Terms of Service

Product: Posting API Operator: Asra (GitHub: Asrasarker) Effective date: 31 August 2026 Last updated: 31 August 2026

These terms govern access to the Posting API (the "Service"): a multi-tenant publishing API that other applications ("Customers") call so their end users ("End Users") can connect social accounts and publish content. We are not a consumer social network and we do not offer a calendar or scheduling UI. We operate as a Tech Provider: other applications call this API so their end users can connect accounts and publish.

This page must be served at https://api.variantpost.com/legal/terms with HTTP 200, no authentication, no cookies required. The privacy policy is at https://api.variantpost.com/legal/privacy.

Replace api.variantpost.com with the production hostname before this page goes live. Contact: legal@api.variantpost.com.


1. Who we are

The Service is operated by Asra. Until a registered legal entity is designated, the operator is the individual associated with GitHub account Asrasarker.

The Customer is the controller of the relationship with that Customer's End Users. We process End User data as a processor in order to complete the Connect and publish jobs the Customer (and the End User, via OAuth consent) requested.

2. The Service

Customers authenticate with Authorization: Bearer sk_live_… or sk_test_…. Keys are shown once and stored as SHA-256 hashes.

The Service:

We do not promise identical reach from identical bytes. Variants are first-class. auto_adapt is the only one-blob fan-out, and we still persist N variants.

Sandbox. sk_test_ keys use the sandbox adapter only. They never call live Instagram, Meta Graph, or other network APIs. Sandbox remote_id values are deterministic and not real posts.

Live keys. sk_live_ keys are intended for production networks. Networks whose live adapter is not yet enabled fail closed with unsupported_for_connection (not retryable). We never silently fall back from live to sandbox.

3. Customer obligations

Customers must:

Customers are responsible for captions, media, first comments, and extra fields they send. Unknown extra keys are rejected.

4. Networks and availability

v1 networks: Instagram (image, carousel, reel; Professional accounts; no Stories), Facebook Pages (text, link, photo, album, video; native schedule 10 minutes–30 days), Threads, LinkedIn personal, X, YouTube, TikTok draft video, Bluesky, Mastodon, Telegram.

Out of v1 (rejected 422 network_not_in_plan): LinkedIn organization pages, WhatsApp, Snapchat, Pinterest, Instagram Stories, Facebook Reels, TikTok Direct Post, Google Business Profile, Reddit.

Network APIs change. Rate limits, quotas, media specs, and review gates are controlled by the networks, not by us. We may pause a network, require reconnect, or fail a delivery with a stable error code (token_invalid, remote_rate_limited, remote_quota, unsupported_for_connection, and others documented in the API contract).

We are not liable for a network refusing, labelling, suppressing, or taking down content.

5. Acceptable use

No Customer or End User may use the Service to:

We may suspend keys, Connections, or a tenant immediately if we reasonably believe this section is violated.

6. Webhooks and security

Webhook bodies are JSON envelopes. Customers must verify:

X-Timestamp: <unix>
X-Signature: v1=<hmac_sha256(secret, "{timestamp}.{raw_body}")>

Reject deliveries where |now - timestamp| > 300s. We do not use X-Signature-256. Secrets are shown once unless rotated. Delivery is at-least-once; dedupe on event_id.

7. Deletion and data

Deletion paths are described in the privacy policy, including:

Post and delivery audit rows may be retained with media URLs redacted, as described in the privacy policy. Tokens are wiped on disconnect, deauthorize, and deletion.

8. Fees, metering, sandbox

Sandbox usage is free. Live usage is billed from delivery.succeeded counts, transcode seconds, and stored GB-month, plus pass-through network costs (for example X credits, YouTube quota). Prices, if any, will be agreed separately. We may hard-cap YouTube videos.insert per tenant.

9. Disclaimers

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. We do not warrant that a given post will appear, remain, or perform on a network, or that live adapters will be enabled on any date.

10. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE ARE NOT LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOST PROFITS, REVENUE, DATA, OR GOODWILL, EVEN IF ADVISED OF THE POSSIBILITY. OUR TOTAL LIABILITY FOR ALL CLAIMS IN THE AGGREGATE SHALL NOT EXCEED THE FEES THE CUSTOMER PAID US FOR THE SERVICE IN THE THREE MONTHS BEFORE THE CLAIM (OR USD $100 IF NO FEES WERE PAID).

Some jurisdictions do not allow some limitations; in those places our liability is limited to the greatest extent permitted.

11. Indemnity

Customers will indemnify and hold us harmless from claims, damages, and reasonable legal fees arising from: content they or their End Users submit; their product; their violation of these terms or of a network's terms; or their End Users.

12. Changes and termination

We may change these terms by posting a new "Last updated" date here. Material changes take effect 14 days after posting, or immediately if required by a network or by law. Continued API use after the effective date is acceptance.

Either party may stop using or providing the Service at any time. On termination we revoke keys, and we delete or anonymize End User tokens and media per the privacy policy. Sections 9–11 survive.

13. Law

These terms are governed by the laws of the State of New York, excluding conflict-of-law rules, unless mandatory consumer law in the Customer's or End User's country says otherwise. Courts located in New York County, New York, have exclusive jurisdiction, except that we may seek injunctive relief in any forum.

14. Contact