1. Authorized access
This document is a draft for founder and legal review. It is not legal advice and does not create a commitment until approved and published.
Use a supported session or API key for an authorized Workspace. Keep credentials secret, scope requests correctly, and never expose service-role keys in browser code.
2. Requests and data
The customer is responsible for request input, imported data, Knowledge, Agent instructions, payloads, destinations, and external effects.
3. Security and replay
Validate inputs, protect secrets, use HTTPS endpoints, implement replay protection where relevant, and verify signatures for provider or webhook messages.
4. Rate limits and availability
Public rate limits, fair-use thresholds, support response targets, and availability commitments are not yet published. Requests may fail due to authentication, validation, provider, network, or service conditions.
5. API surface
Observed V1 areas include Agents, Calls, Campaigns, Leads/Usage, Webhooks, API keys, Actions reads, and Workflows reads. Internal verification routes and private service calls are not API commitments.
6. Webhooks and external effects
Customers own endpoint behavior, secret handling, idempotency, response interpretation, and downstream effects. A successful HTTP response does not prove business completion.
7. Versioning and changes
Versioned routes should be used where available. Bavio may change API behavior subject to approved notice and compatibility policy [API_CHANGE_POLICY].
8. Acceptable use
API use must follow the Acceptable Use Policy, Terms of Service, provider requirements, and applicable law.
9. Contact
Developer support: hello@bavio.in. Security: [SECURITY_EMAIL].
