IMPORTANT NOTICE
These API Usage and Developer Terms ("API Terms") govern access to and use of the Nextkt Partner API, API credentials, webhooks, sandbox, developer tools, documentation and related integration services.
These API Terms apply principally to use of the Partner API, and additionally to any Partner that receives API credentials under another arrangement.
These API Terms are incorporated into the Nextkt Partners Terms and Conditions ("Partner Terms"). The Partner Terms remain the master commercial agreement. These API Terms should be read together with the Partner Terms and the Platform's:
- General Terms and Conditions;
- Privacy Policy;
- Cookies Policy;
- Refund Policy;
- Ticket Sales and Purchase Policy;
- Loyalty Program Terms & Conditions;
- Payment Processing Terms;
- Partners Terms & Conditions;
- Organizer Agreement, where applicable;
- Event-specific terms;
- any Data Processing Agreement;
- any Order Form, Commercial Schedule, Settlement Schedule or signed Partner Agreement;
- Payment Provider terms, including applicable card-network, wallet, bank-transfer and payment-scheme rules.
If there is a conflict between these API Terms and the Partner Terms:
- the Partner Terms prevail on payments, refunds, chargebacks, financial responsibility, indemnity, Partner liability, settlement and commercial risk;
- these API Terms prevail on technical API-use rules, credentials, rate limits, security, integration behavior and developer obligations.
The Partner must not access or use the Partner API unless it agrees to both the Partner Terms and these API Terms.
The API is provided for legitimate integration with the Partner's own approved organization. It is not a public data-extraction service, payment bypass, general-purpose reseller platform or means to access another organization's data.
TABLE OF CONTENTS
- Definitions
- Eligibility and incorporation of Partner Terms
- API access model
- Apps, credentials and organization scope
- Sandbox and live environments
- Authentication and credential handling
- Scope and least privilege
- Authorized origins and redirect URIs
- Permitted use
- Prohibited use
- No cross-tenant access
- Security requirements
- Secret storage and browser restrictions
- Webhooks
- Idempotency and transaction safety
- Rate limits, throttling and abuse controls
- Automated traffic and bots
- API availability
- API changes and deprecation
- Documentation and examples
- Data returned by the API
- Caching and local storage
- Personal Data
- Payment and checkout integrations
- Buyer authentication and sessions
- Inventory integrity and oversell protection
- Error handling and retry behavior
- Logging, monitoring and auditability
- Security incidents
- Vulnerability research and testing
- Malware and harmful code
- Reverse engineering and circumvention
- Competitive misuse and data harvesting
- Resale, sublicensing and service bureaus
- Third-party developers and contractors
- Open-source and client-side code
- Developer representations and warranties
- Monitoring by Nextkt
- Emergency restrictions
- Suspension and revocation
- Fees
- Intellectual property
- Feedback
- Confidentiality
- Indemnity
- Disclaimers
- Limitation of liability
- Termination
- Effect of termination
- Governing law
- Contact
1. DEFINITIONS
"API" or "Partner API" means the Nextkt Partner-facing API, principally available through partners.nextkt.com, together with approved related interfaces.
"API Credential" means any API key, token, secret, client credential, signing secret, webhook secret or other authentication material issued by Nextkt.
"App" means a registered Partner integration associated with an approved organization.
"Developer" means the Partner and any employee, contractor or authorized person developing or operating an integration.
"Documentation" means technical material published by Nextkt, including developer guides, OpenAPI specifications, examples and changelog materials.
"Live Mode" means an approved production environment in which real Buyers, real Transactions and real Tickets may be processed.
"Sandbox" means a test environment or test mode intended for non-production integration activity.
Other capitalized terms have the meanings given in the Partner Terms.
2. ELIGIBILITY AND INCORPORATION OF PARTNER TERMS
API access is available only to approved Partners.
The Partner must maintain an active Nextkt organization in good standing.
The Partner Terms are incorporated into these API Terms.
API access does not reduce or replace the Partner's legal and financial obligations under the Partner Terms.
Nextkt may refuse API access even if the Partner is otherwise approved to sell through Nextkt.
3. API ACCESS MODEL
The Partner API is a Nextkt-operated interface allowing an approved Partner to integrate its own systems with Nextkt.
Nextkt may operate separate public and internal API surfaces.
Access to the Partner API does not imply access to:
- system-administration routes;
- internal staff tools;
- another Partner's organization;
- internal databases;
- non-public services;
- undocumented privileged endpoints.
Any route not expressly made available to the Partner must be treated as unauthorized.
4. APPS, CREDENTIALS AND ORGANIZATION SCOPE
API Credentials are organization-specific and app-specific where applicable.
The Partner must not:
- use one organization's API Credential for another organization;
- share credentials between unrelated companies;
- copy live credentials into test environments;
- transfer credentials to another Partner;
- create hidden sub-tenants or unauthorized resellers using one Partner account.
Nextkt may require separate Apps for materially separate products, domains or business units.
The Partner is responsible for all activity performed using its API Credentials.
5. SANDBOX AND LIVE ENVIRONMENTS
Sandbox is for testing only.
The Partner must not use Sandbox to:
- process real payments;
- mislead Buyers into believing a real purchase occurred;
- issue fake production Tickets;
- test stolen cards;
- perform card testing;
- run fraudulent or abusive transaction simulations against real payment infrastructure.
Live Mode may require review and approval.
Nextkt may require successful testing, security review, verified domains, updated company information or other checks before enabling Live Mode.
6. AUTHENTICATION AND CREDENTIAL HANDLING
The Partner must use only authentication mechanisms documented by Nextkt.
The Partner must not:
- forge authentication headers;
- manipulate organization identifiers;
- replay expired credentials;
- bypass scope checks;
- attempt privilege escalation;
- alter tokens or signatures;
- use credentials obtained from another Partner;
- exploit an authentication error.
The Partner must immediately stop using any credential it knows or reasonably suspects to be compromised.
7. SCOPE AND LEAST PRIVILEGE
The Partner must request and use only the minimum permissions necessary.
Where Nextkt provides scope groups, the Partner must not attempt to access functionality outside approved scopes.
Nextkt may reduce or revoke scopes at any time for security, compliance or risk reasons.
A credential with broad permissions does not authorize misuse.
8. AUTHORIZED ORIGINS AND REDIRECT URIS
The Partner must accurately register authorized browser origins and redirect URIs.
The Partner must not register:
- domains it does not control;
- wildcard origins where prohibited by Nextkt;
- attacker-controlled domains;
- temporary domains that create avoidable security risk;
- redirect URIs designed to capture credentials or payment responses belonging to another party.
The Partner is responsible for securing its registered domains.
Nextkt may reject or remove an origin or redirect URI at any time.
9. PERMITTED USE
The Partner may use the API only to operate an approved integration for legitimate ticketing, box-office, event, inventory, sales, reporting and related workflows supported by Nextkt.
Permitted use includes, where enabled:
- reading Events and inventory;
- displaying approved Event data;
- initiating supported Buyer flows;
- reading sales;
- managing permitted operational functions;
- receiving webhooks;
- integrating reports and internal tools.
Permitted use is always subject to assigned scopes and the Partner Terms.
10. PROHIBITED USE
The Partner must not use the API to:
- commit fraud;
- create fake Transactions;
- test stolen payment credentials;
- launder money;
- create fake Events;
- misrepresent ticket availability;
- bypass fees;
- bypass checkout;
- bypass payment controls;
- bypass inventory controls;
- oversell intentionally;
- access another tenant;
- harvest Personal Data;
- scrape the API at scale for unrelated purposes;
- attack or probe Nextkt infrastructure;
- defeat rate limits;
- distribute malware;
- impersonate Nextkt;
- issue unauthorized Tickets;
- reverse engineer protected internal behavior;
- use the API in violation of law;
- resell API access without written permission;
- create a competing data product from Nextkt-provided data;
- interfere with another Partner;
- exploit a bug instead of reporting it.
11. NO CROSS-TENANT ACCESS
The Partner may access only data belonging to its approved organization and data expressly exposed as public or shared.
The Partner must not manipulate organization identifiers, headers, query parameters, object identifiers or credentials in an attempt to access another tenant.
If the Partner accidentally receives data that appears to belong to another organization, it must:
- stop processing the data;
- not copy or use it;
- notify Nextkt immediately;
- follow Nextkt's remediation instructions.
Unauthorized cross-tenant access is a material breach.
12. SECURITY REQUIREMENTS
The Partner must maintain security appropriate to the sensitivity of the integration.
At minimum, the Partner must:
- use TLS;
- protect secrets at rest;
- restrict production access;
- use least privilege;
- patch critical vulnerabilities promptly;
- maintain secure development practices;
- review dependencies;
- protect administrative accounts;
- segregate test and production;
- monitor suspicious activity;
- maintain incident-response capability.
Nextkt may require additional controls for high-volume or high-risk Partners.
13. SECRET STORAGE AND BROWSER RESTRICTIONS
Live API secrets must not be embedded in:
- public JavaScript;
- browser bundles;
- mobile app binaries where avoidable;
- public repositories;
- downloadable configuration files;
- screenshots;
- support tickets accessible to unauthorized persons;
- client-side storage.
Where Nextkt provides browser-safe public identifiers, those must be used instead of server credentials.
The Partner bears all consequences of secret leakage caused by its implementation.
14. WEBHOOKS
The Partner is responsible for securely receiving and processing webhooks.
Where signing or verification is provided, the Partner must verify webhook authenticity before acting on the message.
The Partner must design webhook processing to tolerate:
- retries;
- duplicate delivery;
- delayed delivery;
- out-of-order delivery;
- temporary failure.
The Partner must not assume a webhook will be delivered exactly once.
The Partner must not expose webhook endpoints that allow arbitrary third parties to trigger privileged actions.
15. IDEMPOTENCY AND TRANSACTION SAFETY
Where Nextkt requires or supports idempotency, the Partner must use idempotency keys correctly.
The Partner must not intentionally replay payment, refund, checkout, reservation or issuance requests to create duplicate results.
The Partner is responsible for preventing duplicate actions caused by its own retry logic.
If the Partner's system causes duplicate Transactions, refunds or Tickets through incorrect use of the API, the resulting financial and Buyer consequences remain the Partner's responsibility.
16. RATE LIMITS, THROTTLING AND ABUSE CONTROLS
Nextkt may apply rate limits by:
- API key;
- App;
- organization;
- IP address;
- route;
- Buyer;
- payment method;
- risk signal.
The Partner must not circumvent limits through:
- key rotation;
- multiple Apps;
- distributed requests;
- proxy networks;
- IP rotation;
- request fragmentation.
Nextkt may throttle or block abusive traffic without prior notice.
Published limits may change where reasonably necessary to protect the Platform.
17. AUTOMATED TRAFFIC AND BOTS
Automation is permitted only where consistent with normal API integration.
The Partner must not use bots or automation to:
- scrape unrelated data;
- reserve inventory to deny access to others;
- manipulate sales;
- simulate fake Buyers;
- inflate activity;
- probe security;
- test cards;
- bypass queueing or inventory protections.
18. API AVAILABILITY
Nextkt will use reasonable efforts to operate the Partner API.
The API may be unavailable because of:
- maintenance;
- security patches;
- Cloudflare or network failures;
- infrastructure incidents;
- payment-provider outages;
- force majeure;
- emergency protective actions.
No uptime, latency or response-time SLA applies unless signed separately.
19. API CHANGES AND DEPRECATION
Nextkt may add, change, replace or remove endpoints, fields, scopes, authentication mechanisms or behavior.
Nextkt will use commercially reasonable efforts to provide notice for material breaking changes where practicable.
Security, fraud, legal, payment-provider or emergency changes may be made immediately.
The Partner is responsible for monitoring developer notices and changelogs.
An undocumented behavior must not be treated as a permanent contract.
20. DOCUMENTATION AND EXAMPLES
Documentation is provided for integration guidance.
Examples are illustrative and may omit production requirements.
The Partner remains responsible for validating:
- error handling;
- security;
- timeouts;
- retries;
- idempotency;
- data validation;
- compliance.
Nextkt is not responsible for code copied from examples and deployed without appropriate review.
21. DATA RETURNED BY THE API
The Partner may use API data only for its legitimate approved integration.
The Partner must not:
- sell API data;
- build unauthorized datasets;
- combine Buyer data for unrelated profiling;
- expose sensitive fields publicly;
- retain data longer than necessary or lawful.
Data may be corrected, deleted, updated or reclassified over time.
22. CACHING AND LOCAL STORAGE
The Partner may cache data only where reasonably necessary for performance or operation.
The Partner must respect any cache headers, data-retention requirements and deletion obligations communicated by Nextkt.
The Partner must not rely on cached inventory, pricing or availability where stale data could cause overselling or Buyer harm.
Transaction-critical information should be refreshed or validated as required by the Documentation.
23. PERSONAL DATA
The Partner must process Personal Data obtained through the API only in accordance with:
- applicable privacy law;
- the Partner Terms;
- Nextkt Privacy Policy;
- any applicable Data Processing Agreement;
- Buyer consent or other lawful basis.
The Partner must not use API access to construct unrelated marketing databases.
The Partner must honor applicable deletion, access, correction and opt-out rights.
24. PAYMENT AND CHECKOUT INTEGRATIONS
The Partner must use only approved payment and checkout flows.
The Partner must not:
- alter payable amounts after authorization without lawful basis;
- bypass required authentication;
- suppress mandatory fees or disclosures;
- intercept payment credentials outside approved flows;
- route payment data through unapproved systems;
- simulate successful payment where payment failed;
- issue a valid Ticket for an unpaid Transaction except where Nextkt explicitly supports an offline/manual workflow.
The Partner is responsible for any payment integration it controls.
25. BUYER AUTHENTICATION AND SESSIONS
Where Buyer authentication is used, the Partner must protect Buyer sessions and tokens.
The Partner must not:
- impersonate Buyers;
- reuse Buyer tokens across customers;
- expose session tokens;
- intentionally weaken authentication;
- bypass login requirements for restricted actions.
26. INVENTORY INTEGRITY AND OVERSELL PROTECTION
The Partner must respect Nextkt inventory, hold, reservation and capacity controls.
The Partner must not:
- create local inventory that conflicts with Nextkt;
- reserve stock indefinitely;
- bypass capacity checks;
- confirm sales after a failed hold;
- issue duplicate access credentials;
- manipulate seat or table allocation outside supported flows.
If the Partner maintains a local display cache, Nextkt remains the authoritative source for final transactional availability.
27. ERROR HANDLING AND RETRY BEHAVIOR
The Partner must correctly handle HTTP errors, validation errors, payment declines, timeouts and conflict responses.
The Partner must not treat a timeout as proof that a Transaction failed.
Before retrying a transaction-sensitive operation, the Partner must follow Nextkt's documented status-check or idempotency flow where available.
The Partner is responsible for duplicate actions caused by unsafe retry logic.
28. LOGGING, MONITORING AND AUDITABILITY
The Partner must maintain logs sufficient to investigate integration issues without storing secrets unnecessarily.
Appropriate logs may include:
- request timestamps;
- correlation IDs;
- route names;
- response codes;
- internal transaction references;
- webhook delivery IDs.
The Partner should not log full payment credentials, raw secrets or unnecessary Personal Data.
The Partner must preserve relevant logs during an incident or dispute.
29. SECURITY INCIDENTS
The Partner must notify Nextkt without undue delay and where possible within 24 hours of becoming aware of:
- leaked API Credentials;
- unauthorized API use;
- cross-tenant exposure;
- malware affecting the integration;
- compromised webhook secrets;
- Buyer-data exposure;
- payment-data exposure;
- material attack against Nextkt through the Partner's systems.
The Partner must cooperate fully with containment and investigation.
30. VULNERABILITY RESEARCH AND TESTING
The Partner must not conduct penetration testing, vulnerability scanning, fuzzing, load testing, denial-of-service testing or other intrusive security testing against production Nextkt systems without prior written authorization.
Good-faith security reports may be submitted to Nextkt through a designated security channel where available.
The Partner must not exploit a vulnerability beyond what is reasonably necessary to demonstrate it.
31. MALWARE AND HARMFUL CODE
The Partner must not use the API or related systems to distribute malware, ransomware, spyware, credential stealers, malicious redirects or harmful code.
The Partner must take reasonable measures to prevent compromised Partner systems from attacking Nextkt.
32. REVERSE ENGINEERING AND CIRCUMVENTION
Except where mandatory law expressly permits otherwise, the Partner must not:
- reverse engineer Nextkt software;
- derive source code;
- circumvent authentication;
- bypass security controls;
- emulate privileged internal services;
- interfere with routing or tenancy controls.
Observation of documented API behavior for normal integration is permitted.
33. COMPETITIVE MISUSE AND DATA HARVESTING
The Partner may not use the API primarily to:
- benchmark Nextkt for publication without consent;
- extract the Nextkt event catalog for an unrelated competing database;
- harvest Buyers;
- copy Nextkt proprietary workflows;
- train a competing commercial model on non-public Nextkt data;
- recreate a substantial part of the Nextkt platform from protected non-public information.
Nothing in this section prevents the Partner from using its own Partner Data for lawful business purposes.
34. RESALE, SUBLICENSING AND SERVICE BUREAUS
The Partner must not resell, sublicense, rent or provide raw API access to third parties without Nextkt's written approval.
The Partner may use contractors to build its own integration, but the Partner remains responsible for them.
If Nextkt approves a reseller or platform arrangement, additional terms may apply.
35. THIRD-PARTY DEVELOPERS AND CONTRACTORS
The Partner may allow its developers and contractors to access API Credentials only where necessary.
The Partner must:
- bind them to confidentiality;
- restrict access;
- revoke access when no longer needed;
- remain responsible for their acts and omissions.
36. OPEN-SOURCE AND CLIENT-SIDE CODE
The Partner must ensure that its use of open-source software does not require disclosure or licensing of Nextkt proprietary materials.
The Partner must not publish Nextkt secrets, confidential schemas or non-public documentation in public repositories.
37. DEVELOPER REPRESENTATIONS AND WARRANTIES
The Partner represents and warrants that:
- its integration is lawful;
- it has authority to access its organization;
- it will maintain appropriate security;
- it will not use the API for fraud;
- it will not access another tenant;
- it will comply with the Partner Terms;
- it will keep credentials secure;
- it will promptly report incidents;
- it will not intentionally interfere with Nextkt.
38. MONITORING BY NEXTKT
Nextkt may monitor API usage for:
- performance;
- security;
- fraud;
- abuse;
- rate-limit enforcement;
- debugging;
- compliance;
- billing;
- product improvement.
Nextkt may retain API logs as permitted by law.
Nextkt is not required to disclose internal security rules, fraud thresholds or monitoring logic.
39. EMERGENCY RESTRICTIONS
Nextkt may immediately:
- rotate or revoke credentials;
- block an IP;
- disable an App;
- reduce scopes;
- throttle traffic;
- disable a route;
- suspend an organization;
- restrict checkout;
- stop webhook delivery;
where necessary to protect Nextkt, Buyers, Payment Providers or other Partners.
Emergency action may occur without prior notice.
40. SUSPENSION AND REVOCATION
Nextkt may suspend or revoke API access for:
- breach of these API Terms;
- breach of Partner Terms;
- non-payment;
- excessive errors;
- abusive traffic;
- security weakness;
- credential compromise;
- fraud;
- fake Events;
- Chargeback risk;
- unlawful activity;
- failure to cooperate with investigation;
- instruction from a Payment Provider or authority.
Revocation may be immediate.
41. FEES
API or developer access fees, if any, are as agreed in writing, shown in Admin or stated in an applicable commercial schedule.
Usage fees may be introduced or changed in accordance with the Partner Terms and applicable commercial agreement.
42. INTELLECTUAL PROPERTY
Nextkt owns all rights in the API, Documentation, schemas, software, SDKs provided by Nextkt, developer tools and related proprietary technology.
The Partner receives a limited, revocable, non-exclusive, non-transferable right to use the API solely for its approved integration.
No ownership rights are transferred.
43. FEEDBACK
If the Partner provides suggestions or feedback, Nextkt may use them without restriction or payment, provided Nextkt does not disclose the Partner's confidential information in doing so.
44. CONFIDENTIALITY
Non-public API details, credentials, pricing, security information, unreleased features and private developer communications are confidential.
The Partner must protect them using reasonable care.
45. INDEMNITY
The Partner's indemnity obligations under the Partner Terms apply fully to API use.
Without limiting them, the Partner will indemnify Nextkt for claims, losses and costs arising from:
- the Partner Application;
- API misuse;
- credential compromise caused by the Partner;
- cross-tenant access by the Partner;
- unsafe retry logic;
- duplicate Transactions caused by the Partner;
- privacy violations;
- security incidents;
- unlawful data use;
- malicious or prohibited activity by the Partner or its developers.
46. DISCLAIMERS
The API is provided on an "as is" and "as available" basis to the maximum extent permitted by law.
Nextkt does not warrant:
- uninterrupted availability;
- error-free operation;
- permanent availability of any endpoint;
- compatibility with every framework;
- that every bug will be fixed;
- that the Partner's implementation is secure or correct.
47. LIMITATION OF LIABILITY
The limitation-of-liability provisions in the Partner Terms apply to these API Terms.
To the maximum extent permitted by law, Nextkt is not liable for losses resulting from:
- the Partner's code;
- incorrect API use;
- stale caches;
- leaked credentials;
- unsafe retries;
- Partner downtime;
- third-party libraries;
- unauthorized browser exposure of secrets;
- unsupported integrations.
48. TERMINATION
These API Terms terminate when:
- the Partner Terms terminate;
- API access is permanently revoked; or
- Nextkt discontinues the Partner's API access.
Nextkt may terminate API access separately while allowing the Partner to continue using other Nextkt services.
49. EFFECT OF TERMINATION
After API access ends, the Partner must:
- stop API calls;
- stop representing itself as an active Nextkt API Partner;
- delete or securely destroy live API Credentials;
- disable automated jobs that call the API;
- cease using non-public API data except where legally required or expressly permitted.
Existing Partner financial obligations remain unaffected.
50. GOVERNING LAW
These API Terms are governed by the laws of Singapore.
The dispute provisions in the Partner Terms apply.
51. CONTACT
Kisum Pte. Ltd. / Nextkt
Support: support@nextkt.com
Partner API: https://partners.nextkt.com
Developer Documentation: https://developers.nextkt.com
END OF DOCUMENT
Questions? Visit the Help Center or contact us.