API Terms of Use & Acceptable Use Policy
These terms govern your use of the who.is public API. By creating an API key or calling the API you agree to them. They sit alongside the who.is site terms and privacy policy; where the API-specific terms below are more specific, they control for API use.
Permitted use
The API is provided so you can look up and integrate parsed WHOIS, normalized RDAP, and DNS and TLS certificate data for individual domains into your own application, workflow, or research. You may query domains you have a legitimate reason to query and display or store the results within your own product, subject to the restrictions below and to the rate limits and quotas for your plan.
What you may not do
- No resale or redistribution. You may not resell, sublicense, redistribute, or otherwise make the API responses available to third parties as a standalone data product or feed. Use the data inside your own application — do not repackage it as a competing lookup or data service.
- No bulk export or scraping. The API is for per-domain lookups. You may not use it to systematically harvest, mirror, or reconstruct our database, the historical archive, or any substantial portion of it, and you may not circumvent the per-key quotas (for example by rotating keys or creating multiple free accounts).
- No abuse of the service. No using the API to send unsolicited communications, to facilitate unlawful activity, to attempt to de-anonymize or re-identify redacted registrant data, or to probe, overload, or interfere with the service or its infrastructure.
- Keep your key secret. Your API key authenticates as you. Do not embed it in client-side code, public repositories, or anywhere it can be extracted. You are responsible for all calls made with your key.
Rate limits and quotas are enforceable
Each plan has monthly, daily, and per-second limits, and separate sub-quotas for live refreshes and full-history queries. These limits are part of the agreement, not just a technical detail: exceeding them, or engineering your usage to evade them, is a breach of these terms. Quotas are hard caps — there is no metered overage — so a request past your limit is refused rather than billed. The current limits are published on the API documentation page and may change over time.
Suspension and revocation for abuse
We may suspend or revoke any API key, and close the associated account, if we reasonably believe it is being used in violation of these terms — including bulk extraction, redistribution, quota evasion, or activity that threatens the stability of the service. Where practical we will reach out first, but for active abuse we may act immediately to protect the service and other customers. Revocation for abuse is a policy action, not a support negotiation.
Availability
The API is provided on an as-available basis. The Free plan carries no service-level agreement and no uptime, latency, or support guarantee; it may be rate-limited, degraded, or paused — including product-wide — to protect the service. Paid plans receive priority but are still offered without a formal uptime SLA at this time. We may change, deprecate, or withdraw endpoints; material changes will be noted in the API changelog.
Data accuracy
who.is serves registry and registrar data substantially as it is received from the source, together with DNS and certificate observations collected over time. We do not warrant that any response is complete, current, or error-free, and we do not enrich, un-redact, or otherwise reconstruct data that the source has withheld. Registrant details may be redacted at the source for privacy or legal reasons. Do not rely on the API as the sole basis for a legal, financial, or security decision without independent verification.
Changes to these terms
We may update these terms as the API evolves. Continued use of the API after a change takes effect means you accept the updated terms. Questions about acceptable use can go to support@who.is.