Legal · API Terms
API Terms
Access and credentials
These API Terms govern access to the Miskari application programming interface ("API"), webhooks, and programmatic exports provided by Hyrax LLC d/b/a Miskari. They are part of, and incorporated into, the Terms of Service and Acceptable Use Policy. By generating an API key or calling the API, you agree to these terms.
API access is authenticated with API keys issued from your organization's settings. You are responsible for keeping keys secret, for all activity performed with your keys, and for rotating or revoking a key you believe is compromised. Keys are scoped (for example read or write) and limited to the data of the organization that issued them. Do not embed keys in client-side code or public repositories.
Permitted use
You may use the API to integrate the service with your own systems and authorized tools. You may not use the API to exceed published rate limits or circumvent technical limits; access data outside your organization; resell, sublicense, or redistribute Miskari data or expose it through a competing product; build a service that replicates the core function of Miskari from API data; or do anything prohibited by the Acceptable Use Policy.
Rate limits and fair use
The API enforces rate limits and pagination. We may throttle, suspend, or revoke access that exceeds fair use, degrades the service for others, or appears abusive. We may change limits with reasonable notice.
Webhooks and share links
Outbound webhooks are signed (HMAC); you must verify the signature before trusting a payload and should treat the endpoint as receiving untrusted input. Public share links and token-scoped links (for example read-only financial summaries, document-request uploads, calendar feeds, and the rental application form) expose only the data you choose to share; you are responsible for who you distribute them to and for revoking them when no longer needed.
Data and privacy
Data you retrieve through the API is your organization's data, handled under the Privacy Policy and, where applicable, the DPA. You remain the controller of personal data you extract and are responsible for its lawful handling once it leaves the service. Financial and tenant data exposed via the API may be sensitive; secure it accordingly.
Changes and deprecation
The API is versioned. We may add functionality at any time and may deprecate or change endpoints with reasonable advance notice for breaking changes. We may modify or discontinue the API, in whole or part, consistent with the Terms of Service.
No warranty; limitation
The API is provided "as is" under the disclaimers and limitation of liability in the Terms of Service. We do not guarantee uninterrupted or error-free API availability.
Contact
API questions or to report misuse: sales@miskari.com.