AuthLocker

Terms of Use

Effective 1 September 2026

In short. Register a client, build something honest with it, and do not use our name to trick people into signing in. We run on shared upstream OAuth applications, so abuse by one developer can take the service down for everyone — which is why the acceptable use rules below are enforced rather than decorative.

1. The agreement

These terms are between you and Creative Robots Inc, a Delaware corporation with its registered office at 1007 N Orange St, 4th Floor #993, Wilmington, DE 19801, United States (“we”, “us”) and govern your use of AuthLocker at authlocker.dev, including its API. By registering a client or calling the API you accept them. If you are agreeing on behalf of an organisation, you confirm you may bind it.

2. What the service does

AuthLocker is an OAuth 2.1 and OpenID Connect authorization server. It brokers sign-in with third-party identity providers using OAuth applications that we own, and provides an API for verifying email addresses and phone numbers. We may add, change or remove providers and features.

3. Client registration

Registration is open and requires no account. You are responsible for everything done with the credentials you are issued, and for keeping your client secret confidential. It must never be embedded in a browser application, a mobile binary or a public repository — register a public client and use PKCE instead. Tell us promptly at security@authlocker.dev if a secret is exposed; you can rotate it yourself at any time.

4. Acceptable use

You must not use AuthLocker to:

  • Impersonate anyone. Do not register a client whose name, logo or redirect domain suggests it is operated by a company, product or person that is not you. The consent screen a user sees carries our name, and passing that trust to a site you do not own is phishing.
  • Collect credentials, payment details or identity documents under a false pretext, or run any deceptive sign-in flow.
  • Send unsolicited messages, or aim the verification API at numbers you have no relationship with. Artificially inflating SMS traffic to premium-rate destinations is fraud and we treat it as such.
  • Attempt to obtain another client's secrets or another user's tokens, or to correlate users across clients.
  • Circumvent rate limits, spend caps or country restrictions, including by registering multiple clients for that purpose.
  • Probe or load-test the service without our written permission, or use it in a way that degrades it for others.
  • Break the law, or breach the terms of Google, GitHub, Twilio or Amazon Web Services, whose services we rely on.

5. Enforcement

We may disable a client immediately and without notice where we reasonably believe it is being used to phish, to defraud, to commit a crime, or in a way that puts our upstream provider applications at risk. Because those applications are shared, a suspension imposed on us by a provider would affect every developer using AuthLocker, so we act quickly and ask questions afterwards. Write to support@authlocker.dev to appeal.

6. Your obligations to your users

You decide what happens to a profile once we hand it to you, which makes you its controller. You must publish your own privacy policy, obtain any consent your jurisdiction requires, and honour access and deletion requests from your users. Do not tell your users that AuthLocker is responsible for how you handle their data.

7. Availability

There is no uptime commitment. The service may be unavailable for maintenance, because of a failure at one of our infrastructure or identity providers, or for reasons outside our control. Do not use AuthLocker as the sole authentication path for a system where an outage would be dangerous or unlawful.

8. Changes and discontinuation

We may change these terms; the effective date above will change with them, and continued use after that date means acceptance. We may discontinue the service or any provider integration. If we discontinue the service entirely we will make a reasonable effort to give registered developers at least 30 days' notice by email.

9. Intellectual property

We retain all rights in AuthLocker, its software and its branding. You get a non-exclusive, revocable, non-transferable right to use the API as documented. Do not use our name or logo to imply endorsement, and do not present the service as your own.

10. No warranty

The service is provided “as is” and “as available”, without warranties of any kind, whether express or implied, including merchantability, fitness for a particular purpose and non-infringement. We do not warrant that it will be uninterrupted, secure or error-free.

11. Limitation of liability

To the fullest extent the law allows, we are not liable for indirect, incidental, special, consequential or punitive damages, nor for lost profits, revenue or data, arising from your use of the service. Our total aggregate liability is limited to the greater of the amount you paid us in the twelve months before the claim, or one hundred euros (€100). Nothing here excludes liability that cannot lawfully be excluded.

12. Indemnity

You will indemnify us against claims, losses and reasonable legal costs arising from your use of the service, your breach of these terms, or your handling of your users' personal data.

13. Governing law

These terms are governed by the law of France, and the courts of Paris have exclusive jurisdiction, without prejudice to any mandatory protection you have as a consumer in your country of residence.

14. Contact

Creative Robots Inc — support@authlocker.dev. See also our Privacy Policy.