API Terms
Last updated: 2026-08-01
These API Terms supplement the VehiclesDB Terms of Service (the "VehiclesDB Terms") and govern all access to and use of the VehiclesDB APIs, endpoints, keys, webhooks, and related developer tools (the "API"). Capitalized terms not defined here have the meanings in the VehiclesDB Terms. In case of conflict, these API Terms control for the API. By requesting an API key or making any API call, you accept these API Terms.
1. Keys and access
1.1 API access requires Credentials issued by us. Keys are issued to your organization, are non-transferable, and may be scoped, rate-limited, metered, rotated, suspended, or revoked by us at any time, with or without notice or cause. You are responsible for all requests made with your keys, including unauthorized ones. Keep secret keys secret; do not embed secret keys in client-side code; publishable keys may be used client-side only as documented.
1.2 You may not share, sell, rent, pool, or rotate keys or accounts to evade limits or pricing, and may not access the API with keys issued to another party.
2. Metering, limits, and plans
2.1 API usage is metered in credits or requests as described in the Documentation and your plan. Our metering records are authoritative and conclusive absent manifest error. Plan limits, rate limits, batch sizes, concurrency caps, and endpoint availability may be changed by us at any time. Exceeding limits may result in throttling, request rejection, suspension, or additional charges as stated in the plan.
2.2 Credits and free-tier allowances have no cash value, are non-transferable, and expire per plan or upon termination.
3. Permitted use; caching; storage
3.1 Subject to continuous compliance and payment, you may make API calls and use returned Content within your own applications and internal systems — including display of Content to your applications' end users as an integrated, incidental part of your own product — within your plan's scope. Serving API responses onward as a data product, reselling access, operating a proxy, wrapper, meta-search, or real-time re-serving layer over the API for third parties, re-indexing the Services or their contents, or using the API to populate a competing or substitute database or service is prohibited absent a signed Order Form. These restrictions are express contractual conditions of the access we provide, on every tier including the free tier.
3.2 Cached Content rules (VehiclesDB Terms § 5.3) apply: caching is permitted only where your plan says so, for a maximum of thirty (30) days per item without a refreshing call, and all cached items must be purged upon plan downgrade, suspension, termination, or our removal/correction notice. Resolution Results are exempt from this Section's refresh and purge obligations (VehiclesDB Terms § 5.4). Bulk pre-fetching, systematic enumeration, or exhaustive traversal of the catalog through the API to reconstitute a dataset is prohibited on all self-serve plans.
3.3 Any images, renderings, or visual assets served by the API are for display within your application and in marketing materials for your own product in which such display is incidental; they may not be redistributed on a standalone basis or used as a stock-imagery library, and must be hotlinked or cached strictly per the Documentation, and remain subject to the Third-Party IP provisions of the VehiclesDB Terms. We may suppress or replace any asset at any time.
4. Attribution
Attribution per VehiclesDB Terms § 10.3 applies on every plan unless expressly waived: a visible link in the designated form wherever API-derived data is publicly displayed. API responses include a machine-readable attribution object (source, url, license, dataset_version) on every plan without an express waiver; you shall not strip it from stored or onward-transmitted Content. Where a signed Order Form permits delivery of Content through your own API or data product, each response or record containing Content or data derived from it must include machine-readable source attribution ("source": "VehiclesDB", "source_url": "https://vehiclesdb.com" or the designated deep link) and, where displayed to end users, the visible link — unless your agreement expressly includes an attribution waiver. We may condition continued access on verified attribution.
5. Availability; versioning; deprecation
The API is provided without any availability, latency, support, freshness, or continuity commitment except as expressly purchased in an Order Form. We may version, modify, deprecate, or discontinue any endpoint, field, parameter, response shape, or behavior at any time. Where practicable we may announce breaking changes in the Documentation or changelog, but we are not obligated to do so on self-serve plans. Do not build in a way that assumes any endpoint, identifier, or field is permanent; identifier-migration mechanisms published in the Documentation must be implemented by you.
6. Webhooks
Webhook delivery is best-effort and unordered; you are responsible for endpoint security, verification of signatures as documented, de-duplication, and tolerance of retries and delays. We may suspend webhooks that fail persistently.
7. Security and abuse
You shall not probe, scan, overload, or test the vulnerability of the API except through a coordinated disclosure we approve in writing; shall not interfere with other customers' use; and shall promptly report suspected vulnerabilities or data leaks to [email protected]. We may throttle or block traffic patterns that we determine, in our sole discretion, degrade or endanger the Services.
8. Telemetry
All API traffic generates Usage Data owned by us (VehiclesDB Terms § 7.3), and API inputs are Submissions licensed to us (VehiclesDB Terms § 7.4), including for improving our datasets and resolution systems. Do not submit personal data through the API except as expressly documented and lawful.
9. AI/ML
AI/ML use of API Content is governed by VehiclesDB Terms § 8.1(j): training, pre-training, fine-tuning, distillation, weight updates, and training-dataset creation are prohibited absent a separate written license, and the express text-and-data-mining reservation applies to all API Content. Inference-time use — prompt context, retrieval-augmented generation, embeddings, vector retrieval, and agent or tool calls at runtime — is permitted within your plan limits, with persistent embeddings treated as Cached Content under § 3.2, except embeddings derived solely from Resolution Results (VehiclesDB Terms § 5.4).
10. Suspension and termination
We may suspend or revoke API access immediately and without notice for actual or suspected breach, abusive traffic, security risk, non-payment, or legal exposure. Upon any termination, all keys are deactivated and Cached Content must be deleted per the VehiclesDB Terms.