Developer terms
These Developer Terms apply when a business uses the Coherence API: the REST API at https://api.coherenceltd.com/v1 and the Model Context Protocol (“MCP”) server at https://api.coherenceltd.com/mcp (together, the “API”). They form part of the Licence Terms between Coherence Limited (“Coherence”) and the business that holds the workspace (the “Customer”). Words defined in the Licence Terms have the same meaning here. If these terms conflict with the Licence Terms, the Licence Terms prevail.
1. Who can use the API
API access is available on Business Licences for each Licensed Tool whose API Coherence has released; the plans show which. Individual Licences are web only. The API is for the Customer's own business, in line with Clause 3.1 of the Licence Terms.
2. API keys and scopes
- Workspace owners and admins create API keys in the workspace. Each key belongs to the workspace, has an expiry date, and carries only the scopes chosen for it, per tool.
- Keep keys secret. Do not put them in client-side code, public repositories or shared documents. Give each key only the scopes it needs, and revoke any key you believe is exposed.
- Scopes that can change things outside Coherence, such as sending receipts to Revolut, must be granted separately and only by an owner or admin.
- The Customer is responsible for everything done with its keys until they are revoked.
3. Allowances and rate limits
API and MCP calls count against the same monthly Allowance as use in the web workspace. The API also has rate limits (currently 120 requests per key per minute), published in the developer documentation. When a limit is reached, requests are refused until it resets. Do not work around Allowances or rate limits, for example by spreading calls across keys or workspaces.
4. AI clients and MCP
- The Customer may connect AI assistants and agents (“AI clients”) through MCP. The Customer chooses them, and is responsible for them and for what they do with the access it grants, including any action a tool allows.
- An AI client can act on instructions hidden in content it reads. Keep scopes that change things (such as sending receipts) off keys used by AI clients unless a person reviews each action.
- Data an AI client receives through the API leaves Coherence and is handled under the Customer's own arrangements with that AI provider. It is not processed by Coherence, and the AI provider is not Coherence's subprocessor.
- Output an AI client produces from the API remains subject to the Licence Terms, including the restrictions on Coherence Materials (Clause 7) and the rules for AI Output (Clause 6).
5. Acceptable use of the API
The Customer must not use the API to:
- resell, sublicense, share or provide API access to anyone outside the Customer, except its own service providers acting for it under confidentiality;
- copy, extract or systematically download the Coherence Materials (such as the ContentIQ database or the Seller Advisor knowledge base) beyond ordinary use of Output;
- build or train a competing product or AI model;
- probe, load-test or disrupt the API, or access another workspace;
- break any law or the terms of a platform the Customer connects.
6. Google user data
Some Receipts Manager data comes from Google mailboxes the Customer connected, such as receipt documents and email details. The API shares this data only under a scope an owner or admin enables for a key, after being told that the data will leave Coherence. The Customer must use any such data only to provide features to its own users, must not use it for advertising, must not sell it, and must not use it to develop, improve or train generalised AI or machine-learning models, in line with the Google API Services User Data Policy, including the Limited Use requirements.
7. Personal data
When the Customer retrieves personal data through the API, it does so as controller, on its own instruction, under the Data Processing Addendum (Section 2.5). The Customer is responsible for having a lawful basis for sending that data to its own systems and AI clients, including any transfer outside the European Economic Area.
8. Changes to the API
Coherence may add to the API at any time. It gives at least 30 days' notice, in the developer documentation and by email to workspace owners and admins, before removing or changing a /v1 endpoint or MCP tool in a way that breaks existing use, unless a change is needed urgently for security or by law.
9. Suspension
Coherence may suspend or revoke a key, or limit API access, when it is used in breach of these terms or puts the Platform, other customers or third parties at risk. Coherence tells the Customer why and restores access when the problem is fixed.
10. Contact
Questions about the API: office@coherenceltd.com.