Acceptable use policy
Last updated 1 August 2026
In short: Do not abuse the service, do not resell the raw data, do not use it to break the law or to hurt people. Cache aggressively — we would rather you did.
Things we actively encourage
- Caching responses. It makes your app faster and costs you nothing.
- Bulk exports instead of crawling the catalog one card at a time.
- Conditional requests with ETags. A 304 is free.
- Sending a descriptive
User-Agent. If something goes wrong, it lets us contact you instead of guessing.
Prohibited uses
You may not use the API to:
- Break the law, or help anyone else break it.
- Resell or redistribute the raw dataset, or operate a competing card data API, without a redistribution licence.
- Facilitate fraud, counterfeit card sales, or misrepresent card authenticity or condition.
- Manipulate a market, including coordinated price manipulation of card listings.
- Harass, dox or endanger anyone.
- Circumvent rate limits or credit accounting, including by rotating keys or splitting traffic across accounts to avoid a cap.
- Probe, scan or stress-test the infrastructure without written permission.
- Remove or obscure attribution where these terms require it.
Rate limits and fair use
Stay within your plan's rate limit and back off when you receive a 429. Retrying immediately and repeatedly against a rate limit is itself a violation. Guidance on retry behaviour is in the rate limits documentation.
If you have a legitimate need for a burst well above your plan — a migration, a backfill, a launch — email us beforehand. We will almost always say yes and lift the limit temporarily. We are far less accommodating when we find out afterwards.
Attribution
Attribution is not required on any plan. If your project is public we appreciate a visible credit linking to tcggraph.com, but it is a courtesy rather than a condition.
Card names, artwork and trademarks belong to their publishers. Where a publisher's own policy requires specific attribution or a disclaimer, that obligation is yours and it applies regardless of your plan.
Security research
We welcome it. Report findings to security@tcggraph.com. If you act in good faith, avoid degrading the service, do not access data belonging to other customers and give us a reasonable window to fix the issue, we will not pursue legal action and we will credit you if you would like.
Enforcement
Most problems are accidents — a runaway loop, a misconfigured cron. In those cases we email you first and help you fix it. For deliberate or repeated abuse we may rate-limit, suspend or terminate the account. Where abuse is causing active harm to the service or to others we act first and explain afterwards.
To report abuse of the API by someone else, email abuse@tcggraph.com.