Updated 16 September 2026 · Early-access policy version 2026-09-16
1. Use the service responsibly
Use the website, workspace and API only for lawful business applications and authorised development. Describe your products and business accurately and keep customer-facing claims consistent with actual capabilities.
2. Prohibited conduct
- Fraud, impersonation, misleading applications, stolen credentials, money laundering, or attempts to bypass applicable sanctions or legal restrictions.
- Unlawful products or services, exploitation, infringement of intellectual property, or content you have no right to submit.
- Malware, credential harvesting, abusive messages, or attempts to access another person’s account, keys, documents or payment records.
- Unauthorised vulnerability exploitation, disruptive scanning, denial-of-service activity, evading rate limits, or creating accounts to circumvent a suspension.
- Sending real card data or customer personal information to the sandbox, presenting a simulated result as a real payment, or using sandbox success for real fulfilment.
- Embedding secret API keys in public clients, sharing admin sessions, or removing the distinction between test and live environments.
3. Merchant eligibility
A product category displayed on the website does not guarantee eligibility. Approval depends on the business, products, operating regions, applicable law and any future processing agreement. Additional restricted-business rules may apply before activation.
4. Enforcement and reporting
Keys or accounts may be suspended or revoked where necessary to contain misuse. Application review and support records can be used to investigate reported issues. Contact the team through workspace support for an account review or to report a suspected security issue; do not include secrets or unnecessary personal information.
Only test systems and accounts you are authorised to test. Stop if you encounter another user’s information and report the issue without retaining or publishing it.
