Acceptable Use Policy
Effective Date: September 19, 2026
Last Updated: September 22, 2026
Platform Provider: Startum Identity Platform ("Startum", "we", "us", or "our")
1. Overview & Purpose
This Acceptable Use Policy ("AUP") sets forth acceptable standards of conduct for all users, developers, and integrated applications interacting with the Startum OpenID Connect (OIDC) identity provider, Account Portal, Developer Portal, and APIs.
The goal of this policy is to preserve platform integrity, protect user privacy, prevent abuse, and maintain high availability across all services.
2. Prohibited Security & API Misuse
Users and application developers are strictly prohibited from performing or attempting to perform any of the following actions:
- PKCE Bypass & Security Downgrades: Attempting to bypass mandatory Proof Key for Code Exchange (PKCE, RFC 7636) code challenge validation or forging state parameters.
- Token Harvesting & Secret Exposure: Publishing, hardcoding, or exposing client secrets or access tokens in client-side code (SPAs, public GitHub repositories, or native binary distributions).
- Cross-Site Request Forgery (CSRF): Initiating authorization code requests without valid, cryptographically random
stateparameters or embedding Startum consent pages inside unauthorized<iframe>tags (Clickjacking). - Brute Force & Rate Limit Evasion: Automating token requests, credential stuffing, password spraying, or employing IP rotation/proxies to bypass API rate limits.
- Denial of Service (DoS): Launching distributed denial-of-service attacks, resource exhaustion attacks, or payload flooding against token or authorization endpoints.
3. Prohibited Application Conduct & Content
OAuth applications registered on Startum must not:
- Deceptive Identity Representation: Misrepresent their application name, logo, publisher identity, or intended scope usage during user consent flows (Phishing / Brand Impersonation).
- Malicious Software: Distribute malware, ransomware, spyware, keyloggers, or unauthorized trojans.
- Identity Scraping & Bulk Harvesting: Scrape user identity claims (
profile,email) for resale, marketing automation, or mass unsolicited commercial messaging (Spam). - Pairwise Identifier Correlation: Attempt to correlate pairwise subject identifiers (
sub) across different application Client IDs to construct global user tracking profiles.
4. OAuth Client Registration Boundaries
- Valid Redirect URIs: Registered redirect URIs are authorized for the following environments:
- Accurate Application Metadata: Developers must maintain updated contact information, accurate application titles, and working support URLs.
- Unused Client Cleanup: Startum reserves the right to disable or prune OAuth Client IDs that remain inactive for more than 180 consecutive days without authorization traffic.
- Loopback Interfaces: http://localhost:*, http://127.0.0.1:*
- Private Networks & Subnets: Local RFC 1918 private IPv4 subnets (http://192.168.*.*, http://10.*.*.*, http://172.16.*.*–172.31.*.*)
- Homelab & Internal Domains: Multicast DNS or internal domains (e.g., *.local, *.lan, custom homelab ports)
- Mesh VPNs: Private overlay networks and mesh VPN domains (specifically Tailscale MagicDNS *.ts.net)
- Standard non-loopback, public routable Internet domains must strictly enforce TLS (https://). Wildcard subdomains (https://*.example.com) or insecure http:// endpoints on public domains are prohibited.
5. Enforcement & Violation Consequences
Failure to comply with this AUP may result in immediate administrative action:
- Automated Rate Throttling (
HTTP 429): Temporary block of offending IP addresses or API client credentials. - Client Application Suspension: Revocation of Client ID and Client Secret, breaking all active authorization flows for that application.
- Developer Account Termination: Permanent ban of developer accounts associated with malicious activities.
- Legal Referral: Reporting malicious breaches or illegal activities to law enforcement and regulatory authorities.
6. Reporting Violations
If you discover an application or user violating this Acceptable Use Policy, please report it immediately:
Email: [email protected]
Security Disclosure: Security & Vulnerability Disclosure Policy