable, nonexclusive, nontransferable right during the applicable subscription term to use Developer Access solely for Customer's authorized internal business purposes and approved integrations.

Developer Access is not generally public and may require case-by-case approval, technical review, security review, additional fees, usage limits, or a specific Order Form.

2. Credentials and Secrets

Customer will:

  • safeguard API keys, OAuth credentials, MCP credentials, tokens, service-account credentials, webhook secrets, and other authentication material;
  • not embed secrets in publicly accessible client-side code or repositories;
  • rotate or revoke compromised credentials promptly;
  • limit access to authorized personnel and systems;
  • use separate credentials where Legasus requires environment or application separation; and
  • notify Legasus promptly of suspected compromise.

Customer is responsible for activity performed using Customer-issued credentials unless caused by Legasus's breach of its own security obligations.

3. Scope and Permissions

Customer may access only resources and data within the scopes Legasus authorizes.

Customer will not use Developer Access to:

  • bypass ordinary matter/user permissions;
  • access another Customer's data;
  • elevate privileges without authorization;
  • evade feature, plan, storage, or AI usage restrictions;
  • access endpoints or methods not documented or authorized for Customer; or
  • recreate disabled functionality through undocumented interfaces.

4. Rate Limits and Usage Controls

Legasus may impose and modify:

  • request-rate limits;
  • concurrency limits;
  • token limits;
  • storage limits;
  • data-transfer limits;
  • webhook limits;
  • model-call limits;
  • connection limits; and
  • other technical quotas.

Legasus may throttle or temporarily suspend access that exceeds limits, threatens stability, creates security risk, or materially interferes with other Customers.

5. Security Requirements

Customer will use reasonable security appropriate to the data and integration, including:

  • encrypted transport;
  • secure secret storage;
  • authentication and authorization;
  • least privilege;
  • input validation;
  • dependency management;
  • logging appropriate to risk;
  • incident response; and
  • timely patching of material vulnerabilities.

Legasus may require a security review before granting or continuing Developer Access.

6. Customer Data

Customer's rights and obligations concerning Customer Data remain governed by the MSA, DPA, Security Addendum, and BAA where applicable.

Customer may retrieve or transmit Customer Data through Developer Access only where Customer has authority to do so and only within approved scopes.

7. Protected Health Information

Customer will not use Developer Access to transmit, retrieve, or Process PHI unless:

  1. the parties have an executed BAA where required;
  2. the relevant API/MCP configuration and connected services are expressly designated HIPAA-eligible; and
  3. Customer's integration meets applicable security and HIPAA requirements.

Ordinary availability of an endpoint does not mean the endpoint is approved for PHI.

8. AI and MCP

Where Developer Access can invoke AI-Enabled Features or expose data to an AI system:

  • the AI AUP applies;
  • no-generalized-training commitments remain governed by the MSA/DPA;
  • Customer must maintain required human review;
  • Customer may not use automated calls to extract, replicate, distill, or train a competing model or service; and
  • Customer must not use MCP tools or agents to bypass permission or approval controls.

9. No Reverse Engineering or Competitive Extraction

Customer will not use Developer Access to:

  • discover nonpublic architecture;
  • enumerate or exploit undocumented endpoints;
  • extract system prompts, model weights, orchestration logic, proprietary schemas, embeddings, or hidden instructions;
  • systematically copy Legasus features for a competing product;
  • construct a competing training dataset from Legasus AI Output; or
  • circumvent technical or contractual protections.

10. Third-Party Applications

If Customer connects Developer Access to a third-party application, Customer is responsible for:

  • evaluating the third party's security and privacy;
  • complying with third-party terms;
  • limiting data shared to what is necessary;
  • obtaining required client/user authorization;
  • configuring access appropriately; and
  • disabling the integration when no longer needed.

Legasus is not responsible for Customer Data after it is transmitted to an independent third party at Customer's direction, except where that third party is acting as a Legasus Subprocessor.

11. Webhooks

Customer must secure webhook endpoints, validate authenticity using available mechanisms, handle retries/idempotency appropriately, and avoid exposing sensitive webhook payloads in insecure logs.

Legasus may retry, delay, or discontinue webhook deliveries according to technical design and may disable endpoints that repeatedly fail or create risk.

12. Developer Documentation

Customer will follow current Documentation. Legasus may update endpoints, schemas, versions, scopes, authentication methods, or Documentation as the Services evolve.

Where reasonably practicable, Legasus may provide notice before materially deprecating a production API version used by paying Customers, but no minimum deprecation period applies unless stated in an Order Form.

13. Beta and Experimental Interfaces

Beta, preview, or experimental APIs/MCP interfaces may change or be discontinued without notice, are excluded from SLA commitments, and should not be used for critical production workflows unless Customer accepts the associated risk.

14. Monitoring and Abuse Prevention

Legasus may monitor Developer Access usage, metadata, errors, and security events to operate, secure, enforce limits, investigate abuse, and support the Services.

15. Suspension or Revocation

Legasus may suspend, throttle, rotate credentials, restrict scopes, or revoke Developer Access where reasonably necessary for:

  • security;
  • excessive use;
  • violation of the Terms;
  • nonpayment;
  • suspected compromise;
  • legal compliance;
  • provider limitations;
  • material product changes; or
  • protection of Customers or the Services.

Where feasible, Legasus will work with Customer to restore compliant access after the issue is resolved.

16. Support and SLA

Developer Access is covered by an SLA only if the applicable Order Form expressly includes it. Third-party dependencies and Beta interfaces are excluded unless stated otherwise.

17. Intellectual Property

Legasus retains all rights in Developer Access, APIs, MCP servers/tools, schemas, Documentation, SDKs supplied by Legasus, underlying technology, and improvements.

Customer owns Customer-created application code, subject to Legasus's rights in the Services and any third-party components.

18. Changes

Legasus may update these Developer Terms in accordance with the MSA.

19. Contact

Developer/support questions: support@legasus.ai
Security: security@legasus.ai
Legal: legal@legasus.ai