Terms of service

The short version: you point traffic at us, we validate it against your contract, and neither of us surprises the other. Last updated 8 August 2026.

1. The service

openapi-proxy.com provides API mocking, validation and drift reporting against OpenAPI documents you supply: hosted mock URLs, a validating reverse proxy in observe and enforce modes, and reporting on where traffic disagrees with the published contract. The service is operated by LNATION ("we", "us").

Fail-open is a design commitment: the gateway is built so that a failure of validation forwards your traffic rather than dropping it. It is not a guarantee that traffic can never be affected - see section 6.

2. Accounts

You need an account for anything beyond an anonymous 24-hour mock. You are responsible for what happens under your account, for keeping credentials secret, and for the accuracy of your billing details. Accounts belong to the organisation named on them; members act with the role their account owner grants.

3. Acceptable use

Do not use the service to proxy unlawful traffic, to attack third parties, or as generic free hosting - free-tier quotas are hard limits precisely so a free proxy cannot become an open relay. Do not probe or disrupt other tenants. Security research against your own tenant is welcome (see the security page); research against anyone else's is not.

4. Plans and billing

Paid plans are billed by subscription through Stripe, metered on requests proxied, with overage billed per million as published on the pricing page. On paid plans, exceeding your ceiling never causes us to reject your traffic; it bills overage. If a payment fails we retry and email you; after 14 days the account downgrades to the free tier, which caps traffic but deletes nothing for a further 30 days. Prices may change with at least 30 days' notice, taking effect at your next renewal. You can cancel at any time from the billing portal; paid periods already started are not refunded except where the law says otherwise.

5. Your content and data

Your specs, your traffic and your drift data are yours. We process proxied traffic as your processor, as described in the data processing addendum - the one-sentence summary being that violation fingerprints and one redacted example per fingerprint per window are what we keep, never full request or response bodies. Aggregate, non-identifying statistics (for example, which categories of contract violation are most common across the service) may be used to improve and describe the service; nothing that identifies you, your customers or your API shapes is published.

6. Availability and support

Service status is published at /status, including incident history. A contractual SLA (99.9%, 4-hour response) exists on the Business tier only, where it is priced; other tiers get honest best effort and the support channel of their plan. We may suspend service for a tenant that endangers the platform or other tenants, and will tell you why.

7. Warranties and liability

The service is provided as-is. To the extent the law allows, our total liability for any claims in a year is capped at the fees you paid us in the twelve months before the claim, and neither of us is liable to the other for indirect or consequential loss. Nothing in these terms limits liability that cannot lawfully be limited.

8. Termination

You can stop using the service and delete your account at any time; deletion removes your proxies promptly and purges stored data on the schedule in the DPA. We may terminate for material breach of these terms with notice naming the breach, or immediately for abuse under section 3.

9. The rest

These terms are governed by the law of England and Wales, and its courts have jurisdiction. If we change these terms materially we will email account owners at least 30 days before the change takes effect. Questions to admin@openapi-proxy.com.