OpenRouter added detailed provisions governing API credentials, promotional credits, and credit management in an update detected on August 5, 2026. The revised terms establish that users are responsible for all activity under their API credentials except where caused by OpenRouter's breach, require notification of suspected unauthorized access, and permit OpenRouter to suspend or revoke credentials if reasonably necessary to protect the service. The terms also clarify that promotional credits have no cash value, expire on specified dates, are non-transferable, and are subject to different refund rules than purchased credits.
Developers: You are responsible for keeping your API keys secure and must tell OpenRouter immediately if you think someone else is using them.
Consumers: Free promotional credits OpenRouter gives you cannot be converted to money, refunded, or transferred to another account, and will stop working on the expiration date.
Consumers: OpenRouter can disable your account or API credentials if it thinks doing so is necessary to protect security.
The updated terms establish that users are responsible for all account activity and charges occurring under their API credentials, with the exception of activity directly caused by OpenRouter's breach of the terms. Users are required to promptly notify OpenRouter of any actual or suspected compromise or unauthorized use of API credentials. OpenRouter reserves the right to suspend, revoke, or limit API credentials or account access if OpenRouter reasonably believes doing so is necessary to protect the service, the user, OpenRouter, or any third party. Additionally, promotional credits provided by OpenRouter have no cash value, cannot be refunded or exchanged except under specific conditions, are non-transferable between accounts, and expire on dates specified at issuance or in accordance with the terms. You can manage your API credentials through your account settings and should promptly contact OpenRouter if you suspect unauthorized access.
→ Review your API credential management practices to ensure compliance with the security and confidentiality requirements stated in the updated terms.
→ If you receive promotional credits, document their expiration date and confirm the non-refundability and non-transferability restrictions before using them.
ConductAtlas has recorded 2 material changes to this document (since July 2026). An additional minor or cosmetic changes were excluded.
Users are liable for all account activity under their API credentials except where directly caused by OpenRouter's breach of terms.
Promotional credits have no cash value, are non-refundable and non-transferable, expire on specified dates, and do not qualify for standard refund protections.
OpenRouter may suspend, revoke, or limit API credentials or account access if reasonably believed necessary to protect the service or any party.
This change record describes what was added, removed, or modified in the document. Analysis reflects what the updated agreement states or permits. It does not constitute a legal determination about enforceability. Applicability may vary by jurisdiction. Methodology
OpenRouter added explicit API credential liability and security notification requirements, plus detailed promotional credit restrictions. The change clarifies user responsibility for account activity while preserving OpenRouter's ability to suspend credentials for security reasons. The promotional …
Regulatory exposure, obligation change, escalation trigger, board-ready language, and recommended action for legal and compliance teams.
Unlock the full institutional analysis — InsightConductAtlas provides verified policy intelligence sourced directly from platform documents. All analysis is intended to support, not replace, legal and compliance review. Record CA-C-004197.
OpenRouter restructured its User Content storage terms detected on July 28, 2026. Previously, the agreement described only Private Prompt Storage …
The navigation header of OpenRouter's privacy policy was simplified in an update detected on July 25, 2026. The 'Search' and …
OpenRouter's Terms of Service page was updated in an update detected on July 25, 2026. Two minor changes were made: …
561 arbitration provisions across 197 platforms. ConductAtlas tracks how dispute resolution is being restructured across the internet.
Coinbase's User Agreement includes a mandatory arbitration clause that most users may not have reviewed. Here is what the clause states and…
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Get alerted when this policy changes again, including what changed and why it matters.