API Terms of Service
Last updated: October 2026
1. Acceptance of Terms
By accessing or using the SukkuAPI REST endpoints, you agree to be bound by these Terms of Service. If you disagree with any part of the terms, you may not access the service. SukkuAPI is an independent entity and is not affiliated with Mojang AB or Microsoft Corporation.
2. Data Ownership and Caching
Data provided by SukkuAPI is heavily processed and served through our proprietary caching engine to ensure optimal latency. We provide this data "as-is" without any warranties of absolute real-time accuracy, though our merge engine guarantees mathematical chronological consistency based on our internal records.
3. Required Headers (User-Agent)
To maintain the stability of our ecosystem and prevent unidentifiable scraping, all API requests MUST include a valid User-Agent header that clearly identifies your service, application, or Discord Bot.
User-Agent: MyDiscordBot/1.0 (contact@mydomain.com)
The use of generic, spoofed, or default library headers is strictly prohibited. Requests containing any of the following types of headers will be automatically rejected by our API Gateway:
- Spoofed Browser Headers: e.g.,
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/... - Default Python Libraries: e.g.,
python-requests/2.x.x,urllib/3.x. - Default JS/Node Libraries: e.g.,
axios/1.x.x,node-fetch.
Requests failing to provide identifiable headers may be subject to stricter rate limits or immediate blocking.
4. Abuse and Rate Limiting
Your API Key is tied to a specific quota and Rate Limit depending on your subscription tier. The following actions are strictly prohibited and will result in the immediate, irreversible revocation of your API Key without a refund:
- The use of automated proxy rotation, VPN pools, or Tor networks to bypass assigned IP-based or Key-based rate limits.
- Attempting to scrape the entirety of our database or performing web scraping/crawling on the SukkuAPI website pages.
- Reverse-engineering our proprietary merge engine algorithms.
- Using the provided player data to facilitate harassment, doxing, or malicious activities against Minecraft players.
5. Subscriptions and Billing
API access tiers are billed periodically. You are responsible for keeping your API Key secure. If your key is leaked and abused by a third party, your account will be held responsible for the generated traffic. You may regenerate your API Key at any time from your Developer Dashboard.
6. API Security Obligations
As a developer, you are strictly responsible for securing the communication between your application and our API:
- Client-Side Exposure: You must never expose your API Secret Key in client-side code (e.g., frontend JavaScript, mobile apps). All API calls must be routed through your own backend server.
- Secure Transmission: All requests to the SukkuAPI must be made via HTTPS (TLS 1.2 or higher). Unencrypted HTTP requests are rejected.
- CORS & Origin Protections: If you construct public-facing endpoints that wrap our API, you must configure strict CORS policies and rate-limit your own endpoints to prevent abuse.
7. Liability Limitations & Data Retention
SukkuAPI provides data strictly for entertainment and informational purposes. We do not guarantee 100% uptime unless specified in a custom Enterprise SLA.
- No Liability: Under no circumstances shall SukkuAPI be liable for direct, indirect, or consequential damages resulting from API downtime, data inaccuracies, or unauthorized access to your account due to leaked keys.
- Data Retention: For security audits and rate-limiting purposes, we temporarily retain IP addresses, User-Agents, and request payloads for up to 30 days. We do not sell this telemetry data to third parties.
8. Changes to Terms
We reserve the right to modify or replace these Terms at any time. We will provide at least 30 days notice prior to any new terms taking effect for active Plus Tier subscribers. What constitutes a material change will be determined at our sole discretion.