Inspekt
Get a key

Acceptable Use Policy

The short version: build your own product on it, do not rebuild ours out of it.

1. Who this applies to

This policy is part of the Terms. It covers you and anyone using the service through your API key, including your end users where your product puts the service in front of them. Breaking it is a material breach of the Terms and can lead to suspension or termination under Terms section 10.

2. What you may do

That covers marketplaces, trading platforms, inventory and portfolio tools, price trackers, and content and media sites. It also covers skin-gambling and case-opening operators, as set out next.

3. Skin gambling

We serve skin-gambling, case-opening, roulette, jackpot, coin-flip and other skin-wagering operators. This is a decision we made deliberately, knowing exactly which sector we were taking on. It is not a gap in enforcement, and you do not need to disguise what you run.

If you operate in this category you represent and warrant, on an ongoing basis, that:

3.1 you hold every licence, permit and registration each jurisdiction requires where you operate or where your offering is reachable, unless you have geo-restricted those jurisdictions out;

3.2 you comply with applicable gambling, gaming, lottery, age-verification, anti-money-laundering and consumer-protection law in each of them;

3.3 you will tell us promptly if your licensing status changes, is suspended or is challenged; and

3.4 you will indemnify us for claims arising from your own regulatory exposure, under Terms section 14.2.

We render pictures. We are not a party to your gambling business and take no responsibility for your compliance with gambling law. None of this obliges us to serve any particular operator: we can still decline, suspend or terminate under Terms section 10, for a sanctioned jurisdiction, credible evidence of fraud, or a licensing failure you do not fix. That is the same reservation we hold for every customer, not a back door out of this section.

4. What you may not do

Whatever your plan, you must not, and must not let anyone using your key:

4.1 break any law, regulation or third party's rights;

4.2 reverse-engineer, decompile, extract or scrape the service or the assets underneath it;

4.3 self-host, mirror, sublicense, resell or white-label the service;

4.4 use our output, or what you learn from watching us, to build or improve a competing 3D weapon-skin renderer;

4.5 work around quotas, rate limits, the origin allowlist or key validation, including by guessing keys or systematically probing our error responses to map them;

4.6 use another customer's key, or knowingly allow your key to be used from an origin you have not registered;

4.7 probe, scan or pen-test the service without our written authorization, or otherwise degrade it for other customers, for example with request bursts designed to exhaust capacity;

4.8 send malware, executable payloads or input crafted to exploit us through any field we accept, including inspect links, Steam IDs and name-tag text;

4.9 impersonate us, or claim we endorse your product beyond the wordmark the service itself displays;

4.10 push anything other than genuine Steam and CS2 inspect data through the parameters meant for it;

4.11 use the Inventory API to harvest Steam account data at scale for anything other than showing an account holder their own inventory. No unsolicited bulk lookups, and no building your own inventory database out of our responses;

4.12 use the service with content that is unlawful, fraudulent or deceptive, or that infringes someone else's intellectual property (Valve's aside, which Terms section 11 deals with) or their publicity or privacy rights; or

4.13 aim the service at minors, or knowingly let them use it, in breach of applicable law. This matters most for the age-verification duties in section 3.

5. Reporting a vulnerability

Section 4.7 prohibits unauthorized testing, but we would still rather hear from you than not. If you find a security problem, email hello@inspekt.gg with enough detail to reproduce it. We will not pursue you for a good-faith report about something you found without attacking the service: no denial of service, no accessing other customers' data, no automated scanning, and give us a reasonable chance to fix it before you publish.

6. Enforcement

Breaking this policy can lead to a warning, suspension or termination under Terms section 10, at our discretion and in proportion to what happened. We may report activity we reasonably believe is unlawful to the relevant authorities.

7. Changes

We update this policy the same way we update the Terms, under Terms section 16.