This API Services Agreement (this “API Services Agreement”) is incorporated by reference into, and forms part of, the Master Services Agreement between Monument Software, Inc. (“Monument”) and Customer (the “MSA”), pursuant to Section 8.B (API Tiers) of the MSA. Capitalized terms used but not defined in this API Services Agreement have the meanings given in the MSA. This API Services Agreement sets forth the API Tiers included in the Services, their API Parameters, the definitions of “Standard API Tier,” “Growth API Tier,” and “API Parameters,” and the usage limits and measurement, service management and remedies, and service level provisions applicable to the API. Customer’s access to and use of the API and the MCP Server are otherwise governed by Section 8 (API Access) of the MSA. This API Services Agreement does not set forth any fees; the fees and parameters for any Higher API Tier are set forth in a separate API Capacity Upgrade Agreement as provided in Section 8.I (Higher API Tiers; Separate API Agreement) of the MSA. In the event of a conflict between this API Services Agreement and the MSA, the MSA controls except as to the matters expressly addressed in this API Services Agreement (the composition, API Parameters, and related definitions of the API Tiers, and Sections 3 through 5), as to which this API Services Agreement controls.
1. Definitions.
“API Band” means the band that establishes the Daily Call Quota applicable to Customer within its API Tier, determined by Customer’s Effective Unit Count (as defined in the MSA). The API Bands are: the “Startup Band” (Effective Unit Count of 1 to 1,000 Units); the “Small Business Band” (1,001 to 3,000 Units); the “Medium Business Band” (3,001 to 5,500 Units); the “Large Business Band” (5,501 to 10,000 Units); the “Extra-Large Business Band” (10,001 to 20,000 Units); and the “Corporate Band” (more than 20,000 Units). Customer’s API Band is determined by Customer’s Effective Unit Count as most recently determined under the MSA and adjusts automatically as Customer’s Effective Unit Count moves between bands. The Daily Call Quota corresponding to each API Band, for each of the Standard API Tier and the Growth API Tier, is set forth in Section 2 (Included API Tiers).
“API Parameters” means, with respect to any API Tier, the read/write scope, the Rate Limit, the Burst Limit, and the Daily Call Quota (which, for the Standard API Tier and the Growth API Tier, varies by Customer’s API Band) applicable to that API Tier. The API Parameters for the Standard API Tier and the Growth API Tier are set forth in Section 2 (Included API Tiers). The API Parameters for any Higher API Tier are set forth in the applicable API Capacity Upgrade Agreement.
“Burst Limit” means the maximum number of Calls the API gateway will absorb in a momentary burst above the Rate Limit, expressed as a number of requests and equal to the capacity of the token bucket applied by the API gateway. The Burst Limit represents the target maximum number of concurrent or near-simultaneous request submissions the API gateway will fulfill before rejecting additional Calls with an HTTP 429 (Too Many Requests) response. The API does not provide, and Monument does not commit to, any separate limit on the number of in-flight or open connections.
“Call” means each request submitted to the API that is counted by the API gateway, including each API request, each Webhook delivery attempt, each MCP Server request, and each Tool Call. Each such request counts as one Call regardless of its payload size or response size, and including any request that returns an error (for example, an HTTP 4xx or 5xx response) or an empty result.
“Daily Call Quota” means the maximum number of Calls Customer may make in any twenty-four (24) hour period (a “day,” as measured by the API gateway in Coordinated Universal Time), applied in aggregate across all of Customer’s API Keys. The Daily Call Quota corresponds to a usage-plan quota configured with a daily period. Monument measures Customer’s Calls against the Daily Call Quota on a per-day basis (including by means of the API gateway’s usage-metering interfaces), and, upon or after Customer reaches the Daily Call Quota, Monument may throttle, queue, reject, or suspend Calls as set forth in Section 4 (Service Management and Remedies). For the Standard API Tier and the Growth API Tier, the Daily Call Quota varies by Customer’s API Band as set forth in Section 2 (Included API Tiers).
“Growth API Tier” means the API Tier that provides read and write access and the following API Parameters, applied in aggregate across all of Customer’s API Keys: a Rate Limit of ten (10) requests per second, a Burst Limit of twenty (20) requests, and a Daily Call Quota that varies by Customer’s API Band as set forth in Section 2 (Included API Tiers). The Growth API Tier is intended for moderate, trial-level use of the API and the MCP Server—sufficient to evaluate the API and the MCP Server across a range of tasks, but not sufficient for sustained, high-volume, or in-depth daily production use, for which a Higher API Tier under a API Capacity Upgrade Agreement is required. Customer acknowledges that the write (read-write) functionality of the Growth API Tier may not be generally available, may not be feature-complete, or may not be available to Customer at all as of the date of the applicable Order Form, and Monument makes no representation or warranty that any write functionality is currently available or complete; Monument may, in its sole discretion, make write functionality (or additional write functionality) available during the Term, and nothing in the MSA or this API Services Agreement obligates Monument to develop, release, or make available any write functionality. The availability or unavailability of write functionality does not affect the read functionality of the Growth API Tier.
“Rate Limit” means the maximum sustained, steady-state rate at which Customer may submit Calls, expressed in requests per second (RPS) and applied in aggregate across all of Customer’s API Keys. The Rate Limit corresponds to the steady-state token-refill rate of the token-bucket throttling model applied by the API gateway (that is, the rate at which request tokens are replenished). Calls submitted at a sustained rate exceeding the Rate Limit are throttled and may be rejected with an HTTP 429 (Too Many Requests) response.
“Standard API Tier” means the API Tier that provides read-only access and the following API Parameters, applied in aggregate across all of Customer’s API Keys: a Rate Limit of five (5) requests per second, a Burst Limit of ten (10) requests, and a Daily Call Quota that varies by Customer’s API Band as set forth in Section 2 (Included API Tiers). The Standard API Tier is intended for basic, low-volume, read-only use. The read-only scope of the Standard API Tier applies to every means of accessing it, including the MCP Server and any Tool Calls; accordingly, the Standard API Tier does not permit any write operation (including any operation that creates, modifies, deletes, transfers, or transmits data), whether initiated directly through the API or through the MCP Server.
2. Included API Tiers.
Each Customer receives an included API Tier at no charge as part of the Services. The Software License Tier that includes each API Tier is set forth in Section 8.A (Included API Access) of the MSA: the Core Software License Tier includes the Standard API Tier, and the Pro and Enterprise Software License Tiers include the Growth API Tier. Within each included API Tier, the Daily Call Quota is determined by Customer’s API Band, which is based on Customer’s Effective Unit Count (as defined in the MSA), as set forth in the table below (Rate Limit and Burst Limit do not vary by API Band):
| API Band | Effective Unit Count | Standard API Tier (read-only) Daily Call Quota | Growth API Tier (read & write) Daily Call Quota |
| Startup Band | 1 to 1,000 | 50 Calls/day | 500 Calls/day |
| Small Business Band | 1,001 to 3,000 | 100 Calls/day | 1,000 Calls/day |
| Medium Business Band | 3,001 to 5,500 | 200 Calls/day | 1,500 Calls/day |
| Large Business Band | 5,501 to 10,000 | 300 Calls/day | 2,500 Calls/day |
| Extra-Large Business Band | 10,001 to 20,000 | 500 Calls/day | 3,500 Calls/day |
| Corporate Band | Above 20,000 | 800 Calls/day | 5,000 Calls/day |
All API Parameters apply in aggregate across all of Customer’s API Keys. For the Standard API Tier, the Rate Limit is five (5) requests per second and the Burst Limit is ten (10) requests; for the Growth API Tier, the Rate Limit is ten (10) requests per second and the Burst Limit is twenty (20) requests. Rate Limit and Burst Limit do not vary by API Band. The Rate Limit and the Burst Limit are enforced by the API gateway in real time; the Daily Call Quota is measured per day and enforced as set forth in Section 3 (Usage Limits and Measurement) and Section 4 (Service Management and Remedies). Customer’s API Band, and the corresponding Daily Call Quota, are determined by Customer’s Effective Unit Count as most recently determined under the MSA (which is redetermined monthly) and adjust automatically, without amendment, as Customer’s Effective Unit Count moves between API Bands. The read-only scope of the Standard API Tier and the write-availability limitations of the Growth API Tier are as set forth in the definitions in Section 1 (Definitions).
3. Usage Limits and Measurement.
All API Parameters and other usage limits applicable to the API are calculated and enforced in aggregate across all API Keys issued to Customer and across all environments and applications used by Customer, regardless of the number of API Key Order Forms executed. Each Call is counted as set forth in the definition of “Call” in Section 1 (Definitions). Monument measures Customer’s usage using the API gateway’s throttling and usage-metering data (including per-API-Key usage records aggregated across Customer’s API Keys), and Monument’s measurements are the authoritative record of Customer’s usage for all purposes under this API Services Agreement and the MSA.
The Rate Limit and the Burst Limit are enforced by the API gateway in real time through a token-bucket model: Calls submitted above the Rate Limit draw down the token bucket, and once the bucket (whose capacity is the Burst Limit) is exhausted, additional Calls are rejected with an HTTP 429 (Too Many Requests) response. The Daily Call Quota is measured on a per-day basis; Monument monitors Customer’s aggregate daily Call volume and, upon or after Customer reaches the Daily Call Quota, may throttle, queue, reject (including with an HTTP 429 or 503 response), or suspend Calls or API access as set forth in Section 4 (Service Management and Remedies).
Customer acknowledges that automated throttling and quota enforcement operate on a best-effort basis and that Customer’s actual usage may momentarily or temporarily exceed the API Parameters before enforcement takes effect. Accordingly, the API Parameters state maximum permitted use, and Customer’s obligation not to exceed them is independent of whether any particular Call was actually throttled, rejected, or counted by the API gateway. Monument may enforce the API Parameters (including retroactively, and including by throttling or suspension under Section 4) notwithstanding that some Calls in excess of the API Parameters were fulfilled. The API Parameters do not guarantee any available capacity, throughput, rate, burst, or performance.
The API Parameters are per-Customer aggregate limits. The issuance of multiple API Keys, or the use of multiple environments, applications, accounts, or Customer Affiliates, does not increase any API Parameter or other usage limit. Monument may aggregate and attribute to Customer all Calls made under any API Key issued to Customer or to any Customer Affiliate. Customer shall not, and shall not permit any AI Agent, AI Provider, or third party to, split, distribute, mask, or otherwise arrange traffic across multiple API Keys, accounts, Customer Affiliates, source identifiers, or credentials, in each case for the purpose or with the effect of exceeding, circumventing, or evading any API Parameter or Monument’s measurement or metering of usage.
Customer shall implement reasonable controls to monitor its own API usage and to keep its aggregate usage within the applicable API Parameters, including controls to prevent its AI Agents from generating looping, runaway, duplicative, or otherwise excessive Calls.
4. Service Management and Remedies.
Monument may manage API access as follows:
(a) Throttling and Suspension for Usage. If Customer’s API usage approaches or exceeds any applicable API Parameter, Monument may implement throttling measures to reduce the rate of Calls to sustainable levels, and if Customer’s usage exceeds any applicable API Parameter, Monument may immediately suspend Customer’s access to the API without prior notice.
(b) Protective Throttling and Suspension. In addition to the foregoing, Monument may throttle, rate-limit, queue, reject (including by returning HTTP 429 (Too Many Requests) or 503 responses), or temporarily suspend Customer’s access to the API, with or without prior notice, to the extent Monument reasonably determines necessary to protect the security, stability, integrity, or performance of the API, the MCP Server, the Platform, or the Services, to prevent harm to Monument’s other customers, or to respond to actual or suspected abuse, credential compromise, or a security threat, in each case regardless of whether Customer’s usage is within the applicable API Parameters. Monument will use commercially reasonable efforts to restore normal access promptly after the underlying condition is resolved.
(c) Rate-Limit Responses; Backoff. When Customer reaches or exceeds the Rate Limit, the Burst Limit, the Daily Call Quota, or any other applicable limit, Monument may return an HTTP 429 or 503 response, which may include a “Retry-After” indication. Customer shall honor any “Retry-After” value returned by the API and shall implement exponential backoff with jitter for retries, and shall not retry rejected, failed, or throttled requests in a manner that itself constitutes excessive use or that contributes to the condition giving rise to the rejection.
(d) Rate and Burst. Customer shall not exceed the Rate Limit or the Burst Limit, and Monument may reject, queue, or throttle any Call that would cause Customer to exceed the Rate Limit or the Burst Limit. The API does not impose, and Monument does not commit to, any separate limit on in-flight or open connections, and no such limit is implied by the Rate Limit or the Burst Limit.
(e) Efficient Use. Customer shall use the API efficiently and in accordance with the Documentation, including by (i) using Webhooks in lieu of polling where available and not polling any endpoint more frequently than the minimum interval stated in the Documentation, (ii) caching responses where reasonable to avoid redundant or duplicative Calls, and (iii) requesting only the data reasonably necessary, using the documented pagination and filtering parameters. Monument may limit the maximum size of any request or response payload, the number of records returned per request, and pagination depth, as set forth in the Documentation.
(f) Webhook Endpoints. Customer shall maintain Webhook endpoints that acknowledge receipt within ten (10) seconds of delivery. Monument may retry failed or unacknowledged Webhook deliveries on a schedule of Monument’s choosing and may disable, suspend, or throttle delivery to any endpoint that repeatedly fails, times out, or returns errors. Each Webhook delivery attempt, including failed and retried deliveries, counts as a Call.
(g) Suspension for Non-Payment. Suspension of API access for non-payment is governed by Section 3.J (Late Payments) of the MSA and the other Service Fee provisions of Section 3 (Service Fees) of the MSA. To the extent Customer elects a higher API Tier, suspension for non-payment of the fees associated with that higher API Tier is governed by the separate API Capacity Upgrade Agreement.
(h) Restoration of Service. Following a suspension for non-payment, Monument will restore API access within two (2) business days after Customer’s payment is received and cleared. Following a suspension for prohibited use or a suspension under paragraph (b), (i), or (j), restoration of service shall be at Monument’s sole discretion and may require renegotiation of terms.
(i) Anti-Circumvention and Metering Integrity. Customer shall not, and shall not permit any AI Agent, AI Provider, or third party to, take any action designed or reasonably likely to circumvent, evade, disable, degrade, interfere with, or corrupt any API Parameter, the throttling or quota controls, or Monument’s metering or measurement of usage, including by (i) distributing or splitting traffic across multiple API Keys, accounts, or Customer Affiliates; (ii) masking, spoofing, rotating, or sharing identifiers, source addresses, credentials, or API Keys; (iii) timing or batching requests to exploit quota-reset boundaries; or (iv) manipulating requests or responses to under-count Calls. Any such action is a material breach of this API Services Agreement and the MSA and constitutes grounds for immediate throttling, suspension, or termination of API access under Section 8.J (Suspension and Termination of API Access) of the MSA.
(j) Automated and Runaway Traffic. Because a substantial portion of Customer’s usage may be generated by AI Agents through the MCP Server, Customer is responsible for configuring and supervising its AI Agents to prevent looping, runaway, duplicative, or excessive Calls. Monument may throttle, rate-limit, queue, reject, or suspend Calls or API access, with or without prior notice, where Monument reasonably determines that Customer’s traffic (whether generated by an AI Agent or otherwise) is excessive, anomalous, abusive, automated beyond the applicable API Parameters, or a threat to the security, stability, integrity, or performance of the API, the MCP Server, the Platform, or the Services, regardless of whether Customer is otherwise within the applicable API Parameters. This paragraph supplements Section 8.F (MCP Server and AI Agent Access) and Section 8.G (AI Agent Responsibility and Security) of the MSA.
5. No Service Level Commitment.
The API and the MCP Server are provided on an “as available” basis. Except as expressly stated in an executed API Key Order Form, Monument makes no commitment or representation regarding API uptime, availability, latency, throughput, error rates, or response time, and no such commitment is implied from any Rate Limit, Burst Limit, Daily Call Quota, or API Tier. The API Parameters state maximum permitted use and are targets only; they do not guarantee that any particular rate, burst, or volume of Calls will be accepted or fulfilled. This Section 5 is in addition to, and does not limit, the warranty disclaimers in Section 10 (Warranties and Disclaimer) of the MSA.
6. Relationship to the MSA.
This API Services Agreement supplements Section 8 (API Access) of the MSA by defining the API Tiers and their API Parameters and by setting forth the usage limits and measurement (Section 3), service management and remedies (Section 4), and service level provisions (Section 5) applicable to the API. All other aspects of API access—including API Keys (Section 8.C (API Keys; API Key Order Forms) of the MSA), permitted use and restrictions (Section 8.D (Permitted Use and Restrictions) of the MSA), modifications (Section 8.E (Modifications to the API; Customer Integrations) of the MSA), MCP Server and AI Agent access (Section 8.F (MCP Server and AI Agent Access) of the MSA), AI Agent responsibility and security (Section 8.G (AI Agent Responsibility and Security) of the MSA), restrictions on AI and data use (Section 8.H (Restrictions on AI and Data Use; AI Providers) of the MSA), higher API Tiers (Section 8.I (Higher API Tiers; Separate API Agreement) of the MSA), and suspension and termination of API access (Section 8.J (Suspension and Termination of API Access) of the MSA)—are governed by Section 8 (API Access) of the MSA. Each API Tier included under Section 8 of the MSA is a Contracted Feature, and Monument may update this API Services Agreement (including the API Parameters and the provisions of Sections 3 through 5) consistent with Section 8.E (Modifications to the API; Customer Integrations) of the MSA.
(Aug-01-2026)