Token Box Acceptable Use Policy
Effective: September 12, 2026
This Policy explains the rules for using the Token Box website, console, and APIs. You must use Token Box lawfully, responsibly, and in a way that does not harm others or the service.
1. 基本原则
你应遵守适用的法律法规、监管要求、第三方权利和所选模型提供商的使用政策。不得利用 Token Box 绕过安全控制、访问限制、计费规则或上游提供商的限制。
你应对通过账户、API Key 或集成应用发起的活动负责,并采取合理措施防止未经授权的访问。
1. Core principles
You must comply with applicable laws, regulations, third-party rights, and the usage policies of the model provider you select. Do not use Token Box to bypass security controls, access restrictions, billing rules, or provider limits.
You are responsible for activity performed through your account, API keys, or integrations and must take reasonable measures to prevent unauthorized access.
3. 访问控制与 API Key
API Key 仅供授权用户和应用使用。不得公开发布、共享给无关第三方、嵌入前端代码或用于未经授权的多租户转发。发现密钥泄露、异常用量或账户被入侵时,应立即撤销密钥并联系支持。
不得规避速率限制、额度限制、身份验证、风控或其他技术措施,也不得创建多个账户以规避限制或处罚。
3. Access controls and API keys
API keys are for authorized users and applications only. Do not publish them, share them with unrelated third parties, embed them in client-side code, or use them for unauthorized multi-tenant relaying. If a key is exposed or you detect unusual usage or account compromise, revoke it and contact support promptly.
Do not evade rate limits, credit limits, authentication, risk controls, or other technical measures, and do not create multiple accounts to avoid restrictions or enforcement.
4. 内容与使用责任
你应确保对提交的输入、文件和个人数据拥有必要的权利、授权和法律依据,并负责核验模型输出后再使用。模型输出可能不准确、有偏差、过时或与他人相似。
请勿提交不必要的身份证件、支付凭证、健康信息、密码、API Key 或其他敏感信息。对于高风险场景,请安排合适的人工审核和安全控制。
4. Content and user responsibility
You must have the necessary rights, authorization, and legal basis for inputs, files, and personal data you submit, and you are responsible for reviewing model output before using it. Model output may be inaccurate, biased, outdated, or similar to output provided to others.
Do not submit unnecessary identity documents, payment credentials, health information, passwords, API keys, or other sensitive information. Use appropriate human review and safeguards for high-impact scenarios.
5. 处理违规行为
我们可以调查疑似违规行为,并根据风险采取警告、限流、阻止请求、暂停或终止账户、撤销 API Key、删除相关内容或配合执法等措施。紧急情况下,为保护用户、公众或服务安全,我们可能不经事先通知立即采取措施。
我们会在适用法律和实际情况允许的范围内考虑违规的性质、严重程度、重复发生情况以及补救措施。
5. Enforcement
We may investigate suspected violations and take measures appropriate to the risk, including warnings, rate limits, blocking requests, suspending or terminating accounts, revoking API keys, removing related content, or cooperating with law enforcement. In urgent cases, we may act immediately without prior notice to protect users, the public, or the service.
Where permitted by law and circumstances, we consider the nature, severity, recurrence, and remediation of the violation.
6. 举报、申诉与政策更新
如果你发现疑似滥用、泄露、未授权访问或其他违反本政策的行为,请尽快提供相关 URL、请求 ID、时间范围和必要的事实信息,但不要发送 API Key 或完整敏感内容。
你可以对与账户相关的限制措施联系支持团队提出说明或申诉。我们可能更新本政策,重大变更会通过网站或控制台以合理方式通知,并注明新的生效日期。
6. Reporting, appeals, and updates
If you identify suspected abuse, exposure, unauthorized access, or another violation, contact us promptly with relevant URLs, request IDs, time ranges, and necessary facts. Do not send API keys or complete sensitive content.
You may contact support to provide context or appeal an account restriction. We may update this Policy; material changes will be announced through the website or console in a reasonable manner with a new effective date.