Terms of Service
Last updated: October 1, 2026
These terms cover three products operated by MNFST, Inc. ("Manifest", "we", "us"). Sections 1 to 11 apply to all three. Part A adds the terms of Manifest, Part B adds the terms of the Manifest LLM Gateway, and Part C adds the terms of Manifest API Bot.
- Manifest is the API resilience layer for your apps: it tracks their API requests and fixes failed ones in real time. It runs at dashboard.manifest.build. Sections 1 to 11 and Part A apply.
- Manifest LLM Gateway routes your agents' LLM requests to providers. It runs in the cloud at app.manifest.build or on your own servers. Sections 1 to 11 and Part B apply.
- Manifest API Bot is a GitHub App that opens a pull request when an API your code calls changes. Sections 1 to 11 and Part C apply.
1. Acceptance of terms
By accessing or using Manifest, the Manifest LLM Gateway or Manifest API Bot (each a "Service"), you agree to be bound by these Terms of Service. If you do not agree, do not use the Services.
2. Accounts
Each Service has its own account. You are responsible for keeping your account credentials and keys secure, including Manifest project keys and Gateway agent keys. You must not share them with third parties. Manifest API Bot has no Manifest account: it works through your GitHub account.
3. Acceptable use
You agree not to:
- Use the Services for any unlawful purpose or in violation of any applicable laws
- Attempt to gain unauthorized access to the Services or their systems
- Interfere with or disrupt the integrity or performance of the Services
- Use the Services to provide a competing service or resell access without written permission
- Reverse engineer the Services, except the open source code of the Gateway, which is freely available
4. Data you send us
Your requests can contain personal data about your own users. You are responsible for having the right to send that data to us. Our handling of data is described in the Privacy Policy.
5. Third-party services
Your requests go to the APIs and LLM providers you choose. You are responsible for complying with their terms of service and usage policies. We are not responsible for charges they bill you.
6. Service availability
We strive to maintain high availability but do not guarantee uninterrupted service. The Services are provided "as is" without warranties of any kind, whether express or implied. Enterprise customers may negotiate a separate Service Level Agreement (SLA) that supersedes this section.
7. Limitation of liability
To the maximum extent permitted by law, Manifest shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, or business opportunities arising from your use of the Services.
Manifest's total aggregate liability for any claim arising from or related to the Services shall not exceed the fees paid by you for the month in which the claim arose.
8. Termination
You may stop using a Service and delete your account at any time. Sections A6, B6 and C5 describe how each Service deletes your data. We may suspend or terminate your access to a Service if you violate these terms.
9. Changes to terms
We may update these terms from time to time. Changes will be posted on this page with an updated revision date. For material changes affecting pricing or plan features, we will notify registered users by email at least 30 days before the changes take effect. Continued use of the Services after changes constitutes acceptance of the new terms.
10. Governing law
These terms are governed by the laws of the State of California, United States, without regard to conflict of law provisions. Any disputes shall be resolved in the courts of Alameda County, California.
11. Contact
For questions about these terms, email us at bruno@manifest.build.
Part A. Manifest
A1. How Manifest works
The Manifest SDK runs in your app. It records every API request your app sends. When an API answers with a 4xx status other than 401, 402, 403 or 429, the SDK sends the failed request to Manifest. When Manifest knows a patch for the error, it returns a corrected request, and your app retries it with its own credentials. Manifest does not use your API credentials.
A2. What the SDK sends
When your app starts, the SDK sends the name and version of the SDK and of your language runtime. For every request, it sends the method, the URL without its query string, the status code, the response time and the date, with no headers and no body. For each failed request it sends to Manifest, it also sends the headers, the JSON or form body, and the error status and body. After a retry, it sends the retry's status code, and the retry's error body when the retry fails. It masks credential values in headers and query strings, removes user names and passwords from URLs, and holds back top-level body fields with credential names. It does not remove personal data inside request bodies. Once installed, the SDK covers the requests your app makes through the HTTP clients it supports and that you connect to it.
The URL path is sent as your app wrote it, so a credential
inside a URL path, such as a webhook token, is also sent. The
Manifest plugin for Hermes reports calls to MCP tools: for a
failed tool call, the tool's arguments and its error, and the raw
error text when a retry raises one; for other tool calls, only
the server host, tool name, outcome and duration. The SDK and the
plugin send this data whenever they have a project key, except
for calls you exclude with MNFST_ALLOWLIST or
MNFST_DENYLIST in recent versions of the SDKs. To
stop all reporting, remove the key from your app. Manifest stores
nothing sent with a key that was rotated in the dashboard.
A3. Patches and patch proposals
When no patch covers an error, our agent may study it and suggest a patch proposal. A patch proposal serves only after a person at Manifest approves it. A patch describes an error and its fix. It does not contain your request body. A patch learned from one customer's error can serve other customers who hit the same error.
Manifest provides patches "as is". You remain responsible for your app and for the requests it retries. You can turn Live self-healing off for a project at any time. Manifest then keeps recording your requests and stops returning patches.
A4. Plans
Manifest is available on the Starter plan, which is free, and on the Enterprise plan, governed by a separate agreement. Plans are described in the pricing section.
- The Starter plan is not a trial. It needs no payment details and does not convert to a paid plan.
- We may change or limit the Starter plan at any time.
A5. Early access
Manifest is in early access. Features, SDKs and limits may change as the product evolves.
A6. Deleting your data
Deleting a project deletes its keys and all its requests. Deleting your account deletes your user, and your organization and its projects when you are its only member. Patches and the error records they fix are shared and remain. An error record can keep the value your request sent in the field the API rejected. Our agent's notes on an error, which can contain a copy of a failed request, also remain.
Part B. Manifest LLM Gateway
B1. Editions
- Open source (self-hosted): Released under the MIT License. You may use, modify, and distribute the code freely. No Manifest account required: you create a local admin account on your own server. These terms do not apply to the open source version, except section B7, which applies whenever a deployment enables Autofix, and except where a separate commercial agreement is in place.
- Cloud: Hosted at app.manifest.build with dashboard, routing, and account management. These terms apply to the cloud version.
- Self-hosted with license: Self-hosted deployments with additional features, support, or SLAs are governed by a separate agreement negotiated between the parties. These terms apply to the extent not superseded by such agreement.
B2. Plans and billing
The Gateway cloud is available on the Free, Pro and Enterprise plans. Free includes 10,000 routed requests per calendar month. Pro removes that limit. Enterprise is governed by a separate agreement. Plan features and prices are shown in the Gateway dashboard.
- The Free plan is not a trial. It does not automatically convert to a paid plan. You will never be charged unless you voluntarily upgrade.
- Paid subscriptions are billed monthly and renew automatically at the end of each billing cycle. Payment is processed through Stripe.
- If payment fails, access to paid features may be restricted until payment is resolved. Retry and cancellation follow Stripe's standard procedures.
- You may cancel your subscription at any time. Cancellation takes effect at the end of the current billing cycle. No refunds are issued for partial months.
- When a Free account reaches its monthly limit, requests are blocked until the next calendar month or until you upgrade.
B3. Price changes
We may change plan pricing or limits. For existing paying customers, we will notify you by email at least 30 days before any price increase or material reduction in plan features takes effect. If you do not agree with the change, you may cancel your subscription before the new pricing applies.
We may modify or discontinue the Free plan at any time.
B4. Provider keys and subscriptions
You connect your own API keys, subscriptions or local models. The Gateway routes requests to these providers on your behalf. You are responsible for complying with each provider's terms, including the terms of any subscription you connect. Manifest is not responsible for charges incurred with third-party providers.
B5. Request recording
In the cloud, new agents record full request and response bodies by default to power the request logs in your dashboard. You can turn recording off for each agent. Recordings are kept 7 days on the Free plan and 365 days on the Pro plan. If Pro ends, recordings older than 7 days are deleted. Request metadata (model, tokens, cost, timestamps) powers your dashboard for as long as your account exists.
B6. Deleting your account
To delete a Gateway cloud account, email bruno@manifest.build. We then delete your account data. The open source version remains available under the MIT License regardless of account status.
B7. Autofix
The Gateway uses Manifest to fix failed requests. When Autofix is on for an agent and a request fails with a repairable error, the Gateway sends the failed request, including its message content, and the provider's error response to Manifest. Provider credentials (API keys, OAuth tokens) are not sent. Manifest may return a corrected request that the Gateway retries once. Part A applies to the data Manifest receives.
In the cloud, Autofix is on by default for each agent. On self-hosted deployments, Autofix stays off until you turn it on for an agent. You accept it when you create an agent with Autofix on or turn it on later. The deployment then identifies itself with an anonymous install identifier and a random workspace identifier. You can turn Autofix off per agent
from the dashboard, or disable it globally by setting the
AUTOFIX_GLOBAL_ENABLED environment variable to
false.
B8. Provider credits
From time to time we offer promotional credits toward provider usage in the Gateway, for example in exchange for taking part in a user research call. The amount, provider, and timing of each offer are stated in the offer. These terms apply to any such credit.
- Eligibility: the credit is granted only if you complete a scheduled research call and genuinely take part in it. The call must serve its purpose: a good-faith research conversation where you share real feedback about your use of the Gateway and agent reliability. Booking a call, not showing up, joining without engaging, or refusing to answer does not qualify. We decide in good faith whether a call met this bar.
- Booking: booking a call does not guarantee it will take place. We may decline, reschedule, or cancel any booking at our discretion. If a call does not happen, no credit is owed and you owe us nothing.
- Feedback: by taking part, you agree we may take notes during the call and use your feedback, in anonymized form, to improve our products.
- What it is: the credit is an allowance toward provider usage inside the Gateway, made available as the provider named in the offer. It is not cash, has no cash value, and cannot be transferred, resold, or redeemed for money.
- How it is measured: the credit is metered at the provider's own published per-model rates. We do not add any margin; the amounts reflect the provider's prices as billed.
- Where it works: the credit can be used only within the Gateway, through the provider named in the offer. It cannot be moved to another provider, key, account, or workspace.
- When we provide it: we add the credit to your workspace after the call, within the window stated in the offer. We do not guarantee same-day activation.
- How long it lasts: once provisioned, the credit is valid for the period stated in the offer. Any amount not used within that period expires and is forfeited.
- Limits: one credit per person, identified by email or account. It cannot be combined with other offers, stacked, or reissued.
- Fair use: we may withhold or revoke the credit for abuse, including missed or fake calls, automated consumption, resale, or attempts to claim more than one credit.
- Third-party terms: provider usage remains subject to that provider's applicable terms. The credit is delivered through a Manifest-managed key and reflects usage we cover on your behalf up to the stated amount.
- Changes: this is a limited program. We may change, pause, or end it at any time, and may cap the number of participants.
Part C. Manifest API Bot
C1. How API Bot works
You install Manifest API Bot on the GitHub repositories you choose. API Bot reads their code to find the APIs it calls and checks those APIs every day. When a change to an API affects your code, API Bot pushes a branch and opens a pull request with a proposed fix. It never pushes to your default branch and never merges a pull request. It never installs or runs your code.
C2. Fixes written with AI
API Bot writes its fixes with an AI model, Claude by Anthropic, and people at Manifest can review them. A fix can be wrong or incomplete. Review every pull request before you merge it. You remain responsible for the code you merge. To report a wrong or unwanted fix, comment on its pull request. Our team reads those comments.
C3. Your code
By installing API Bot, you allow us to access and copy the code of the repositories you selected, only to provide API Bot. You must have the right to give us that access. You keep all rights to your code and to the fixes you merge.
C4. Early access and pricing
API Bot is in early access and free for early adopters. Its features and limits may change as the product evolves, and we may pause or stop the service. If API Bot becomes paid, we will announce it on manifest.build/api-bot at least 30 days before, and by email when we have your address. A paid plan never applies to work done before it starts. Free use during early access does not commit us to keep it free.
C5. Deleting your data
We keep a copy of each repository while API Bot is installed on it. When you uninstall API Bot or remove a repository from it, we delete our copy of that repository. The pull requests API Bot opened stay in your repositories until you close or delete them.
C6. Fair use
API Bot analyzes repositories within the resources we give each installation. We may limit, delay or decline the analysis of a repository because of its size or the resources it needs, and offer it under a paid plan instead. We may also decline repositories that are copies of projects you did not write.