API access
API access is limited to approved integrations and assigned environments, organisations, roles and scopes. Credentials, signing secrets and tokens are confidential and belong in a secret manager, never browser code, logs or public repositories.
Authentication and security
Clients must follow documented OAuth, PKCE, bearer-token, request-signing, replay-protection and idempotency requirements. Validate TLS, timestamps, destinations and response status before relying on results.
Report suspected exposure or abuse immediately to info@blockcontrol.de.
Acceptable use
- Use data only for the approved purpose and authorised data subjects.
- Respect rate limits, retry guidance and lifecycle transitions.
- Do not scrape, replay, enumerate, interfere with or bypass policy controls.
- Do not present unverified responses as final legal or settlement records.
Data protection and evidence
Integrators are responsible for lawful processing, least-privilege access, retention, incident response and deletion in their systems. Evidence and personal data must not be copied beyond applicable permissions, contracts and legal bases.
Versions, limits and availability
Clients must use supported versions and handle errors, timeouts and asynchronous states. We may apply rate limits, suspend compromised clients or retire versions with reasonable notice, except when urgent security action is required.
Technical reference
Use the RWAT OpenAPI specification and technical documentation. A commercial integration agreement may add service levels, support and data-processing terms.