โก
The 0% Markup Guarantee (ยง08)
olywork never inflates upstream API prices. Calls on our catalog keys are metered at exact provider cost in micro-USD. Calls on your own team keys (BYOK) are always 100% free with zero platform fee.
01
Scope and Agreement
olywork ("we", "us", "our") provides an agent tooling registry and credential orchestration proxy at olywork.com (the "Service"). These Terms of Service govern your access to and use of our hosted platform, API, CLI, and associated tools.
Self-hosted installations: If you deploy the open-source olywork engine on your own private infrastructure, your use is governed exclusively by the Apache 2.0 / MIT Source License. We retain no data and assume no operational obligations for self-hosted instances.
02
Accounts and Identity
You access the Service via authentication tokens or OAuth sign-in. You must maintain the confidentiality of your credentials and are fully responsible for all calls and actions initiated under your account tokens, including actions performed by autonomous AI agents operating on your behalf.
- Access tokens are hashed via SHA-256; raw tokens are never persisted in plaintext.
- You may revoke active tokens instantaneously via the dashboard or CLI at any time.
03
Team Workspaces & Role-Based Access
Accounts can create and join multiple team workspaces. Team owners and administrators maintain administrative control over member roles, tool assignment, daily spend caps, and credential configuration.
Members never see or export raw secret values stored by the team. Stored credentials are injected strictly server-side during proxied upstream execution.
04
Credential Vault & Encryption
We treat credential custody with zero-trust architecture:
- All API keys, secrets, and OAuth refresh tokens are encrypted at rest with Fernet authenticated encryption (AES-256-CBC + HMAC-SHA256).
- Secrets are never written to disk unencrypted, never returned to client endpoints, and never rendered in browser interfaces.
- In-flight calls decrypt secrets directly into memory exclusively to inject required authorization headers before transmitting requests upstream.
05
Upstream APIs & Provider Terms
When you execute calls to third-party providers (including Google, LinkedIn, Slack, X, Hunter, and others), you remain bound by the respective terms of service, acceptable use policies, and rate limits of those upstream services. olywork acts as a transport and authorization proxy and does not alter upstream terms.
YouTube API Services: Use of YouTube integrations is subject to the YouTube Terms of Service and Google Privacy Policy. Access may be revoked via Google Security Settings.
06
Acceptable Use & Sandbox Boundaries
You agree not to use the Service for malicious activities, including credential harvesting, denial-of-service attacks, cryptocurrency mining, unsolicited bulk messaging (spam), or attempts to circumvent tenant isolation and server sandboxes.
07
Prepaid Balances & Metered Billing
Catalog endpoints served through olywork-managed provider keys deduct funds from your team's prepaid balance in micro-USD. All deductions match the exact advertised per-call rate card with 0% platform markup. Balances are prepaid and non-refundable except where required by law.
08
Limitation of Liability
The Service is provided "AS IS" and "AS AVAILABLE". To the maximum extent permitted by applicable law, olywork shall not be liable for indirect, incidental, special, consequential, or punitive damages, or loss of profits, data, or goodwill.