anti-abuse-policy Developer

Last updated Aug 15, 2026

Governing language: The Simplified Chinese version is authoritative. This translation is provided for convenience.

Anti-Abuse Policy

Effective date: August 8, 2026

This Anti-Abuse Policy is adopted to protect the security and availability of end users, the developer ecosystem, and 摇月 Swaymoon Developer Portal, Swaymoon Account, and related services (this “Service”). This policy supplements the Developer Portal Terms of Use; if the two conflict, the stricter constraint on abusive conduct prevails. Abuse rules on the Swaymoon Account side are in the Swaymoon Account Anti-Abuse Policy; when both apply, the stricter prevails.

1. Scope

This policy applies to all individuals and organizations that use the Developer Portal or related developer APIs, including registering identifiers, configuring callbacks and privacy policy links, proxying calls to Swaymoon Account developer APIs, and accessing the Portal and documentation.

2. Prohibited Abuse

Without written permission from 摇月 Swaymoon, you must not engage in or assist others in engaging in the following:

2.1 Developer identity and credential abuse

  • Circumventing developer eligibility checks without binding a valid notification email
  • Buying, selling, renting, or lending Developer Portal access or team affiliation
  • Leaking, publicly posting, or sharing client_secret or session tokens, or intentionally deploying a confidential client as a non-confidential client so that the secret is exposed
  • Bulk or automated creation of identifiers with no actual application intent, or occupying system resources

2.2 Identifier and authorization-flow abuse

  • Registering misleading application names or icons, or impersonating 摇月 Swaymoon, other vendors, or well-known applications
  • Registering redirect URIs or data-deletion callbacks you do not control, in order to intercept authorization codes or tokens or to forge deletion confirmations
  • Tricking end users into authorizing permissions unrelated to the business, or using authorized data beyond the agreed scope
  • Abusing OAuth / OIDC flows to carry out phishing, session hijacking, or account takeover
  • Using integration capabilities for illegal applications, content distribution, or underground activity

2.3 Technical and API abuse

  • Scanning, penetrating, stress-testing, or conducting denial-of-service attacks against the Portal, Swaymoon Account APIs, or infrastructure (except security testing with our written authorization)
  • Scraping, bulk-exporting, or reselling data without authorization
  • Interfering with or tampering with requests/responses, spoofing clients, or exploiting rate-limit vulnerabilities
  • Distributing malware or phishing pages, or inducing users to visit a counterfeit Swaymoon Account / Developer Portal page

2.4 Other illegal or harmful conduct

  • Endangering national security or public safety, or infringing the rights and interests of minors
  • Infringing others’ intellectual property, privacy, reputation, or other lawful rights and interests
  • Money laundering, gambling, trading in prohibited goods, or other illegal activities, or facilitating such activities
  • Any conduct we reasonably believe poses a material risk to users, the Service, or third parties

3. Detection and Investigation

We may identify abuse using risk controls, rate limiting, log audits, user reports, third-party intelligence, and similar means. To investigate suspicious activity, we may, to the extent permitted by law, restrict related features, require additional verification, or temporarily suspend the Service.

You agree to cooperate with reasonable investigations. If you refuse to cooperate and a material risk exists, we may proceed directly to the measures in Section 4.

4. Enforcement Measures

Once abuse is confirmed or we have reasonable grounds to believe it exists, we may, depending on the circumstances, take one or more of the following measures:

  • Warn, require remediation, or require that the relevant conduct stop
  • Restrict sign-in to the Developer Portal, or restrict creating or updating identifiers
  • Restrict, disable, or delete related OAuth clients (identifiers)
  • Freeze or terminate developer capabilities, and coordinate measures on the Swaymoon Account side as appropriate
  • Report to competent authorities, or preserve and disclose necessary information in accordance with law
  • Pursue civil, administrative, or criminal liability

In emergencies (such as an ongoing attack or fraud), we may take temporary restrictive measures before prior notice, and inform you within a reasonable time thereafter (except where law provides otherwise or notice would hinder handling).

5. Appeals

If you believe a measure was taken in error, email hello@swaymoon.com within a reasonable period after receiving notice, stating the account identifier, the relevant client_id (if any), times and reasons, and providing verifiable materials. We will review as soon as possible. Where abuse is severe or violations are repeated, we may not restore the Service.

6. Policy Updates

We may update this policy and will publish it on the documentation site. Continued use of this Service constitutes awareness of and acceptance of the updated rules (except where law requires consent to be obtained again).

7. Contact Us

To report abuse or a security vulnerability, or to file an appeal: hello@swaymoon.com

For security issues, please provide reproduction steps and impact scope where possible. Do not conduct destructive testing against the production environment without prior arrangement. For more contact options, see Contact Swaymoon.