V
Vorenthic Identity
IDENTITY PLATFORM GOVERNANCE

Terms of Service

Last updated: July 25, 2026 • Effective Date: July 25, 2026

01. Acceptance of Platform Terms

By creating a Vorenthic Identity account, accessing our OAuth 2.0 / OpenID Connect endpoints (`/auth/o/*`), or integrating "Continue with Vorenthic" into your web or mobile applications, you agree to be bound by these Terms of Service.

If you do not agree to these Terms, you may not register OAuth applications or use our Single Sign-On (SSO) services.

02. Developer OAuth Application Rules

Developers configuring client applications via the Vorenthic Developer Console agree to:

  • Exact Redirect URIs: Register exact, valid HTTPS callback URLs (`redirect_uris`). Wildcard URIs or unencrypted HTTP endpoints (except `http://localhost`) are strictly forbidden.
  • Client Secret Confidentiality: Maintain strict security over issued 256-bit client secrets. Secrets must never be committed to public code repositories or client-side code bundles.
  • PKCE Enforcement: Use PKCE `S256` SHA-256 code challenge verification for all public clients (SPAs, mobile apps).

03. Acceptable Use & Abuse Prevention

You may not use Vorenthic Identity to:

No Phishing / Deception Spoofing identity provider screens or tricking users into revealing credentials.
No Token Scraping Automated scraping, credential stuffing, or token harvesting.
No Denial of Service Flooding token or authorization endpoints to disrupt edge availability.
No Scope Escalation Accessing claims beyond what the end-user explicitly consented to.

04. Service Availability & Rate Limits

Vorenthic Identity operates on Cloudflare Edge infrastructure with global high availability. We enforce automated rate limits via Cloudflare KV namespaces to prevent denial-of-service attacks and ensure fair resource distribution across all third-party developer clients.

05. Account Termination

We reserve the right to suspend or terminate developer applications or user accounts that violate these Terms of Service or engage in deceptive authentication practices. Suspended applications will have their Client IDs revoked and access tokens invalidated immediately.

06. Contact Legal Engineering

For legal inquiries, developer compliance questions, or security disclosures, reach out to our team at legal@vorenthiclab.com.

© 2026 VorenthicLab Inc. All rights reserved.