dxAuth Terms of Service
Service terms for registered applications, passwordless verification, email delivery, admin access, and auth-code exchange.
Platform services
- 1.1
dxAuth provides application registration, passwordless email verification, magic-link and 6 digit code sign-in, auth-code exchange, email delivery support, anti-abuse controls, and admin tools.
- 1.2
dxAuth verifies email challenges and issues one-time auth codes. It does not directly create another application's final logged-in session.
Application-owner obligations
- 2.1
Application owners are responsible for registering accurate redirect URIs and browser origins, protecting client secrets in backend secret storage, exchanging auth codes only from trusted backend services, creating and securing their own application sessions, and honoring user privacy, consent, and access requirements in their own products.
Administrative access
- 3.1
Admins must keep access credentials secure and use admin tools only for authorized application registration, support, security, and operational purposes.
- 3.2
We may suspend or restrict access to protect the service, enforce terms, prevent abuse, respond to legal obligations, or investigate security issues.
Prohibited use
- 4.1
Users, admins, and application owners must not abuse email delivery, attempt account enumeration, brute force codes, perform phishing or spam, bypass redirect/origin/rate-limit controls, register deceptive apps, expose client secrets, or interfere with service operation.
Email delivery and suppression
- 5.1
dxAuth may send magic-link or 6 digit code emails for registered applications. Suppressed, bounced, complained, or abusive recipients may be blocked or rate-limited.
Service changes and termination
- 6.1
We may change, limit, suspend, or discontinue features. We may perform maintenance and remove or suppress records when retention rules, security needs, abuse reports, or legal obligations require it.
- 6.2
Admins or application owners may stop using dxAuth. We may suspend or terminate access for violations, abuse, security risk, non-payment, or legal reasons.
Disclaimers and liability
- 7.1
dxAuth is provided as available. It is not a substitute for legal, compliance, identity-governance, or security advice.
- 7.2
To the maximum extent permitted by applicable law, doxanh is not liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost data, lost goodwill, service interruption, or substitute services. To the maximum extent permitted by applicable law, doxanh's total liability for claims relating to dxAuth is limited to the amount paid for the service during the 12 months before the claim, or USD 100 if no paid amount applies. These limits do not apply where prohibited by law.
Governing law
- 8.1
These terms are governed by applicable law for the service operator and user relationship, excluding conflict-of-law rules. Mandatory local consumer, privacy, or business rights apply where they cannot legally be excluded.
Contact
- 9.1
General contact: contact@doxanh.dev.
- 9.2
Legal contact: legal@doxanh.dev.