This policy sets out what you may and may not do with the API. It exists to keep the service available and accurate for everyone, and to make clear where responsibility sits when the output is used to make automated decisions.
Stay within the tier limits set out in the documentation. Do not hammer endpoints when rate-limited.
The service sends standard rate-limit headers (including Retry-After on 429 responses); honour them.
Sustained flooding will trigger IP-level or subnet-level blocking.
If you use API output to drive automated transactions, you are solely responsible for the transactions your systems submit. The API is a factual observation layer, not an investment advisor, auditor or execution guarantee. You must build your own fallbacks, slippage controls and circuit breakers.
Good-faith research is welcome. Report findings to contact@m2msentinel.com and give us reasonable time to fix an issue before disclosing it. Do not access other users' data, degrade the service for others, or run high-volume automated attacks. We will not pursue legal action against research that follows this section.
We may throttle, suspend or permanently revoke a key for a breach of this policy. Serious breaches — payment enforcement bypass, attacks on infrastructure, or use of the service to facilitate fraud — result in immediate termination without refund, and may be reported to the relevant authorities.
Where a breach is likely inadvertent, we will normally contact you first. If you believe an enforcement action was mistaken, appeal to contact@m2msentinel.com.
Report misuse of the service to contact@m2msentinel.com with the relevant timestamps and, where possible, the transaction hashes or key digest prefix concerned.