Effective: July 2026
By applying for, receiving, or using a SuperPay Agent Partner API key, you ("Partner") agree to these terms on behalf of yourself or your organization. If you do not agree, do not apply for or use the API.
SuperPay grants you a limited, non-exclusive, non-transferable license to call the Agent Commerce API endpoint (POST /v1/agent/recommend) solely for the purpose of powering AI agent, chatbot, or automated shopping-assistant features that recommend credit cards to end users. You may not resell, sublicense, or redistribute API responses as a standalone data product.
Your sp_agent_… key is a credential. Do not expose it in client-side code, public repositories, logs, or LLM prompts. You are responsible for all API requests made with your key. Notify hello@superpayrewards.com immediately upon suspected compromise. SuperPay may suspend a key without notice if abuse is detected. Keys may be rotated via the POST /api/agent-partner/rotate-key endpoint using your current key for authentication.
You may use API responses to: (a) recommend which payment card a user should use for a specific purchase; (b) explain the reward rate and reason to a user in natural language; (c) power automated checkout-optimization flows in AI agents, browser extensions, or mobile applications; (d) display estimated reward values to end users. All returned data is informational — SuperPay does not process payments or guarantee reward values, which are set by the issuing institution.
You may not: (a) store or re-sell card catalog data as a standalone dataset; (b) use the API output to train or fine-tune language models without written consent from SuperPay; (c) include cardholder PII (names, account numbers, SSNs, card numbers, CVVs) in API request bodies; (d) exceed rate limits or circumvent authentication; (e) use the API to systematically enumerate, scrape, or cache the SuperPay card catalog for distribution; (f) use the API in any way that violates applicable law including GLBA, CCPA, GDPR, or the EU AI Act.
The Agent API is designed to receive card metadata only — not cardholder PII. Do not pass user names, email addresses, account numbers, or transaction IDs in API requests. API requests are logged for security, analytics, and debugging purposes. Logged fields include: timestamp, key ID (prefix only), endpoint, amount, category, MCC, and card IDs — never cardholder-identifying information. SuperPay's Privacy Policy (/privacy) governs all data handling.
Sandbox keys (sp_agent_… issued at signup confirmation) are intended for development and testing only. Do not use sandbox keys in production environments or expose them to end users. Production keys are issued following SuperPay's review and approval of your use case and registered origins. Using a sandbox key at production scale is a violation of these terms.
The API is rate-limited to 300 requests per minute per key. Rate-limit headers (X-RateLimit-Limit, X-RateLimit-Remaining, Retry-After) are included in every response. If your use case requires higher throughput, contact hello@superpayrewards.com.
Production keys may be configured with an origin allowlist. Browser requests bearing an Origin header from an unregistered domain will be rejected with 403 ORIGIN_NOT_ALLOWED. Server-to-server requests (no Origin header) are authenticated by key alone. Update registered origins by emailing hello@superpayrewards.com or via the key management endpoint.
Reward rates and card data returned by the API are estimates based on publicly available card program information and SuperPay's catalog. Actual rewards earned may differ due to promotional rates, issuer program changes, or category restrictions not captured in the catalog. SuperPay does not guarantee that any recommendation will result in the maximum possible reward for any specific transaction.
If you use the API to power an autonomous AI agent that takes actions on behalf of end users, you must: (a) disclose to end users that card recommendations are powered by a third-party data service (SuperPay); (b) not represent SuperPay recommendations as guaranteed financial advice; (c) ensure end users can opt out of card recommendation features; (d) comply with all applicable AI disclosure requirements in your jurisdiction.
SuperPay may update these terms or discontinue the API with 30 days' notice except where immediate action is required for security or legal reasons. Continued use after notice constitutes acceptance. SuperPay may suspend a key immediately for Terms violations without prior notice.
The API is provided "as is" without warranty of any kind. SuperPay disclaims all implied warranties including merchantability, fitness for a particular purpose, and non-infringement. Reward rates are estimates and may not reflect current promotional offers.
To the maximum extent permitted by applicable law, SuperPay shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of the API, including but not limited to any losses arising from incorrect reward recommendations made by an AI agent.
Questions about these terms? Email hello@superpayrewards.com. For partnership inquiries, visit /for-agents.
© 2026 SuperPay Ai, Inc. All rights reserved.