Certifada
ProductHow it worksPricingBlogHelpFAQ
Sign inGet startedarrow_forward
Productarrow_outwardHow it worksarrow_outwardPricingarrow_outwardBlogarrow_outwardHelparrow_outwardFAQarrow_outward
Sign inGet started arrow_forward
api Enterprise Procurement v1.5

Developer API Terms of Use

Rules governing REST API access, authentication token security, rate limits, webhooks, and deprecation schedules.

event Last updated: 2026-09-13gavel Sharjah Media City, Sharjah, United Arab Emirates
Legal AgreementsshieldPrivacy PolicygavelTerms of ServicecookieCookie PolicydescriptionData Processing AgreementreportAcceptable Use Policy
Trust & SecuritylockSecurity OverviewverifiedTrust Centerverified_userCompliance & GovernancehubSubprocessors Listbug_reportResponsible DisclosureaccessibilityAccessibility Statement
Enterprise ProcurementspeedService Level Agreementreceipt_longRefund & Billing PolicyapiAPI Terms of Usecontact_supportContact & Support
toc On This Page:
1. API Access & Authentication Keys2. Rate Limits & Fair Usage3. Webhook Security & Signatures4. API Deprecation & Version Policy

# 1. API Access & Authentication Keys

Use the authentication method documented for each API and the access enabled for your plan. Protect API keys and tokens, restrict their permissions, and rotate them if exposed. Do not use another workspace’s credentials or bypass authorization.

# 2. Rate Limits & Fair Usage

Authenticated APIs may have plan-based rate and usage limits. Follow current documentation and HTTP 429 responses rather than assuming a universal requests-per-minute allowance. Public credential verification is separate from paid API quotas. Security protections may restrict abusive traffic.

# 3. Webhook Security & Signatures

Outbound webhooks use the Certifada-Signature header with timestamp and HMAC SHA-256 values. Verify the signature against the raw request body and configured secret, check timestamp freshness, and handle retries safely. Follow the developer documentation for the exact signed payload format.

# 4. API Deprecation & Version Policy

We aim to give reasonable notice of breaking API changes and provide migration guidance. Urgent security or legal changes may require faster action. A specific notice period in an existing binding agreement remains applicable; this overview does not create a new blanket version-support guarantee.

verified_user

Questions about these policies?

Contact us about privacy, security, billing, or an enterprise agreement.

mail Contact usdescription Data processing terms
Certifada

The certificate lifecycle platform. Design, issue, deliver and verify digital credentials your recipients can trust — at any scale.

gavel Privacy & data protectionverified_user Security information

Product

ProductHow it worksPricingVerify a CredentialRecipient WalletAboutComparisonsBlog

Help

Getting startedDocumentationContact us

Trust & Security

Security OverviewTrust CenterCompliance & StandardsSubprocessorsResponsible Disclosure

Legal & Privacy

Privacy PolicyTerms of ServiceCookie PolicyData Processing (DPA)Acceptable Use PolicyCookie preferences

Enterprise & SLA

Enterprise SLAAPI Terms of UseAccessibility StatementRefund & Billing PolicyContact & Legal Support
© 2026 Certifada — All rights reserved.•Sharjah Media City, Sharjah, United Arab Emirates
Powered by CuspForge Technologies L.L.C