OKX API Agreement

Опубликовано 26 мар. 2026 г.

This OKX API Agreement (the “Agreement”) governs access to and use of the OKX Application Programming Interfaces (the “API Services”). This Agreement supplements the OKX Terms of Service (“OKX ToS”). In the event of conflict, this Agreement controls solely with respect to API Services. By accessing or using the API Services, you agree to be bound by this Agreement and the OKX ToS.

1. Definitions

The following terms have the meanings given below. Terms not defined herein have the meanings given in the OKX ToS.

1.1 “API Key” means a unique credential (comprising a key, secret, and passphrase) issued by OKX to a verified User to authenticate programmatic access to the API Services.

1.2 “API Services” means collectively the OKX REST API, WebSocket API, SBE(Simple Binary Encoding), Fast API, Agent Trade Kit, and all related interfaces, endpoints, documentation, data feeds, and tooling made available by OKX for programmatic access, as further described in Section 3.

1.3 “Agent Trade Kit” means the suite of tools made available by OKX to facilitate programmatic and AI-agent interaction with the API Services, including the MCP Server, Skills, CLIs, SDKs, and related infrastructure, as further described in Section 4.

1.4 “Authorized AI Agent” means an LLM, artificial intelligence system, algorithmic trading system, automation script, or other non-human software system that a User configures to access the API Services on the User’s behalf under this Agreement.

1.5 “CLI” or “Command-Line Interface” means a text-based interface provided as part of the Agent Trade Kit that allows Users and Authorized AI Agents to interact with the API Services via command-line instructions, scripts, or terminal environments, without requiring a graphical user interface.

1.6 “MCP” or “Model Context Protocol” means the open protocol standard that enables AI agents and LLMs to interact with external tools and data sources in a structured, standardized manner. The OKX MCP Server implements this protocol to enable Authorized AI Agents to access the API Services.

1.7 “MCP Server” means OKX’s implementation of the Model Context Protocol (MCP), which exposes OKX API Services as structured tools callable by LLMs and Authorized AI Agents that support the MCP standard.

1.8 “Market Data” means any price, order book, trade history, ticker, funding rate, index, volatility surface, open interest, trading volume, or other market information made available through the API Services or through OKX’s publicly accessible endpoints, whether accessed with or without authentication.

1.9 “OKX Materials” means the API Services, Agent Trade Kit, MCP Server, Skills, CLIs, SDKs, documentation, specifications, protocols, software, interfaces, data schemas, Market Data, and all related materials provided by OKX under this Agreement.

1.10 “SDK” or “Software Development Kit” means a collection of pre-built libraries, code examples, authentication helpers, and developer tools provided by OKX (or maintained by OKX-approved third parties) to facilitate the integration of the API Services into applications and trading systems. SDKs are available in multiple programming languages.

1.11 “Skills” means task-specific instruction sets provided as part of the Agent Trade Kit that describe how Authorized AI Agents should perform designated categories of OKX operations. Skills provide AI agents with the operational context and guidance needed to execute trading, account management, market data, and bot-related tasks through the Agent Trade Kit by providing the agent with MCP tools to use, without requiring the agent to call OKX APIs directly.

1.12 “Third-Party AI Provider” means any company or individual whose AI model, LLM, or AI inference service a User integrates with the API Services, including but not limited to OpenAI, Anthropic, Google DeepMind, Meta AI, Mistral AI, and their respective successors and affiliates.

1.13 “User” means any individual or entity that has a verified OKX account and accesses or uses the API Services under this Agreement. References to “you” or “your” mean the User.

2. Eligibility

2.1 General Eligibility

Access to the API Services is available to all Users who hold a valid, verified OKX account and who meet the eligibility requirements set out in the OKX ToS, including applicable age, residency, and jurisdictional requirements. Institutional and professional users, as well as retail users, are eligible to access the API Services, subject to the conditions in this Section 2 and any product-specific eligibility restrictions imposed by OKX from time to time.

2.2 KYC and Onboarding

Users must have completed OKX’s KYC and AML verification process at the level required for API access and must not be subject to any account restrictions at the time of application. OKX may require additional information about a User’s intended use case, AI systems, trading strategies, or risk management frameworks before granting or continuing API access. OKX reserves the right to apply enhanced due diligence to any User and to restrict or revoke API access where OKX determines, in its sole discretion, that the User presents elevated risk.

3. Scope of API

3.1 API Access

OKX provides programmatic access to a broad range of account, trading, market data, funding, and ancillary services via its APIs (the API Services). The specific endpoints, rate limits, authentication requirements, and data schemas applicable to each service category are set out in the OKX API documentation available at https://www.okx.com/docs-v5/en/, as updated from time to time. Access to specific service categories may be subject to additional eligibility requirements, account tier restrictions, or product-specific terms.

3.2 Service Categories

The API Services include, but are not limited to, the following service categories. OKX may add, modify, or discontinue service categories at any time in accordance with Section 15. Certain services listed below may not be available in your jurisdiction or region.

(a) Market Data. Public market data endpoints that do not require authentication, including real-time and historical price tickers, order book snapshots and updates, recent trade data, candlestick / OHLCV data, funding rates, index prices, mark prices, open interest, volatility surfaces, and instrument specifications across all product types. Public Market Data endpoints are accessible without an API Key but remain subject to this Agreement, the OKX ToS, and the market data restrictions in Section 9.

(b) Agent Trade Kit. The MCP Server, Skills, CLIs, and SDKs that collectively form the Agent Trade Kit, enabling Authorized AI Agents and developer tooling to interact with the API Services in a structured, programmatic manner, as further described in Section 4.

(c) Trading Account . Authenticated endpoints for account configuration and management, including retrieval of account balances, positions, margin information, leverage settings, account mode configuration, fee rates, and account-level risk parameters.

(d) Trade (Order Book Trading). Authenticated endpoints for the placement, amendment, and cancellation of orders across spot, margin, futures, perpetual swap, and options products, including single orders, batch orders, and post-only or reduce-only order types. Also includes retrieval of open orders, order history, and fill history.

(e) Algo Trading. Authenticated endpoints for the creation and management of algorithmic order types, including Iceberg orders, TWAP (Time-Weighted Average Price) orders, trailing stop orders, and other advanced order execution strategies.

(f) Grid Trading. Authenticated endpoints for the creation, management, and termination of automated grid trading bots, including Spot Grid, Futures Grid, and Moon Grid strategies, and retrieval of grid trading history and performance metrics.

(g) Signal Bot Trading. Authenticated endpoints allowing integration with external trade signals to trigger order placement and position management actions automatically in response to user-defined or third-party signal inputs.

(h) Recurring Buy. Authenticated endpoints for configuring and managing automated recurring purchase strategies (dollar-cost averaging) for spot assets, including creation, modification, and termination of recurring buy plans.

(i) Copy Trading. Authenticated endpoints for the copy trading service, enabling eligible users to replicate the trading activity of lead traders, including configuration of copy parameters, monitoring of copied positions, and retrieval of copy trading performance data.

(j) Block Trading. Authenticated endpoints for negotiating and executing large-notional over-the-counter block trades between counterparties, including request-for-quote (RFQ) creation, quote submission, and settlement.

(k) Funding Account. Authenticated endpoints for managing fund transfers between a User’s trading account and funding account, including asset transfers, deposit address retrieval, deposit and withdrawal history, and asset balance inquiries. Initiation of external withdrawals via API is subject to additional security controls and may be restricted at OKX’s discretion.

(l) Earn Products. Authenticated endpoints for OKX’s earn products, including Simple Earn (flexible and fixed-term), On-Chain Earn, ETH Staking, SOL Staking, and other yield-generating products, encompassing subscription, redemption, and earnings retrieval. Access to Earn endpoints is subject to product availability in the User’s jurisdiction and applicable product-specific terms.

(m) Sub-Account Management. Authenticated endpoints for master account holders to create, configure, and manage sub-accounts, including transfer of assets between sub-accounts and master accounts, configuration of sub-account API keys, and retrieval of sub-account balances and transaction history.

(n) Spread-Trading. Authenticated endpoints for trading spread instruments, including order placement, order management, and retrieval of spread order book and trade data.

(o) Broker and Affiliate Services. Authenticated endpoints available to Users who have been approved by OKX as registered brokers, partners or affiliates, enabling eligible rebate management and other broker-specific functions. Access to broker endpoints may require separate approval and may be subject to additional terms. End users may authorize a broker, partner or affiliate to interact with the API on their behalf.

3.3 Permitted Use

Subject to this Agreement and the OKX ToS, Users may access the API Services for lawful trading, account management, market data consumption, and integration purposes. Users may configure an Authorized AI Agent to access the API Services on their behalf, subject to the conditions in Sections 4 and 5.

3.4 LLM and AI Integration

Users may use the API Services to connect to, integrate with, or operate through their own LLMs, Authorized AI Agents, or automation tools, provided that such usage complies with this Agreement, the OKX ToS, and the terms of use of the relevant Third-Party AI Provider. An Authorized AI Agent may be authorized to perform the following functions, subject to the exclusions in Section 3.5:

(a) Read Access: retrieve real-time Market Data, order book data, account balances, open positions, order history, and other data made available via the API Services;

(b) Order Placement: submit orders for spot, futures, perpetual swap, options, algo, and grid products;

(c) Order Management: modify or cancel existing orders that have not yet been executed; and

(d) Position Management: reduce or close existing open positions.

3.5 Excluded Functions

The following functions are expressly excluded from the scope of authority that may be delegated to an Authorized AI Agent, regardless of User configuration:

(a) modifying Account security settings, including API key management, two-factor authentication settings, or withdrawal address whitelists;

(b) entering into any delegation of authority to further third parties without OKX’s prior consent;

(c) accessing or modifying KYC or personal identification information;

(d) accepting new terms, agreements, or product-specific terms on behalf of the User; and(e) taking any action that is prohibited under this Agreement, the OKX ToS, or applicable law.

3.6 No Expansion of Platform Rights

API access does not expand or modify the rights, permissions, trading privileges, or product access otherwise granted to the User under the OKX ToS. The API Services are an interface to the same underlying Platform capabilities to which the User is entitled based on their account verification level, jurisdiction, and applicable terms.

4. Agent Trade Kit (MCP Server, Skills, CLIs, SDKs)

4.1 Description

The Agent Trade Kit is OKX’s suite of developer tools designed to facilitate structured, programmatic access to the API Services, particularly for AI-agent and LLM-based integrations. The Agent Trade Kit comprises several components including, but not limited to MCP Server, Skills and CLIs.

4.2 No Validation of Logic

OKX does not review, validate, audit, endorse, or evaluate the internal logic, prompts, strategy, model weights, or behavior of any Authorized AI Agent. OKX’s provision of the Agent Trade Kit does not constitute approvalof, or responsibility for, any action taken by an Authorized AI Agent.

4.3 Skills provided as is

Skills are provided strictly on an “as is” basis, without any representation or warranty — express or implied — that any Skill is accurate, complete, current, or fit for any particular purpose. Skills may contain errors, ambiguities, or gaps, and may become outdated following changes to the API Services, the OKX platform, or market conditions. Prior to deploying any Skill in a live trading or production environment, the User must independently review, test, and validate the behavior of that Skill to satisfy themselves that it performs as intended under their specific configuration and use case. OKX bears no liability for any losses, damages, or claims arising from or related to the execution of any Skill, including where such losses result from an error, ambiguity, outdated instruction, or unexpected interaction contained within or arising from the Skill. The User’s reliance on any Skill without independent validation is at the User’s sole risk.

4.4 Monitoring and Intervention

OKX, notwithstanding Section 4.2, implements monitoring mechanisms to detect abusive, manipulative, anomalous, or unauthorized API . OKX may throttle, suspend, modify, or terminate API or Trade Kit access for any account at any time in accordance with Section 14. The foregoing monitoring is generally conducted for platform integrity or regulatory compliance purposes and does not constitute pre-trade review or approval of any individual Authorized AI Agent strategy.

4.5 Right to Modify or Discontinue

OKX retains the right to modify, throttle, suspend, or discontinue any component of the Agent Trade Kit at any time. OKX may revoke individual User access to the Agent Trade Kit without prior notice if OKX detects suspicious, unauthorized, or prohibited activity.

5. Account Control and Delegated Instructions

5.1 User Responsibility for API Keys. You are solely responsible for the generation, safekeeping, rotation, and revocation of all API Keys, credentials, permissions, and access tokens associated with your account. You must not share API Keys with unauthorized persons and must promptly revoke any API Key that may have been compromised.

5.2 AI Agents as Authorized Delegates. Where you configure an Authorized AI Agent to access your account via the API Services or Agent Trade Kit, that system shall be deemed your authorized delegate acting on your explicit instruction. You are responsible for all actions taken by your Authorized AI Agent under your account, to the same extent as if you had taken those actions manually.

5.3 User Control and Attribution. Every API call submitted by an Authorized AI Agent under your account credentials is deemed your instruction. OKX does not validate the logic, strategy, or outputs of your Authorized AI Agent and is entitled to act on all instructions received in accordance with your API credentials without independent verification.

6. Orders, Verification, and Instruction Validity

6.1 Verification Standard. Where orders are generated autonomously by an Authorized AI Agent, you acknowledge that:

(a) the system operates pursuant to your configuration and authorization;

(b) you are deemed to have verified, reviewed, and confirmed the transaction logic through your deployment and configuration of that system; and

(c) OKX is entitled to treat each order as a valid, authenticated instruction from you.

6.2 Accuracy and Responsibility. You remain solely responsible for ensuring the validity, accuracy, and appropriateness of all orders and API actions conducted under your account, including those generated by Authorized AI Agents. You should implement appropriate pre-trade risk controls and position limits at the application level, independent of any controls OKX may impose.

7. No Investment Advice; Execution-Only

7.1 Execution and Data Only. OKX provides data access and order execution services only through the API Services. OKX does not provide investment advice, trading recommendations, portfolio management, or financial planning services through the API Services or Agent Trade Kit.

7.2 AI Output Attribution. Any output generated by a User’s AI model, LLM, or Authorized AI Agent is not attributable to OKX. OKX is not responsible for the accuracy, completeness, or suitability of any AI-generated analysis, recommendation, or trading signal.

7.3 No Fiduciary Relationship. Nothing in the API Services or Agent Trade Kit establishes a fiduciary, advisory, brokerage, or discretionary trading relationship between OKX and the User or between OKX and any Authorized AI Agent or Third-Party AI Provider.

8. PROHIBITED CONDUCT

In addition to the prohibited conduct set out in the OKX ToS, the following conduct is expressly prohibited in connection with the API Services:

8.1 Market Integrity

(a) configuring an Authorized AI Agent with the intent or foreseeable effect of engaging in wash trading, layering, spoofing, quote stuffing, momentum ignition, or any other form of market manipulation;

(b) using the API Services to implement strategies that exploit OKX’s system vulnerabilities, latency arbitrage, or order matching logic in a manner not consistent with legitimate trading;

(c) operating an Authorized AI Agent in a manner that degrades platform performance, imposes unreasonable load on OKX’s infrastructure, or circumvents rate limits; and

(d) deploying an Authorized AI Agent that has been trained on, or that processes, material non-public information in the course of placing orders.

8.2 Access and Security

(a) Granting API access or credentials to any third party not authorized under this Agreement;

(b) Attempting to circumvent platform restrictions through the use of multiple accounts, sub-accounts, or coordinated AI agents; and

(c) Misrepresenting to OKX the nature, capabilities, or intended use of any Authorized AI Agent.

8.3 Third-Party AI Provider Terms of Service Compliance

(a) Overview. Where a User integrates the API Services with a Third-Party AI Provider’s model or service, the User is solely responsible for ensuring that their use of the API Services complies with all applicable terms of service, usage policies, and acceptable use policies of that Third-Party AI Provider. OKX is not a party to any agreement between a User and a Third-Party AI Provider, and OKX bears no responsibility for a User’s violation of such terms.

(b) Specific Restrictions. Without limiting the generality of the foregoing, Users acknowledge that Third-Party AI Provider terms commonly impose restrictions that may affect the permitted scope of API integration

(c) User Obligation. If a Third-Party AI Provider’s terms of service prohibit or restrict the specific use case for which a User intends to employ the API Services — including but not limited to fully automated trading without human oversight — the User must not implement that use case through the API Services, regardless of any technical capability to do so. OKX’s provision of API access does not constitute authorization to use that access in a manner that violates a Third-Party AI Provider’s terms. Any breach of this Section 8.3 shall constitute a material breach of this Agreement. OKX shall be entitled, in addition to any other remedies available to it, to immediately suspend or terminate the User’s access to the API Services without prior notice.

(d) Indemnification for Third-Party Violations. Users shall indemnify and hold harmless OKX against any claims, losses, or liabilities arising from or in connection with the User’s integration of any Third-Party AI Provider with the API Services, including any violation of such Third-Party AI Provider’s terms of service, and any loss, damage, or liability arising from any failure, malfunction, security vulnerability, or erroneous output of any Third-Party AI Provider’s model or service used in connection with the API Services, regardless of whether such failure constitutes a violation of the Third-Party AI Provider’s terms.

9. Intellectual Property; Limited License; Non-Commercial Use

9.1 Ownership

All rights, title, and interest in and to the OKX Materials, including the API Services, Agent Trade Kit, MCP Server, Skills, CLIs, SDKs, documentation, specifications, protocols, software, interfaces, data schemas, and Market Data (collectively, the “OKX Materials”), are and shall remain the exclusive property of OKX or its licensors. Nothing in this Agreement transfers any ownership rights in the OKX Materials to the User.

9.2 Limited License

Subject to compliance with this Agreement and the OKX ToS, OKX grants you a limited, revocable, non-exclusive, non-transferable, non-sublicensable license to access and use the API Services solely: (a) for your own internal purposes; (b) in connection with managing and operating your own OKX account; and (c) in a manner consistent with this Agreement and the OKX ToS.

9.3 Non-Commercial Use Restriction

Unless expressly authorized in writing by OKX, you may not:

(a) commercialize, resell, sublicense, distribute, or make available the API Services or Agent Trade Kit to any third party;

(b) offer the API Services as part of a commercial product, SaaS platform, brokerage service, signal service, strategy marketplace, or managed trading service;

(c) use the API Services to operate trading accounts or execute orders on behalf of third parties without OKX’s prior written approval; or

(d) create derivative commercial infrastructure based on the MCP Server, Skills, CLIs, SDKs, or Trade Kit tooling.

For the avoidance of doubt, use of the API Services to execute trades for your own account, even if profitable, does not constitute commercial resale. However, operating the API Services as a service for others requires prior written approval from OKX.

9.4 Market Data — Non-Commercial Use and Redistribution Restrictions

General Restriction. Market Data obtained through the API Services is proprietary to OKX or its data licensors. You may access and use Market Data solely for your own personal, non-commercial trading and account management purposes. You may not:

(a) resell, redistribute, publish, display, or otherwise make Market Data available to any third party, whether for commercial gain or otherwise, without OKX’s prior written consent;

(b) use Market Data to build, operate, or contribute to any competing data product, market data service, financial data aggregator, price feed, or analytics platform;

(c) use Market Data to train, fine-tune, or evaluate any machine learning model or AI system that is intended to be commercialized or made available to third parties; or

(d) use Market Data in any manner that competes with or substitutes for OKX’s commercial data licensing offerings.

Public Endpoint Data. OKX makes certain Market Data available through unauthenticated public API endpoints without requiring an API Key. The restrictions in this Section 9.4 apply equally to Market Data accessed through public endpoints as to Market Data accessed through authenticated endpoints. The fact that Market Data is publicly accessible does not grant any right to redistribute, resell, or commercially exploit that data.

Automated Scraping and Circumvention. You must not use automated scripts, bots, web scrapers, or any other automated means to extract Market Data from OKX’s public endpoints or website at a rate or scale that: (a) exceeds what is reasonably necessary for your personal trading use; (b) is intended to circumvent OKX’s commercial data licensing requirements; or (c) imposes unreasonable load on OKX’s infrastructure. Users who require high-frequency or large-scale access to Market Data for commercial or institutional purposes must obtain a separate data licensing agreement with OKX.

Non-OKX Users. OKX acknowledges that certain Market Data endpoints are accessible without an OKX account or API Key. Any person accessing OKX Market Data through public endpoints without authentication is subject to the same Market Data restrictions set out in this Section 9.4. OKX reserves the right to implement rate limiting, authentication requirements, or other technical measures on public endpoints at any time to protect the commercial value of its Market Data. Bypassing or circumventing such technical measures is expressly prohibited and constitutes a violation of this Agreement and, where applicable, applicable computer fraud or unauthorized access laws.

9.5 General IP Restrictions

You shall not: reverse engineer, decompile, disassemble, or attempt to derive source code of any OKX Materials; circumvent rate limits or security controls; modify or create derivative works of the MCP Server protocol or Trade Kit infrastructure; remove or alter any proprietary notices; or use OKX trademarks, trade names, or logos without OKX’s prior written consent.

9.6 Feedback

If you provide feedback, suggestions, or improvements regarding the API Services, you grant OKX a perpetual, irrevocable, royalty-free, worldwide license to use and incorporate such feedback without restriction or compensation to you.

9.7 Reservation of Rights

All rights not expressly granted are reserved by OKX. OKX may revoke the license granted under this Section at any time upon breach of this Agreement or if required for security, compliance, or regulatory reasons.

10. DISCLOSURE OF AI SYSTEM INFORMATION

10.1 OKX may, from time to time, require the User to disclose information about any Authorized AI Agent, including: (a) the identity of the AI model, LLM, or Third-Party AI Provider; (b) the general nature of the trading strategy implemented; (c) the risk management controls implemented at the User’s or AI provider’s level; and (d) any known limitations, failure modes, or historical incidents of unexpected behavior.

10.2 The User must notify OKX promptly upon becoming aware, and in any event within 24 hours, if: (a) the Authorized AI Agent exhibits unexpected or anomalous trading behavior; (b) the User becomes aware of a security incident affecting the AI system or API credentials; or (c) the AI model or Third-Party AI Provider used is materially changed, updated, or replaced.

11. DISCLAIMER OF WARRANTIES AND LIMITATION OF LIABILITY

11.1 No warranty on AI Outputs. OKX makes no representation or warranty as to the accuracy, reliability, suitability, or fitness for purpose of any data, signal, analysis, or output provided through the API Services or accessible to an Authorized AI Agent. The User acknowledges that AI models may produce erroneous, hallucinated, or otherwise unexpected outputs, and that OKX bears no responsibility for the consequences of such outputs.

11.2 No Liability for AI-Driven Losses.

To the maximum extent permitted by applicable law, OKX shall not be liable for any losses, damages, or claims arising directly or indirectly from: (a) any order submitted by an Authorized AI Agent; (b) the failure, malfunction, misconfiguration, hallucination, or unexpected behavior of an Authorized AI Agent or LLM; (c) any security breach affecting the User’s AI system, API credentials, or MCP configuration; (d) any interruption to the API Services or Agent Trade Kit, whether scheduled or unscheduled; (e) the User’s violation of any Third-Party AI Provider’s terms of service in connection with the API Services, or (f) any error, inaccuracy, ambiguity, omission, or defect in any Skill, including where such Skill is executed by an Authorized AI Agent and results in an unintended order, position, or account action.

11.3 User Bears Risk. The User expressly acknowledges that the use of an Authorised AI Agent for trading carries significant risks that differ from and are additional to the risks of manual trading, including risks arising from model failure, adversarial inputs (including prompt injection), latency, and market conditions that the AI model may not be equipped to handle. The User accepts these risks in full.

11.4 Indemnification. The User shall indemnify, defend, and hold harmless OKX, its affiliates, officers, directors, employees, and agents from and against any claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising from or related to: (a) the User’s use of the API Services or any Authorized AI Agent, including any use or execution of a Skill; (b) any breach of this Agreement or the OKX ToS; (c) any violation of any Third-Party AI Provider’s terms of service; (d) any regulatory action or proceeding arising from API activity attributable to the User’s account; or (e) any third-party claim arising from orders submitted by the User’s Authorized AI Agent.

12.SECURITY

12.1 The User is solely responsible for the security of their API Keys, MCP credentials, and any access tokens. The User must implement commercially reasonable security measures, which shall include at minimum: (i) enabling multi-factor authentication on the User’s OKX account; (ii) restricting API Key permissions to the minimum scope required for the intended use case; (iii) enabling IP address allowlisting on API Keys where available; (iv) storing API Keys and access tokens in encrypted form and never in plaintext in code repositories or logs; and (v) rotating API Keys promptly upon any suspected or confirmed compromise to prevent unauthorized access, including multi-factor authentication where available.

12.2 The User is solely responsible for ensuring that any AI system or infrastructure under the User’s control that is used to host or operate an Authorized AI Agent is secured against prompt injection attacks, adversarial manipulation, and unauthorized third-party access. OKX makes no representation as to the security of the User’s AI environment and shall not be liable for any losses, damages, or unauthorized instructions arising from a prompt injection attack or adversarial manipulation directed at the User’s systems, regardless of whether the resulting API call was processed in good faith by OKX.

12.3 In the event of a suspected or confirmed security compromise, the User must immediately revoke the relevant API Key or Authorized AI Agent authorization and notify OKX. OKX may independently suspend access upon detecting anomalous activity.

12.4 OKX shall not be liable for orders submitted as a result of a security compromise of the User’s AI system or credentials, provided OKX acted in good faith in processing such orders.

13. Data and Privacy

13.1 API logs, request metadata, and telemetry generated through the User’s use of the API Services may be collected and retained by OKX for security, compliance, audit, and system integrity purposes, in accordance with OKX’s Privacy Policy.

13.2 Users remain solely responsible for compliance with applicable data protection laws — including GDPR, CCPA, PIPL, and Singapore PDPA as applicable — in connection with any personal data processed by their Authorized AI Agents, including in the context of AI model training, fine-tuning, or inference using data derived from the API Services.

13.3 Users must not use data obtained through the API Services to train or fine-tune any AI model in a manner that incorporates or exposes other users’ personal data or OKX’s proprietary Market Data contrary to Section 9.4.

14. Suspension and Termination

14.1 User Termination. The User may terminate this Agreement at any time by revoking all API Keys and Authorized AI Agent authorizations and providing written notice to OKX. Termination does not affect obligations arising from orders submitted prior to termination.

14.2 OKX Termination or Suspension. OKX may, without prior notice and at its sole discretion, suspend or terminate the User’s access to the API Services if: (a) the User breaches any provision of this Agreement or the OKX ToS; (b) OKX reasonably suspects market manipulation, prohibited conduct, or harm to the Platform or other users; (c) the User no longer meets the eligibility criteria in Section 2; (d) OKX is required to do so by applicable law or a competent authority; or (e) OKX discontinues any portion of the API Services.

14.3 Effect of Termination. Upon termination, all API Key access and Authorized AI Agent authorizations are immediately and automatically revoked. Open orders submitted prior to termination may remain live unless the User or OKX cancels them. OKX bears no responsibility for market exposure remaining at the time of termination.

15.AMENDMENTS

OKX reserves the right to amend this Agreement at any time, consistent with the OKX ToS. Continued use of the API Services following notice of an amendment constitutes acceptance of the amended terms. If the User does not agree to an amendment, they must terminate their use of the API Services in accordance with Section 14.1.

16.GOVERNING LAW AND DISPUTE RESOLUTION

16.1 This Agreement shall be governed by, and construed in accordance with, the laws of the jurisdiction applicable to the User's contracting OKX entity as set out in the Terms of Service.

16.2 Any dispute arising out of or in connection with this Agreement shall be resolved in accordance with the dispute resolution mechanism set out in the OKX ToS, including the arbitration obligation contained therein.

17. MISCELLANEOUS

17.1 Entire Agreement. This Agreement, together with the OKX ToS and any product-specific terms incorporated by reference, constitutes the entire agreement between the parties with respect to the API Services.

17.2 Severability. If any provision of this Agreement is found to be invalid, illegal, or unenforceable, it shall be modified to the minimum extent necessary to make it enforceable, or if not possible, severed, without affecting the remainder of the Agreement.

17.3 No Waiver. No failure or delay by OKX in exercising any right under this Agreement shall constitute a waiver of that right.

17.4 No Partnership or Agency. Nothing in this Agreement creates a partnership, joint venture, agency, or employment relationship between OKX and the User, or between OKX and any Authorized AI Agent or Third-Party AI Provider.

17.5 Language. This Agreement is made in English. In the event of any conflict between the English version and any translation, the English version shall prevail.