VibeCode Terms of Service
These Terms of Service govern how you use VibeCode: the app, the site, Credit and the Wallet, the Free, Pro, and Max Plans, and the public API. Read them in full before you create an Account, buy anything, or use the Service.
Last updated:
1. Scope and acceptance
1.1 These Terms of Service ("Terms") are an agreement between you and VibeCode, located at Jakarta (the "Operator").
1.2 These Terms apply to the Service, meaning the App, the Site, Credit, the Wallet, the Plans, and the API, as defined in Article 2.
1.3 By creating an Account, signing in, using the Service, buying Credit or a Plan, or creating an API Key, you confirm that you have read and agree to these Terms. If you do not agree, do not use the Service.
1.4 The Privacy Policy and the Refund Policy are separate documents that apply together with these Terms. The Privacy Policy governs the processing of personal data, the Refund Policy governs refunds, and these Terms govern everything else.
2. Definitions
2.1 The following terms are used in these Terms:
- You or User: every person who creates an Account or uses the Service.
- Operator: the party named in clause 1.1.
- Service: the App, the Site, Credit, the Wallet, the Plans, and the API.
- App: the VibeCode app for computers (macOS and Windows) and the VS Code extension.
- Site: the VibeCode website at vibecodeagent.my.id, including web Chat and the payment page.
- API: the public VibeCode programming interface, compatible with the OpenAI format, at
https://api.vibecodeagent.my.id/v1. - API Key: a secret code starting with
sk-vc-that is used to access the API. - Account: your VibeCode account, which is created and authenticated through Firebase Authentication (a third-party service).
- Credit: the unit of balance and usage in the Service. Paid Model usage is billed in Credit. Credit is valid for use within VibeCode only.
- Wallet: the Credit balance of your Account, which grows through Top-Ups and shrinks through usage.
- Top-Up: adding balance to the Wallet by a QRIS payment.
- Plan: a service tier, Free, Pro, or Max. Free costs nothing; Pro and Max are paid.
- Plan Credit: the usage allowance in Credit that comes with the Pro and Max Plans, which is limited per time window and is not a balance.
- Model: an artificial intelligence model offered through the Service.
- Third-Party Model Provider: another party that runs a Model or provides the infrastructure to run it.
- Content: messages, files, code, commands, images, and other data that you send to the Service or receive from it, including Model output.
- Request: a single call to a Model through the Service.
- Token: the unit of text that is used to measure Model usage.
3. Account
3.1 To use the Models provided by VibeCode, web Chat, Credit, Plans, and the API, you need an Account. The Account is created and authenticated through Firebase Authentication (a third-party service), with an email address and password or with a Google account.
3.2 The information you give must be accurate, and you must keep it accurate, especially an email address where you can be reached.
3.3 One person may hold only one Account. An Account is personal and may not be shared or transferred to anyone else. You may not create additional Accounts to avoid usage limits, to obtain free usage again and again, or to avoid a suspension. A team that uses the Service creates one Account for each member.
3.4 You are responsible for keeping confidential your password, access to the linked Google account, devices you leave signed in (the "Stay signed in on this device" option), and your API Keys. You are responsible for all activity through your Account, including Credit usage and API Key usage. If you suspect that your Account or an API Key is being used without permission, revoke the access immediately and contact the Operator.
3.5 Minimum age: the Service is only for users who are at least 18 years old. By creating an Account, you confirm that you are at least 18 years old. There is no exception with the consent of a parent or guardian. The Operator does not check the age of users, but may close an Account that is known to belong to a user below that age.
3.6 You can delete your Account in the App (Settings, the Account tab, "Delete my account"). Deletion is permanent and cannot be undone: your sign-in account and your Account profile in Firebase are deleted, while conversations stored on your computer remain. Deletion does not automatically delete the Account records on the Operator's server (among other things the balance, Plan time, transactions, web Chat history, and API Keys), and after the Account is deleted you can no longer sign in to use the remaining balance and Plan. Those records remain until you ask for them to be deleted through vibetokenapi1@gmail.com; the Site does not yet have a delete-account button. An API Key that has not been revoked stays valid after the Account is deleted and is still billed to the Wallet, so revoke your API Keys before you delete the Account. The remaining balance and Plan are not refunded automatically when the Account is deleted, so ask for a refund first under the Refund Policy. Deletion of server data is governed by the Privacy Policy.
4. Credit and the Wallet
4.1 Credit is the unit of balance and usage in the Service. Paid Model usage is billed in Credit. Credit is valid for use within VibeCode only.
4.2 The Wallet grows through Top-Ups, which are paid by QRIS. You can choose any Top-Up amount from Rp5,000 to Rp100,000 in steps of Rp1,000 (the "base amount").
4.3 The total you pay is the base amount, plus a service and payment admin fee of 13%. The service and payment admin fee is not added to your balance: the Wallet grows by the base amount. The Operator does not issue tax invoices, and receipts issued by the Service are not tax invoices.
4.4 A QR code is valid for 10 minutes. Pay exactly the total shown on the QR code. A payment of a different amount may fail to be matched automatically. Creating a new QR code cancels your earlier QR code that has not been paid.
4.5 A payment for a QR code that has expired or been cancelled is still recognized if it is detected within 15 minutes afterwards. A payment that cannot be matched automatically, or that is detected later, is handled under the Refund Policy. The Operator does not guarantee how long it takes for a payment to be detected.
4.6 The Wallet has no expiry date.
4.7 Credit is a balance for using the Service. The Wallet cannot be transferred to another Account, sold, exchanged for money, or withdrawn in cash, except for a refund under the Refund Policy.
4.8 The price per Token of each Model is shown in the App and, for the API, in the model list. Input and output usage are each counted in Tokens and rounded up to the smallest unit of Credit. The prices shown already account for the minimum per-Token rate that applies. The Operator may change prices at any time; new prices apply to Requests processed afterwards.
4.9 In the App and web Chat, paid Model usage is billed first against Plan Credit (if you have an active paid Plan and its limit has not been reached), and the rest against the Wallet. API usage is billed against the Wallet only.
4.10 In the App and web Chat, the final cost of a Request may differ from its initial estimate, so the Wallet balance may temporarily fall below zero; the shortfall is offset against your next Top-Up. API usage never makes the Wallet balance negative (clause 6.8).
5. Subscription Plans
5.1 The Service offers three Plans: Free, Pro, and Max. Free costs nothing. Pro and Max are sold at the price per 30 days and with the Plan Credit shown on the Site and in the App; that price does not include the 13% service and payment admin fee. Purchases are paid by QRIS, and clauses 4.3 to 4.5 also apply to Plan purchases.
5.2 Pro and Max are active for 30 days from when their payment is confirmed and are not renewed automatically; to extend, you must buy again. A purchase made while a Plan is still active adds time at the end of the current active period. A Plan of a lower tier cannot be bought while a Plan of a higher tier is still active. If you buy a Plan of a higher tier (for example from Pro to Max) while the old Plan is still active, the remaining time of the old Plan also becomes the higher tier and the active period grows by the full length, at the full price with no discount for the remaining time of the old Plan.
5.3 Plan Credit is a usage limit, not a balance. Plan Credit is limited per five-hour window and per weekly window, is used first, and expires each time its time window changes; unused amounts do not carry over to the next window. When either limit is reached, usage is taken from the Wallet. Plan Credit cannot be accumulated, transferred, withdrawn, or cashed out.
5.4 Plan Credit applies only to usage through the App and web Chat, not through the API.
5.5 After a Pro or Max Plan ends, the Account returns to the Free Plan. The Wallet balance is not affected.
5.6 Use of Models marked as free is limited in the number of Requests per day and per week, and the limit depends on your Plan (Free, Pro, or Max). Free Models do not reduce Credit, but they still count toward that limit. The Operator may change those limits.
5.7 Refunds for Plans are governed by the Refund Policy. The Operator may change the price, Plan Credit, or features of a Plan. A change to Plan Credit or features takes effect at once, also for a Plan that is already active (the Plan Credit limit is read directly on every Request); a change of price does not alter a payment that has already been made. Changes are announced through a banner on the Site and in the App.
6. Public API
6.1 The API is compatible with the OpenAI format and is available at https://api.vibecodeagent.my.id/v1 through three routes: POST /v1/chat/completions, GET /v1/models, and GET /v1/models/{id}. Other features, such as the Responses API, embeddings, and image and audio generation, are not available.
6.2 To create an API Key, your Account must have completed at least one QRIS payment that has settled, whether a Top-Up or a Plan purchase. Manual top-ups made by the Operator do not count.
6.3 API Keys start with sk-vc-. A key is shown only once, right after it is created. The Operator does not store the full key; it stores, among other things, a fingerprint (hash) of the key, the key name, and its last four characters, so a lost key cannot be viewed again: revoke it and create a new one. One Account can hold at most 10 active API Keys and create at most 30 API Keys per day (the day according to WIB, which is UTC+7).
6.4 You are responsible for all Requests that use your API Key, and all of their cost is billed to your Wallet until that key is revoked. Keep your key secret. The API accepts requests from any browser (open CORS), so a key embedded in publicly readable code can be used by anyone to drain your balance. Revoke a leaked key immediately through the panel on the API page; revocation takes effect at once.
6.5 You may not use, outside that App and web Chat, the routes and tokens that the VibeCode App and web Chat use for your Account. Programmatic access to the Models from outside the App and web Chat is allowed only through the API with an API Key.
6.6 The default limit is 20 Requests per minute per Account (a sliding one-minute window), counted across all of your API Keys. The Operator may change this limit; the figure that applies to your Account is shown in the key panel and in response headers. A Request over the limit is rejected with status 429 (rate_limit_exceeded).
6.7 Model capacity is shared by the App and all other users. When capacity is full, a Request may wait in a queue or be rejected with status 429 (capacity_exhausted); follow the Retry-After header. The Operator does not guarantee the availability, speed, or response time of the API.
6.8 How the API is billed:
- API usage is billed per Token at the Model price in the API model list (Credit per 1 million Tokens) at the time the Request is processed, and against the Wallet only. Plan Credit and the daily, weekly, and five-hour limits of the App do not apply to the API.
- Before the Model runs, the Service reserves an estimated cost from the Wallet: input Tokens are estimated from the size of the Request (about 4 bytes per Token), plus the output limit. When the Request finishes, the difference is returned. If the balance is not enough for that estimate, the Request is rejected (402,
insufficient_balance) before the Model runs and is not billed. - The values of
max_tokensandmax_completion_tokens, if you set them, must be integers of at least 1; if both are present, the larger one is used. If you do not set them, the Service sets an output limit equal to what your balance can pay, at most 32,768 Tokens or the Model's context window, whichever is smaller, so the answer may end withfinish_reason"length". - The Wallet balance never becomes negative through the API. If the actual cost exceeds the estimate and the remaining balance cannot cover it, you are billed the balance that is available and the excess is not billed.
- If the Token count from the Model does not arrive (for example, the stream from the Model is cut off), the Service bills input Tokens estimated from the size of the Request and output Tokens estimated from the text already sent to you (about 4 bytes per Token), never more than the amount already reserved, and marks it "estimated" in the usage log.
- If your connection drops after the Request has been forwarded to the Model, the Model still finishes its answer on the Service side and all of its output is billed; if it drops while the Request is still waiting in the queue, the Request is cancelled and is not billed.
- Not billed: Requests rejected before the Model runs (for example an invalid key, a blocked account, an exceeded rate limit, or an insufficient balance), and failures on the Model side before any answer was produced.
- The Service adds one short identity sentence to your Request so that the Model knows its own name; those extra Tokens are billed as input Tokens.
- In certain circumstances (for example, the server restarts while a Request is running), the reserved balance may be held. Contact the Operator (Article 16) and quote the
x-request-idheader from the response. - Usage that has already run is not refunded, unless it is proven to have been billed in error. Objections to a bill are sent to vibetokenapi1@gmail.com no later than 14 days after the date of usage, quoting the
x-request-idheader. Per-Request logs are kept only for a limited period and daily summaries for longer (see the Privacy Policy), so a late objection may not be possible to check.
6.9 Only Models marked as available in the API can be used through the API. Not every Model in the App is available in the API, and free Models are not offered through the API. The list of Models, their ids, prices, and capabilities may change, and Models may be added, replaced, or removed at any time; there is no guarantee that a particular Model will remain available. Capabilities such as function calling and response_format depend on the Model and are not guaranteed.
6.10 You are responsible for any third-party tool or software that you connect to the API, including the number of Requests it makes and the cost it causes. The Operator does not guarantee that the API works with any particular tool.
6.11 The Operator records one row for every API Request that passes the API Key check and the rate limit (among other things the time, Request id, API Key id, Model, status, Token counts, and cost), without message content and without the API Key itself, for billing, security, and support. The retention period and details are in the Privacy Policy. You can view your usage summary and log on the Credit page.
6.12 The Operator may restrict, suspend, or discontinue the API, wholly or in part, under Article 9.
7. Content, Third-Party Model Providers, and Model output
7.1 Your Content remains yours. You are responsible for the Content you send, and you confirm that you have the right to send it and that it does not violate the law or the rights of others.
7.2 To process a Request to a Model provided by VibeCode, the substance of the Content you send (messages, files or code that the agent reads, and images) is forwarded through the VibeCode server to a Third-Party Model Provider so that your Request can be answered. That provider processes it and may keep it under its own policies on the data it receives. The Operator itself does not use your Content to train models. Do not send Content that you are not allowed to share with third parties, including passwords, secret keys, and other people's personal data without a valid basis. Details on data processing and storage, including web Chat history, are in the Privacy Policy.
7.3 Model output is generated automatically and may be wrong, incomplete, outdated, or unsafe. Check the output before you use it, especially code, commands, and advice for important decisions. Model output is not legal, medical, financial, or other professional advice.
7.4 The agent in the App can read and write files and run commands on your computer at your request. The App asks for your approval according to the permission mode you choose; in certain modes, for example Auto and Bypass, commands and edits run without per-action approval. You are responsible for the mode you choose, the project you run it in, and the results. The safety limits in the App are not a sandbox and do not guarantee that every unwanted action is prevented, so keep backups of your data and use version control.
7.5 MCP servers, skills, and other tools that you install or connect to the App yourself run at your own responsibility. The Operator does not guarantee their safety or content.
7.6 If you use your own model key or endpoint in the App (for example a key from another model provider, or a local or custom endpoint), that use is governed by that provider's terms, you pay it directly, and it does not use Plan Credit or the Wallet. Content is sent directly to the address you set.
8. Prohibited conduct and abuse
8.1 You may not, and may not help others to:
- use the Service for a purpose that violates applicable law or the rights of others, including creating, storing, or distributing unlawful Content;
- use, outside that App and web Chat, the routes and tokens that the VibeCode App and web Chat use for your Account, including through scripts, proxies, or automated tools; programmatic access to the Models is allowed only through the API with an API Key;
- circumvent, evade, or aggressively test rate limits, queueing, billing, usage limits, or other restrictions, including by creating many Accounts or many API Keys to multiply a limit;
- send spam or unreasonable bulk, repeated, or automated Requests, or load the Service until it disturbs other users;
- try to break through security, scan for vulnerabilities, or gain unauthorized access to systems, Accounts, API Keys, or data that belong to others;
- share, sell, or publish an API Key or Account credentials, or embed them in publicly readable code such as public frontend code, distributed applications, or public repositories;
- resell API Keys, Credit, or raw access to the Models to third parties without the written permission of the Operator (building an application or workflow of your own that calls the API to serve your own users remains allowed);
- give false information, impersonate another party, or manipulate payments or balances;
- reverse engineer, decompile, or modify the Service, except as permitted by applicable law;
- send Requests that violate the usage policy of a Third-Party Model Provider. These Terms do not pass on any additional policy from that provider, but the Operator may refuse or limit Requests that violate it.
8.2 The Operator may act on violations under Article 9.
9. Suspension, restriction, and termination
9.1 If a violation of these Terms, abuse, a security risk, or a legal obligation is suspected, the Operator may, at any time:
- revoke one or all of your API Keys;
- block API access for your Account (API Keys remain on record, but Requests are rejected and creating new keys is refused, until the block is lifted);
- restrict Service features for your Account; or
- suspend or deactivate your Account.
9.2 Notice, objections, and balance: the Operator may take the actions in clause 9.1 without prior notice if the abuse is serious, and will tell you by email to the Account where possible. Objections to such an action are sent to vibetokenapi1@gmail.com. The remaining Wallet balance stays yours and is refunded under the Refund Policy if the termination is not due to a violation; if the termination is due to a violation, the balance may be forfeited.
9.3 The Operator may switch the API off temporarily or entirely (an emergency switch), at any time and for any reason, including security, capacity, and maintenance. While the API is off, Requests through the API are rejected (503, service_unavailable) and are not billed; the model list is still served. The App, web Chat, and Plans keep running as usual unless stated otherwise.
9.4 You may stop using the Service at any time. You can revoke your own API Keys through the panel on the API page and delete your Account under clause 3.6.
9.5 Provisions that by their nature continue after termination (among others those on responsibility for API Keys, intellectual property, and limits of liability) remain in force.
10. Availability and changes to the Service
10.1 The Service is provided "as is" and "as available", without a service level agreement (SLA). Maintenance, technical faults, limited capacity, network problems, or problems at Third-Party Model Providers may make the Service or particular Models unavailable or slower.
10.2 The Operator may add, change, replace, or discontinue features, Models, prices, usage limits, Plan Credit, and other parts of the Service, including ending support for older versions of the App. Changes that affect users are announced through a banner on the Site and in the App.
10.3 The Service uses or connects to third-party services, for example Firebase Authentication for signing in and the QRIS payment app of your choice. Those third-party services are subject to their own terms.
11. Intellectual property
11.1 The Service, including the App, the Site, trademarks, logos, designs, documentation, and related software, is protected by copyright and other intellectual property rights and is owned by the Operator or its licensors. As long as you comply with these Terms, you receive a personal, limited, non-exclusive, non-transferable license to use the Service in line with these Terms. Open source components inside the App are subject to their own licenses.
11.2 Your Content remains yours. You give the Operator a limited permission to process, forward to Third-Party Model Providers, store, and display the Content solely to provide the Service to you.
11.3 The Operator does not claim ownership of the Model output generated for you. Output may be similar to output generated for other users.
12. No warranty and limits of liability
12.1 To the extent permitted by applicable law, the Service is provided without any warranty, express or implied, including warranties of availability, accuracy, fitness for a particular purpose, and freedom from errors.
12.2 To the extent permitted by applicable law, the Operator is not liable for indirect, incidental, special, or consequential loss, including loss of profit, data, or business opportunity, and is not liable for: actions the agent performs on your computer under the permissions or mode you choose; Model output; faults or changes at Third-Party Model Providers; and use of your API Key by a party that obtained it through your negligence.
12.3 Nothing in these Terms excludes or limits liability, or reduces your rights, where applicable law does not allow it to be excluded, limited, or waived.
13. Changes to these Terms
13.1 The Operator may change these Terms. The date of the latest update is shown at the top of the document.
13.2 How changes are notified and when they take effect: changes are announced through a banner on the Site and in the App and through the last-updated date at the top of this page. A change applies from that date to later use, and does not apply retroactively to payments already made.
13.3 If you keep using the Service after a change takes effect, you are deemed to accept it. If you do not agree, stop using the Service (clause 9.4).
14. General provisions
14.1 If any provision of these Terms is found invalid or unenforceable, the remaining provisions stay in force.
14.2 The Operator does not lose a right by not exercising it immediately.
14.3 These Terms, together with the Privacy Policy and the Refund Policy, are the entire agreement between you and the Operator concerning the Service.
14.4 You may not assign your rights or obligations without the Operator's written consent. The Operator may assign these Terms to the successor of its business.
14.5 The Operator is not liable for delay or failure caused by circumstances beyond its reasonable control (force majeure), including failures of electricity, networks, infrastructure providers, or Third-Party Model Providers.
15. Language
15.1 These Terms are provided in Indonesian and English. If the Indonesian and English versions differ, the Indonesian version prevails.
16. Contact
16.1 Questions about these Terms, reports of abuse, and payment or billing problems can be sent to vibetokenapi1@gmail.com.
16.2 For API billing problems, include the x-request-id header from the response concerned.