Go to top

Koronet API Terms of Service

Floral Software Holdings d/b/a Koronet

Version 1.0 · Effective Date: September 1, 2026

1. Acceptance; Who These Terms Bind

1.1. These API Terms of Service ("API Terms") govern access to and use of the application programming interfaces, developer tools, sandbox environments, credentials, documentation, and related services (collectively, the "APIs") made available by Floral Software Holdings, Inc. d/b/a Koronet, on behalf of itself and its affiliates ("Koronet," "we," "us").

1.2. By accepting these API Terms — by click-through, by executing an Order that incorporates them, by registering for API access, by completing a re-authorization that requires acceptance, or by accessing or using the APIs — you ("API User") agree to be bound by them. If you accept on behalf of an entity, you represent that you have authority to bind that entity, and "API User" means that entity.

1.3. These API Terms apply to every class of API User, including: (a) Customers — parties with a Koronet account or Order who access the APIs for their own use; (b) Partners — third parties authorized to access the APIs through a Customer Authorization or a partner agreement, whether or not they are otherwise Koronet customers; and (c) any other party Koronet expressly authorizes in writing. The Customer that issues a Customer Authorization and the Partner that receives it each accept, and are each independently bound by, these API Terms; a Customer's acceptance also covers its own internal integrations, applications, and agents operating under its Credentials. If you have an Order with Koronet, these API Terms form part of your Agreement with Koronet and are read together with the Terms of Service at koronet.com/terms-of-service (the "Terms of Service"), the Pricing Schedule, and any Credits Schedule. These API Terms govern access under Koronet's API / developer program; where access is provided solely under a marketplace or other program agreement that Koronet designates as governing that access (for example, marketplace vendors accessing exclusively through marketplace-issued grants), that agreement governs and these API Terms apply only to the extent it so provides.

1.4. Order of Precedence. In the event of conflict among the documents governing API access, the following order of precedence applies: (1) an executed Order, to the extent it expressly addresses the conflicting subject matter; (2) the Pricing Schedule and any Credits Schedule, with respect to pricing, billing, credits, allotments, overages, and fee calculations; (3) these API Terms, with respect to API access, Credentials, grants, scopes, API Data, and API use; and (4) the Terms of Service. Notwithstanding clause (1), fee rates may change in accordance with the Pricing Schedule except to the extent an Order expressly fixes a rate for a stated period.

2. Definitions

2.1. "API Credentials" (or "Credentials") means API keys, access tokens, refresh tokens, client identifiers, client secrets, OAuth client credentials, authorization grants, scopes, and any other credentials or authorizations issued or made available by Koronet for API access, in each form Koronet makes available from time to time.

2.2. "API Data" means data, content, records, fields, metadata, responses, and documentation made available through or derived from the APIs, excluding Customer Data submitted by the API User.

2.3. "Customer Authorization" means the authorization a Customer issues to a Partner through a registration, invitation, grant, consent flow, or similar mechanism made available by Koronet, permitting that Partner to access designated APIs or API Data in connection with that Customer's account.

2.4. "Customer Data" means data submitted to the Services or the APIs by or on behalf of a Customer.

2.5. "Documentation" means the API documentation, method and endpoint references, scope descriptions, and rate-limit specifications published or provided by Koronet, as updated from time to time.

2.6. "Order" means an ordering document between Koronet (or an affiliate) and an API User that references the Agreement, including an API subscription order.

2.7. "Pricing Schedule" means the schedule published at koronet.com/koronet-pricing, as amended from time to time; "Credits Schedule" means any schedule of API credit rates, allotments, weights, and overage charges published by Koronet, whether within the Pricing Schedule or separately.

2.8. "Scopes" means the named permission bundles (for example, inventory.read or orders.write) that define the operations and data domains an API Credential or Customer Authorization may access. "Transactional Methods" means API methods that create, send, or receive transactions via Koronet's network and communication services, as designated in the Documentation or applicable schedules; "Operational Methods" means all other API methods.

3. Registration; Verification

3.1. API access requires registration through the mechanism Koronet makes available (including any partner registration or invitation flow). You must provide accurate, current, and complete information — including legal entity name, jurisdiction of organization, business contact, technical contact, and security contact — and keep it updated.

3.2. Koronet may condition access on identity and business verification, security review, execution of an Order or partner agreement, provision of a valid payment method, or acceptance of additional terms. Koronet may approve, deny, condition, or tier any registration at its discretion.

3.3. Each Partner receives its own Partner-level credential establishing its identity. Customer-facing keys issued under a Customer Authorization are separate credentials scoped to that Customer's account. You may not use another party's registration or identity, and you may not misrepresent the application, system, or party on whose behalf a call is made.

4. License; Access Classes

4.1. Subject to the Agreement and your compliance with these API Terms, Koronet grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access and use the APIs, solely: (a) for a Customer — for the Customer's own business use, including internal integrations, automations, applications, and agents operating under the Customer's Credentials, as authorized by these API Terms, the Documentation, and, where applicable, an Order or Koronet's written approval, whether or not the Customer otherwise uses the Services; and (b) for a Partner — within the scope of a valid Customer Authorization or partner agreement, and only for so long as it remains in effect. No implied licenses are granted.

4.2. Orders. Koronet designates when an Order is required for access to the APIs, and may require an Order for any access — including for Transactional Methods, negotiated rates or terms, partner arrangements Koronet designates as contract-level, and, at Koronet's election, all new API access. Where Koronet permits access without an Order, your acceptance of these API Terms, together with the Documentation and the published Pricing Schedule and Credits Schedule, governs your access, and the applicable transaction fees and credit consumption charges under Section 9 apply.

4.3. Your access is limited to the specific methods, endpoints, Scopes, environments, and rate limits designated by Koronet in the Documentation, applicable schedules, and/or your issued Credentials and grants, as Koronet may update from time to time. Access to any method, endpoint, or Scope not so designated requires Koronet's prior written authorization.

4.4. Sandbox. Koronet may provide sandbox or test environments. Sandbox data is not production data, carries no availability commitment, and may be reset at any time.

5. Credentials; Security

5.1. Credentials identify you and bind your activity. You are responsible for all activity conducted through your Credentials and grants, whether or not authorized by you, and you must notify Koronet immediately at security@koronet.com upon suspected loss, theft, or compromise.

5.2. Credentials may not be shared, sublicensed, resold, published, embedded in client-side code, transmitted in URLs, or made available to any third party, except through Customer Authorizations, grants, or consent flows made available by Koronet or as expressly permitted by an Order or Koronet's written approval. Koronet's authorization of any third party, or tolerance of any past practice, does not waive this section. This prohibition includes sharing, or permitting the use of, account login credentials (including any user email and password), user seats, or any other means by which a third party could create, obtain, or use Credentials. Credentials created for your internal use (including any Credential designated with an internal audience) may not be made available to, or used for the benefit of, any external party; external access to your data is available solely through the Customer Authorization and grant mechanisms Koronet provides.

5.3. Retroactive Fees; Concealed or Misclassified Use. If you make Credentials available to a third party in violation of Section 5.2, or conduct, route, structure, or label API activity so as to avoid, understate, or conceal fees that would otherwise apply (including conducting transactional activity through Operational Methods or other channels, misidentifying the calling application or party, or obscuring usage from Koronet's metering), you agree to pay retroactive fees equal to the fees (including subscription, transaction, and credit consumption fees) that would have been payable under the Agreement had the activity been properly conducted and classified, at the rates in effect during the relevant period, calculated from Koronet's API logs (which are controlling absent manifest error). Where your conduct has obscured or degraded the records needed for that calculation, Koronet may calculate the retroactive fees from its reasonable, good-faith estimate based on available records and comparable usage. Retroactive fees bear interest at 1.5% per month (or the maximum allowed by law, if lower) from the date they would originally have been payable, and you will reimburse Koronet's reasonable costs of investigation where a material underpayment is confirmed. These amounts are payment of fees owed, not a penalty, and are in addition to Koronet's other rights and remedies, including suspension and termination for material breach.

5.4. You will implement and maintain industry-standard administrative, technical, and physical safeguards for Credentials and API Data, including secret storage, least-privilege access, personnel controls, and prompt rotation on personnel change or suspected compromise. Koronet may require rotation, re-issuance, or upgraded credential forms at any time.

5.5. You may not probe, scan, or test the vulnerability of the APIs or Koronet systems without Koronet's prior written consent.

5.6. Liquidated Damages for Credential Sharing and Fee Evasion. If Koronet determines that (a) a Credential enabled for Transactional Methods — or account access permitting its creation or use — has been shared with or used by a third party in violation of Section 5.2, or (b) you have conducted transactional activity without the transactional enablement required under the Agreement, or have conducted, routed, structured, labeled, or concealed API activity so as to avoid, understate, or evade transaction fees that would otherwise apply (as described in Section 5.3), then, the parties agreeing that Koronet's actual damages would be difficult to ascertain (including the transaction fees and partner subscription fees that would have been payable had the activity been properly established and classified under the Agreement, the costs of investigating, discovering, and reconstructing misuse structured to be difficult to detect, and the harm to the integrity of Koronet's network and metering), you will pay, as liquidated damages and not as a penalty, an amount equal to five percent (5%) of the Transaction Value of each affected transaction — each transaction created, sent, or received through the shared Credential by or for the benefit of the third party, or conducted, routed, or concealed in violation of clause (b) — calculated from Koronet's API logs (or, where records were obscured, Koronet's reasonable, good-faith estimate under Section 5.3), plus Koronet's reasonable out-of-pocket costs of collection and enforcement. The parties agree this amount is a reasonable pre-estimate of Koronet's damages and not a penalty. Amounts paid under this Section for a given transaction are credited against retroactive fees payable for the same transaction under Section 5.3, and vice versa. This Section does not limit Koronet's rights of suspension, revocation, or termination, or its right to injunctive relief.

6. Customer Authorizations; Grants; Revocation

6.1. A Customer controls its Customer Authorizations: the Customer may issue, scope, restrict, and revoke them through the mechanisms Koronet provides. A Partner's access under a Customer Authorization ends when that authorization is revoked, expires, or is suspended, or when the underlying Customer relationship with Koronet ends. Revocations, suspensions, and scope reductions take effect no later than the expiry of any then-outstanding access token (access tokens are short-lived); scope changes otherwise apply at the next credential or token issuance. Koronet does not guarantee interruption of in-flight requests.

6.2. Unless an Order expressly provides otherwise: fees and credit consumption attributable to activity under a Customer Authorization are the responsibility of the Customer that issued it; a Partner's transactional activity under a partner agreement or Order is the responsibility of the Partner.

6.3. Upon revocation or expiration of a Customer Authorization, the Partner will promptly cease access under it and, within thirty (30) days, delete API Data obtained under it, except: (a) records of completed transactions the Partner processed for its own account, retained for bona fide legal, accounting, or audit purposes; and (b) as otherwise required by law.

7. API Use Restrictions

7.1. You shall not, directly or indirectly: (a) modify, reverse engineer, decompile, or create derivative works based on the APIs; (b) distribute, sell, sublicense, lease, or otherwise transfer the APIs or API access to any third party except as permitted under Section 5.2; (c) exceed designated rate limits or circumvent any technical limitation, throttle, metering, quota, or security control; (d) cache, store, or retain API Data beyond the freshness and retention limits in the Documentation or applicable schedule; (e) use the APIs to develop a substitute or substantially similar API or data service, or perform or publish any benchmarking or competitive analysis of the APIs or the Services without Koronet's prior written consent; (f) use the APIs in a manner that Koronet reasonably determines poses a security, stability, legal, or abuse risk; or (g) use the APIs for any unlawful purpose or in breach of the Agreement.

7.2. Competing Portal Restriction. Except to the extent expressly permitted by an Order, a partner agreement, or a written approval, grant, consent, or Scope issued by Koronet, you shall not access or use the APIs to set up, operate, or otherwise engage in the provision of an ecommerce or payments portal, software, or service serving third-party buyers or sellers that competes with or is substantially similar to those provided by Koronet. Any violation of this Section 7.2 is a material breach.

7.3. Automated and Agentic Access. Automated agents, AI systems, MCP servers, and autonomous applications are welcome as registered API Users, and are not a separate access class: they must register, hold their own Credentials, and comply with these API Terms like any other application. In addition, any such agent or system must: (a) accurately identify itself as an automated system in its registration and its API traffic, and must not impersonate a human user, borrow a human user's session, or misrepresent its identity, operator, or the party on whose behalf it acts; (b) operate only under Credentials scoped to that agent and its authorized use case; (c) disclose autonomous behavior at registration, including whether it initiates transactions without human review; and (d) obtain human-authorized confirmation before executing Transactional Methods, unless Koronet has expressly authorized autonomous transactional operation for that agent in an Order, partner agreement, or written approval. Unregistered or misidentified automated access is unauthorized access.

7.4. No Substitution or Circumvention. You shall not use the APIs, any combination of Operational Methods, or any automation to substitute for, or enable any party to avoid, a required license, subscription, user seat, Order, or the transaction fees or credit consumption applicable under the Agreement — including by structuring, routing, splitting, or re-characterizing transactions or API usage so that activity that would otherwise be subject to Transactional Method fees is conducted through Operational Methods or other channels, or by enabling parties without a required account or authorization to submit transactions for processing by the Services.

8. API Data Restrictions

8.1. Except as expressly permitted by an Order, these API Terms, or Koronet's prior written consent, you shall not: (a) sell, license, republish, syndicate, or otherwise redistribute API Data, other than displaying it to your own authorized end users in connection with the use case authorized under Section 4; (b) create, derive, publish, or distribute any aggregated, benchmarked, statistical, index, or market-intelligence product from API Data, including any measure of transaction volume, pricing, availability, or market share of Koronet, its affiliates, or any Koronet customer; (c) use API Data to train, fine-tune, improve, or otherwise develop any machine learning or artificial intelligence model — including any foundation, frontier, or large language model — or to generate labeled data, calibrate model behavior, or improve model performance, or use or transfer any model parameters, weights, representations, or other outputs derived from any such training; (d) re-identify any de-identified, aggregated, or pseudonymized data; or (e) combine API Data with other data in a manner that circumvents the restrictions of this Section. For clarity, using API Data at inference time — including retrieving, grounding, or providing API Data as context to an AI system — is permitted solely within, and for the duration of, the use case authorized under Section 4, provided no API Data is retained in or extractable from any model and clause (c) is not violated.

8.2. You shall preserve source attribution and shall not display availability, inventory, or pricing data older than the freshness limit stated in the Documentation without indicating the time of retrieval.

8.3. Records; Verification. You will keep reasonable records of your access to and use of API Data sufficient to demonstrate compliance with this Section 8 and Section 6.3. No more than once per year (or at any time following a reasonably suspected violation), Koronet may request, and you will provide within thirty (30) days, written confirmation of compliance and reasonable supporting information — including, where relevant, a description of where API Data is stored, retention practices, and deletion confirmations. This is a records-and-attestation right, not an on-premises audit; Koronet's own API logs remain controlling for usage and fee questions (Section 5.3, Section 9.2). If an attestation or Koronet's records demonstrate a discrepancy exceeding five percent (5%) in reported or fee-bearing amounts, or Koronet has a reasonable, documented basis to suspect a material violation of this Section 8, Koronet may engage an independent third party, subject to confidentiality obligations, to review the relevant records; if the review confirms a material underpayment or violation, the reasonable costs of the review are payable by you, in addition to any amounts owed.

8.4. Customer Data submitted by you remains your property, subject to the Privacy Policy and the Agreement. As between you and Koronet, Koronet and its licensors retain all right, title, and interest in the APIs, the Documentation, the Services, and all Koronet IP, including analytical and usage data derived from operation of the APIs.

9. Fees

9.1. Transactional Methods are subject to the applicable API transaction fees set forth in the Pricing Schedule and/or your Order. Operational Methods are billed on a token/credit consumption basis at the rates, allotments, weights, and overage charges in the applicable Credits Schedule. No credit or token consumption charges accrue until Koronet has published a Credits Schedule applicable to you and provided at least thirty (30) days' notice of its effective date.

9.2. Unless otherwise stated in an applicable schedule or Order: consumption is measured, and credit allotments reset, by calendar month computed in Coordinated Universal Time (UTC); unused credits do not carry over and are not refundable; and usage, consumption, and fee calculations are determined from Koronet's systems of record.

9.3. A valid payment method on file may be required as a condition of Credential issuance or continued access. Late amounts accrue interest at 1.5% per month or the maximum allowed by law (whichever is lower); Koronet may suspend Credentials for amounts unpaid thirty (30) days after their due date.

10. Versioning; Migration; Deprecation

10.1. Koronet may modify, replace, or retire any authentication method, credential type, endpoint, method, Scope, or API version, including by migrating access to new authorization frameworks and permission models.

10.2. Upon notice from Koronet, you will, at your own cost: (a) complete required re-implementation, re-registration, and re-authorization; and (b) accept the then-current version of these API Terms, in each case within ninety (90) days of notice or such longer period as Koronet specifies. Shorter periods may apply where required for security or legal compliance. Koronet is not obligated to maintain superseded credential types, endpoints, or versions beyond the applicable deadline, and failure to migrate or accept is grounds for suspension. No migration under this Section is a breach by Koronet, entitles you to any refund or fee reduction, or extends any Order term. An API User that cannot reasonably complete a migration within the applicable period may request an extension in writing before the deadline, describing the constraint and a completion plan; Koronet will not unreasonably refuse a reasonable extension. Except where required for security or legal compliance, Koronet will apply enforcement in stages (notice, then throttling, then suspension) rather than immediate termination.

11. Suspension; Termination

11.1. Koronet may suspend or throttle Credentials and API access immediately, without prior notice, in the event of a suspected security incident, abuse, violation of Sections 5, 7, or 8, non-payment (subject to Section 9.3), legal requirement, or risk to the APIs, Koronet systems, or other customers.

11.2. Where your API access is provided under a paid, fixed-term Order, Koronet will not revoke it during the term other than: (a) for your breach; (b) under Section 11.1; (c) for non-payment; or (d) in connection with migration or retirement under Section 10. If Koronet revokes such access for convenience, its sole liability and your sole remedy is a pro-rata refund of prepaid, unused subscription fees. Where access is not under a paid fixed-term Order (including free, sandbox, or Customer-Authorization-based access), Koronet may modify, suspend, or terminate it at any time.

11.3. Upon termination or revocation of your API access (effective per Section 6.1's timing): cease all use of the APIs; delete Credentials, non-public Documentation, and API Data (subject to Section 6.3's retention carve-outs); and, on request, certify deletion. Sections 5.3, 7, 8, and 11–15 survive.

12. Warranties Disclaimer; Indemnity; Liability

12.1. THE APIS, DOCUMENTATION, AND API DATA ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTY OF ANY KIND. KORONET DOES NOT WARRANT ACCURACY, RELIABILITY, AVAILABILITY, OR FITNESS FOR A PARTICULAR PURPOSE, AND DISCLAIMS ALL IMPLIED WARRANTIES TO THE MAXIMUM EXTENT PERMITTED BY LAW. NO SERVICE LEVELS OR UPTIME COMMITMENTS APPLY UNLESS EXPRESSLY STATED IN AN ORDER.

12.2. You will defend, indemnify, and hold harmless Koronet and its affiliates, officers, directors, employees, and providers from and against all claims, damages, and expenses (including attorneys' fees) arising out of or relating to: your use of the APIs or API Data; your applications, marketplaces, or services; your breach of these API Terms; your violation of law or third-party rights; and any third party's access under your Credentials or Customer Authorizations.

12.3. TO THE MAXIMUM EXTENT PERMITTED BY LAW, KORONET'S AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE APIS WILL NOT EXCEED THE GREATER OF (A) THE FEES PAID BY YOU FOR API ACCESS IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM AND (B) ONE THOUSAND U.S. DOLLARS ($1,000). KORONET WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOST PROFITS, REVENUE, OR DATA.

13. Confidentiality; Publicity

13.1. Non-public aspects of the APIs, Documentation, sandbox, roadmaps, and any credentials are Koronet's Confidential Information under the Terms of Service.

13.2. No Implied Affiliation; Marks. You shall not use Koronet's (or its affiliates') names, logos, trademarks, or brand elements, and shall not state or imply that Koronet sponsors, endorses, certifies, is affiliated with, or is a partner of you or your application, in each case without Koronet's prior written consent or as expressly permitted by brand guidelines Koronet publishes for the applicable program. You may accurately state that your application integrates with Komet Sales / Koronet using plain text. You shall not describe your application as "official," "certified," "verified," or similar unless Koronet has granted that designation in writing. You shall not register or use any domain name, social media handle, application name, or advertising keyword that is confusingly similar to Koronet's marks. Any goodwill from permitted use of the marks inures to Koronet. You may not issue press releases regarding the relationship without prior written consent.

14. Privacy; Data Protection

14.1. Each party will comply with applicable data protection laws. Where you access Personal Information through a Customer Authorization, you do so as directed by the authorizing Customer and within the granted Scopes, and you will: use it solely to provide your authorized services to that Customer; not sell or share it (as those terms are defined under applicable U.S. state privacy laws); apply appropriate safeguards; cooperate with consumer rights requests; and notify the Customer and Koronet without undue delay of any personal-data breach affecting it.

14.2. Koronet's processing of Personal Information is described in the Privacy Policy and, where applicable, the Data Processing Addendum to the Terms of Service.

15. General

15.1. Changes to these API Terms. Koronet may update these API Terms from time to time. Each version carries a version identifier and effective date. Updates will be notified via the developer portal, email to your registered contacts, and/or in-product notice. Continued use of the APIs after the effective date, and any acceptance completed at registration or re-authorization, constitutes acceptance of the updated version. Material changes will be notified at least thirty (30) days before their effective date, except where required sooner for security or legal compliance.

15.2. Governing law; disputes. These API Terms are governed by the law of the State of Florida (excluding conflicts rules), and disputes are resolved by binding arbitration with a class-action waiver as set forth in Section 12 of the Terms of Service, which is incorporated by reference; provided that, for API Users to whom Section 13.6 of the Terms of Service applies a different governing law and forum (including API Users domiciled in the European Economic Area), that section applies to these API Terms as well.

15.3. Notices. Koronet may provide notices by email to your registered contacts, via the developer portal, and/or by posting to koronet.com. You are responsible for keeping contact information current. Notices to Koronet must be sent to Floral Software Holdings, Inc. d/b/a Koronet, Attn: Legal, 8400 NW 36th St #450, Doral, FL 33166, with a copy by email to support@koronet.com (or the notice address stated in your Order, if any). Notices of disputes follow Section 12 of the Terms of Service.

15.4. Relationship to other documents; Transition. These API Terms form part of the Agreement. From their Effective Date, these API Terms constitute the "API Terms of Service" referenced in the Terms of Service and any Order; for API Users who have not yet accepted these API Terms, the API Access Addendum to the Terms of Service continues to govern their API access until they accept these API Terms (including at registration, key or grant creation, or re-authorization). The Terms of Service apply to your use of the APIs to the extent not inconsistent with these API Terms (see Section 1.4). No agency, partnership, or joint venture is created. Failure to enforce is not waiver. If any provision is unenforceable, the remainder stands. Koronet may assign these API Terms to an affiliate or in connection with a merger, acquisition, or sale of assets; you may not assign without Koronet's consent.