Skip to contentSkip to navigation
Hatcel
Developers
2026-10-08API status

API terms

The terms for using the Hatcel API

These terms apply whenever your venue, or anyone acting for it, uses the Hatcel API. They add to Hatcel's main Terms of service, and where the two disagree about the API, these terms win.

Status

Last updated 8 October 2026.

Agreeing to these terms

If you act for a venue, you confirm you are authorised to bind it. Every person, contractor, integration and AI agent that uses one of your venue's keys is bound by these documents through your venue.

These documents can change, as the API terms set out. Continuing to use the API after a change takes effect means you accept the change.

Who these terms are between

These terms are between Hatcel Pty Ltd ("Hatcel", "we") and the business that holds the Hatcel subscription for the workspace a key belongs to ("your venue" or "you").

Anyone who makes or uses a key for your venue - a staff member, a contractor, an agency, an integration or an AI agent - does so on your venue's behalf, and your venue answers for what they do with it.

Definitions

TermMeans
APIHatcel's application programming interface at api.hatcel.com, and every endpoint, header and response it serves
DocsThis documentation at developers.hatcel.com, including llms.txt, llms-full.txt and openapi.json
KeyA credential made in Settings > Developers that authenticates requests to the API, of any kind or mode
AI agentSoftware that decides what requests to make with some autonomy, such as a large language model with tools
IntegrationAny other software that uses a key: a sync, a report, a booking tool, a script
API dataAny data the API returns, or that your venue sends through it
WorkspaceYour venue's account on Hatcel, which a key belongs to and is limited to
Main TermsHatcel's Terms of service and Privacy policy

How these documents fit together

The API terms, the Acceptable use policy and the Data and privacy terms form part of the main Terms, and together they are the whole agreement between your venue and Hatcel about the API. If they disagree, this order decides:

  1. A separate order form Hatcel has signed with your venue, on anything it covers.
  2. These API terms, then Acceptable use, then Data and privacy, on anything about the API.
  3. The main Terms of service and Privacy policy, on everything else.

The guides and reference in these docs explain how the API works. They are not promises unless these terms make them one.

Your licence

While your subscription is active, Hatcel grants your venue a limited, non-exclusive, non-transferable, non-sublicensable and revocable licence to use the API and the docs to read and change your own workspace's data, for your own business.

A contractor or service provider may build or run an integration for your venue, using your venue's keys, for your venue alone. Your venue makes sure they keep to these terms.

Hatcel keeps every right in the API, the docs, the platform and its name and marks; nothing in these terms transfers any of them. Your venue keeps every right in its own data, as the main Terms say. If you send us suggestions about the API, we may use them freely.

What the licence does not allow

  • Reselling, renting, sublicensing or sharing access to the API, or giving a key to anyone not acting for your venue.
  • Reaching, or trying to reach, any workspace but your own.
  • Getting around a rate limit, a key's access, test mode, authentication or any other safeguard.
  • Copying, scraping or rebuilding Hatcel, or using the API, the docs or API data to build a product that competes with it.
  • Reverse engineering the API or the platform, except to the extent the law allows despite this clause.
  • Presenting an integration as made, endorsed or supported by Hatcel, or using Hatcel's name or marks beyond saying, truthfully, that it works with Hatcel.
  • Anything the Acceptable use policy forbids.

Keys and credentials

  • Keys are confidential. Keep every key secret and on a server. Never put one in a browser, an app, a URL, a public repository or a conversation with an AI agent.
  • Give each integration and agent its own key, with the least access it needs, and revoke keys that are no longer used.
  • Your venue is responsible for every request made with its keys, whoever made it, until the key is revoked.
  • If a key may have been exposed, revoke it in Settings > Developers straight away and tell Hatcel within 24 hours at nigel@hatcel.com.

Hatcel may revoke a key without notice when it learns the key has been published or exposed, or when it is being used against these terms, and will tell your venue when it does. Hatcel also revokes a key that has not been used for 90 days, after warning your venue.

Security

Hatcel protects the API and the data it holds with reasonable technical and organisational measures, described on Security. Hatcel may change those measures, but will not materially reduce the overall protection they give.

Your venue protects its keys, the systems that hold them, and API data once it has left Hatcel, with measures at least as protective as good industry practice. It keeps its integrations and agents up to date and fixes a security weakness in them promptly once it knows of one.

If your venue learns of a security incident affecting a key or API data, it tells Hatcel within 24 hours at nigel@hatcel.com, works with Hatcel to contain it, and gives Hatcel the information it reasonably asks for.

Your integrations and AI agents

Your venue chooses which integrations and AI agents use the API, what access their keys have, and what they do with what they read. Hatcel does not review, approve or support third-party integrations or agents, and is not responsible for them.

Your venue is responsible for everything its integrations and AI agents do with its keys as if a member of its own staff had done it - a mistaken change, a wrong answer, a message sent, a record removed, data sent somewhere else. That is so whether or not anyone at your venue told the agent to do it, reviewed it, or knew about it.

An AI agent is software, not a person: it cannot agree to anything, hold a permission of its own or take responsibility. Somebody at your venue owns each agent and can stop it. The rules for agents are in Acceptable use.

Data ownership and data you take out

API data is your venue's data. Inside Hatcel, Hatcel handles it on your venue's behalf, as the main Privacy policy says.

Once API data leaves Hatcel, your venue alone controls it and is responsible for it, as the entity that holds it under the Privacy Act 1988 and every other law that applies - including how it is kept, who it is shared with, and where. Hatcel does not control, and is not responsible for, a copy that has left Hatcel. See Data and privacy.

Hatcel uses information about how the API is used - the request log, the change journal, and counts of requests and errors - to run, secure, support and improve the API, as Data and privacy describes.

Confidentiality

Each party keeps the other's confidential information secret and uses it only for the purposes of these terms. Your venue's keys, its API data and its customers' personal information are confidential. So is anything Hatcel shares about the API that is not public, such as a preview, a security report or a fix in progress.

Information is not confidential if it is or becomes public through no fault of the party receiving it, was already lawfully known to it, or is independently developed. A party may disclose confidential information where the law requires it, after telling the other first where the law allows.

Rate limits and fair use

The API is rate limited, as Rate limits sets out. Do not try to get around a limit, for example by spreading requests across keys or workspaces. Use the API in a way that does not degrade it for other venues.

Hatcel may change the limits. It will give 30 days' notice before lowering one, unless it must act sooner to protect the platform or other venues. Hatcel may throttle or refuse requests that threaten the platform, whatever the published limits.

Changes, versions and deprecation

  • Hatcel may add endpoints, fields, values and headers at any time. Build your integration to ignore what it does not recognise.
  • A breaking change - removing or renaming a field or endpoint, or changing what one means - ships as a new version, as Versioning explains.
  • A version your integration pins keeps working for at least 12 months after the next one is released. Hatcel emails your workspace's owner at least 6 months before retiring it.
  • Hatcel may change or remove something sooner where security, the law or a supplier requires it, and will give as much notice as it can.
  • Anything marked Coming soon, preview or beta can change or end without notice, and is provided without any commitment.
  • Hatcel may stop offering the API altogether on at least 6 months' notice.

Changes to these terms

Hatcel may change these terms, the Acceptable use policy and the Data and privacy terms. The date at the top of each page says when it last changed.

A change that materially affects your venue is emailed to its owner at least 30 days before it takes effect, unless the law or a security risk requires it sooner. If your venue does not accept a change, it can stop using the API and revoke its keys, or cancel its subscription, before the change takes effect. Continuing to use the API after a change takes effect means your venue accepts it.

Suspension and ending

Hatcel may suspend a key, or your venue's API access, straight away where it reasonably believes that is needed to protect customers' data, the platform or other venues, or to comply with the law. Otherwise it will first tell your venue what is wrong and give it a reasonable chance to fix it. Hatcel lifts a suspension once the reason for it has gone.

Hatcel may end your venue's API access, on notice, if your venue seriously or repeatedly breaks these terms or the Acceptable use policy. Your venue may stop using the API at any time by revoking its keys.

API access ends when your venue's subscription ends, and every key stops working. Data your venue took out before then stays its responsibility. The clauses on confidentiality, data you take out, liability, indemnity and governing law continue after access ends.

Warranties

Nothing in these terms excludes, restricts or modifies any right your venue has under the Australian Consumer Law.

Beyond those rights, the API and the docs are provided as they are and as available. Hatcel does not promise they will be uninterrupted, free of errors, or fit for a particular purpose, or that an integration or agent built on them will work as your venue intends.

Liability

The main Terms' limit of liability covers the API: beyond the rights the Australian Consumer Law gives, Hatcel's liability to your venue is limited to the fees your venue paid Hatcel in the twelve months before the claim. There is no separate or additional limit for the API.

Neither party is liable to the other for indirect or consequential loss. Hatcel is not liable for loss caused by an integration or AI agent your venue chose, by a key your venue failed to keep secret, or by what happens to API data after it leaves Hatcel, except to the extent Hatcel caused it.

Indemnity

Your venue indemnifies Hatcel against claims by others - including its own customers and regulators - and the reasonable costs of meeting them, to the extent they arise from:

  • your venue's breach of these terms, the Acceptable use policy or the Data and privacy terms;
  • what your venue's integrations or AI agents do with its keys;
  • API data after it has left Hatcel, including marketing your venue sent with it.

This indemnity is reduced to the extent Hatcel caused or contributed to the claim. Hatcel tells your venue promptly of a claim it relies on this clause for, and lets your venue take part in its defence.

General

  • Governing law. These terms are governed by the laws of New South Wales, Australia, the same as the main Terms, and each party submits to the non-exclusive jurisdiction of its courts.
  • Notices. Hatcel gives notice by email to your workspace's owner, in the product, or on these docs. Your venue gives notice to nigel@hatcel.com.
  • Assignment. Your venue may not transfer its rights under these terms without Hatcel's written agreement. Hatcel may transfer them to whoever takes over the platform.
  • Severance. If part of these terms is unenforceable, it is read down or left out, and the rest stands.
  • Waiver. A right not enforced straight away is not given up.
  • Entire agreement. About the API, these documents and the main Terms are the whole agreement, and replace anything said or written before. The order in How these documents fit together applies.

Questions about these terms go to nigel@hatcel.com.