LEGAL
API, MCP and Data License Terms
Effective 2026-09-22 · Version 1
Operator: Discry LLC, a New York limited liability company, 418 Broadway, Suite 10855, Albany, NY 12207. Contact: legal@discry.ai.
Defined terms used. Discry, Site, Services, Scan, Directory, Index, Band, Fix Kit, and Machine Access have the meanings given in the Terms of Use. Correction Request, Rescan Request, and Takedown Notice have the meanings given in the Directory and Benchmark Policy. These Terms define three terms of their own: Index Data, Service, and Badge (section 2).
Part A governs access to the machine surfaces. Part B is the licence for the data those surfaces return and stands on its own.
1. What these Terms cover
1.1 These Terms apply to every machine surface Discry publishes: /api/mcp (the MCP server), /api/v1/index.json, /api/v1/:slug (JSON or markdown for one API), /api/index.json, /api/index.csv, /api/badge/:slug (Badge SVGs), the .md mirrors of Site pages, llms.txt, llms-full.txt, and AGENTS.md. Together these are the Service (section 2.2).
1.2 You accept these Terms by sending a request to any part of the Service, whether you send it yourself or an agent, script, crawler, or model sends it for you. There is no sign-up, key, or click to accept, because the Service has none. Discry's own robots.txt allows every user agent across the whole Site; these Terms are the conditions on which that openness is offered.
1.3 These Terms are linked from llms.txt and from the /mcp page. They are not yet linked from the machine exports themselves, which will carry the link when the licence field in section 17 ships; section 17.1 states exactly where the licence marker appears today.
1.4 Precedence. The Fix Kit Terms prevail over these API, MCP and Data License Terms (for Machine Access), which prevail over the Terms of Use. The Privacy Policy, Cookie Policy, Crawler and Acceptable Use Policy, and Directory and Benchmark Policy are notices incorporated by the Terms of Use. The Refund Policy is incorporated by the Fix Kit Terms. The Terms of Use apply to your use of the Service except where these Terms say something different about Machine Access, in which case these Terms govern.
1.5 The Service is free. A paid, keyed, or quota-based tier, if Discry ever offers one, will be governed by a new version of these Terms.
2. Defined terms
2.1 Index Data means the structured benchmark records Discry publishes about APIs through the Service and the Directory: for each API, its slug, name, category, status, overall score, discovery and comprehension sub-scores, Band identifier and Band name, capability floor, discovery signals, off-ladder status and reason summary, instrument version, and scan date; together with the corpus-level counts, medians, adoption figures, rankings, and the machine label scheme that the exports carry. Section 12 lists what Index Data does not include.
2.2 Service means the machine surfaces listed in section 1.1, as they exist from time to time.
2.3 Badge means the SVG image Discry serves at /api/badge/:slug for an API in the Index, showing that API's current Band; an unscored row's Badge never carries a Band.
Part A: Access terms
3. Licence to use the Service
3.1 Discry grants you a non-exclusive, revocable, non-transferable permission to send requests to the Service and receive its responses, for any lawful purpose, subject to these Terms.
3.2 This permission is to the Service, not to the data. Your rights in the data come from Part B, which survives anything that happens to your Service access (section 9.4).
3.3 You may not resell, sublicense, or charge others for access to the Service itself. You may build products, including paid ones, on the data you receive under Part B, subject to its conditions.
4. Access is unkeyed and unmetered today
4.1 As of the effective date, no part of the Service requires authentication, an API key, or a token, and no part of the Service is rate limited, quota'd, or metered. The only rate limit anywhere in Discry's code is on an unrelated Fix Kit email route, lives in the memory of a single serverless instance, and is not a durable control.
4.2 Reasonable use. In return for open access Discry asks that you: honour Discry's cache headers (section 5.3); fetch the bulk exports (/api/v1/index.json, /api/index.csv) when you want the whole Index instead of walking every per-slug route; avoid distributed or concurrent request patterns that degrade the Service for others; and do not scrape the Site's HTML to rebuild what the machine surfaces already give you.
4.3 Discry's reserved rights. Discry may at any time, on notice given by updating these Terms and the /mcp page, introduce throttling or a quota, require a key or other credential for some or all of the Service, block a network, user agent, or client that is causing harm, or suspend the Service. Discry will not publish a number for a limit it does not enforce; when it introduces one, the number, the surface, and the response your client will see will be stated in the version of these Terms that introduces it.
4.4 Emergency measures. Where a pattern of requests is degrading the Service for everyone, Discry may block it first and update these Terms afterwards.
5. No service level, and the Service may change
5.1 The Service is provided as it is and as it is available. Discry gives no uptime commitment, no support commitment, and no commitment that any endpoint, field, tool, schema, or response shape will continue to exist. The Site's database runs on a free tier that pauses when idle and is kept warm by a scheduled job; a pause can make dynamic surfaces slow or unavailable.
5.2 Discry may change, version, deprecate, or withdraw any part of the Service without notice. indexContractVersion in /api/v1/index.json is there so a client can detect a schema change; it is a courtesy, not a promise.
5.3 Caching. The JSON and CSV exports carry a public cache lifetime of 3,600 seconds and Badges 86,400 seconds. /api/v1/index.json is statically generated at build time; /api/index.csv is generated on request because it accepts a category filter. A response may therefore be up to an hour behind the Index for data and up to a day for Badges, on top of the Index's own refresh cadence (section 15).
5.4 Formats. /api/v1/:slug returns JSON or a markdown representation served as text/markdown. /api/index.csv follows RFC 4180 and is served as an attachment named discry-index.csv. Machine exports carry the raw engine colour values for Bands, which differ from the colours the human Site displays; numbers, names, and Band identifiers are the same on both.
6. What you may not do with the Service
6.1 You may not:
(a) send requests designed to degrade, overload, or take down the Service or the Site, or probe them for vulnerabilities without written permission from legal@discry.ai;
(b) evade a block, key requirement, quota, or throttle once Discry has introduced one under section 4.3, including by rotating addresses, user agents, or credentials;
(c) scrape the Site's HTML pages to reconstruct the Index when the same data is available from the machine surfaces;
(d) present a response from the Service as if it came from your own measurement, your own benchmark, or a benchmark other than Discry (section 16 covers the same rule for the data);
(e) use the Service to send unsolicited communications to the companies listed in the Index, or to build contact lists from it; or
(f) attempt to reach the bearer-authenticated internal worker endpoints, which are not part of the Service and are not offered to the public.
6.2 Section 6.1(b) is written for the future. While section 4.1 is true there is no limit to evade, and ordinary high-volume use of an unlimited surface is not circumvention.
7. The MCP server
7.1 What it is. Discry runs a Model Context Protocol server at /api/mcp. It runs on a Node runtime, is stateless, keeps no session identifier, and answers GET, POST, and DELETE. It identifies itself to clients as discry, version 1.0.0.
7.2 What the tools do. Every tool is a read against the published Index. No tool runs a scan, calls a model, or reaches the API being asked about; a tool call returns only what the Index already holds. The tools are discry_profile (decomposed scores, capability floor, discovery signals, status and reason, and provenance including instrument version and scan date) , discry_find (up to 20 ranked results, with rank precomputed by the Index export and never recomputed in the tool) , discry_compare (a head-to-head of two APIs plus a link to the comparison page) , and discry_methodology (the methodology summary and corpus statistics).
7.3 Tool responses are dated opinion. Every score, Band, ranking, and reason summary a tool returns is Discry's opinion of how agents found and understood an API's documentation on the scan date the response carries, under the instrument version it names. It is not a statement about the API's quality, security, reliability, or fitness; the methodology tool itself states that Discry does not test authentication, live calls, reliability, or SDK behaviour. An agent that acts on a tool response acts on a dated opinion, at its operator's risk (section 10).
7.4 What the server logs. Discry records every MCP tool call to its own event store, including the tool name and the caller's full arguments. No IP address is stored. Do not put personal data, secrets, or confidential material into tool arguments; the tools need only a slug, a query, or a pair of slugs, and anything else you send is stored with the call. No retention limit or deletion job exists for that store today; the Privacy Policy describes the record and your rights over it.
7.5 Registry listings. Discry may list the server in the official MCP Registry or other directories. A listing describes the server and does not change these Terms.
7.6 Everything a tool returns that is Index Data is licensed under Part B. The tool's prose framing, the comparison link it hands you, and the methodology summary are Site content, not Index Data.
8. Badges
8.1 What a Badge shows. A Badge is served for every API in the corpus, is statically generated, is cached for a day, and an unscored row's Badge never carries a Band. Badges carry literal hex colours because an embedded image cannot read the Site's fonts or style variables.
8.2 Permission to embed. You may embed the Badge for any API, including one you do not operate, on any page, README, or document, on these conditions:
(a) load it from /api/badge/:slug on https://discry.ai; do not copy, re-host, or inline it, so that it always shows the current Index state;
(b) link it back to that API's profile page on the Site or to https://discry.ai;
(c) do not alter it: no recolouring, cropping, relabelling, overlaying, or editing of its text, Band, status, or mark; and
(d) do not place it so as to suggest that a different API, product, or company holds the Band it shows.
8.3 A Badge is a live display of Index Data, not a certificate. It changes when the Index changes, including downward. Discry does not freeze a Badge at a Band an operator prefers, and a Fix Kit purchase never buys Band movement.
8.4 To stop a Badge showing on a page you control, remove the embed. To object to the Index row behind it, use the Directory and Benchmark Policy routes (section 18).
9. Suspension and revocation
9.1 Discry may suspend or revoke your access to the Service, in whole or in part, with or without notice, if you breach section 6, 8, or 16, if your use is harming the Service, the Site, or a third party, or if the law requires it. Where practical Discry will tell you why.
9.2 Discry may also suspend or withdraw the Service for everyone under section 5.
9.3 While section 4.1 holds there are no keys to revoke, so Discry can only block by network, user agent, or pattern, and may block more broadly than one client to reach the one causing harm, narrowing the block as soon as it can.
9.4 Revocation of access does not revoke the data licence. Index Data you received under Part B while your access was valid stays licensed to you under CC BY 4.0, because that licence is irrevocable while you comply with it and Discry ceasing to distribute the material does not end it (CC BY 4.0 section 6(c)). Losing Service access means you stop receiving new Index Data, nothing more.
10. No warranty, and no reliance by machines
10.1 Discry gives no warranty of any kind for the Service or anything it returns: not accuracy, completeness, currency, fitness for any purpose, or non-infringement, and not that the Service will be available or error-free. Every response is Discry's dated opinion under its published methodology (section 7.3).
10.2 Scores rest on a locked instrument and a task bank, part public and part permanently held out. Public tasks are assumed contaminated once published; held-out tasks rotate only on instrument version bumps. A scan that hits a model alias re-point never writes a score. These controls are not a guarantee that the numbers are right.
10.3 No reliance. If you, or an agent acting for you, select, reject, rank, route to, or avoid an API on the strength of Index Data or a Service response, you do so at your own risk. Discry did not test the API for your use case; it tested how agents found and understood the API's documentation on a given date.
10.4 Unscored rows. A row with a status such as unreachable, blocked, or insufficient-coverage carries no Band and no score, and nothing in the Service supplies one. A client that treats a missing score as a low score is misreading the data.
11. Liability
11.1 The limitation of liability in the Terms of Use applies to the Service and to Index Data exactly as it applies to the rest of the Services; these Terms add no separate cap and remove none of the exclusions there. Because the Service is free, the amount recoverable under that cap for a Service claim will ordinarily be zero.
11.2 Nothing in these Terms limits liability that the law applying to you does not allow to be limited, or a consumer's mandatory rights in the EU or UK.
Part B: Data licence
12. What is licensed and what is not
12.1 Licensed. Index Data as defined in section 2.1, in every form Discry publishes it: the JSON and CSV exports, the per-slug JSON and markdown, the MCP tool responses, the Band and status values behind Badges, and the same figures where they appear on the Directory, comparison, data, signals, and report pages. The public-development task prompts, score formulas, grading rubric, schemas, and grading logic are published under Discry's holdout policy. Those materials are published, but only Index Data as defined in 2.1 is licensed under Part B.
12.2 Not licensed under Part B:
(a) the name Discry, the phrase Discry Benchmark, the Band names Sharp, Clear, Legible, Murky, and Opaque as marks (their use as data values is licensed under 12.1), the mascot, logos, and the Site's design and typography (section 13.3);
(b) the held-out task prompts, per-scan task selection, rotation schedule, ground-truth accept-sets and citation quotes, and canary strings, all permanently withheld;
(c) the names, marks, and logos of the companies and APIs described in Index Data, which belong to those companies (section 18.1);
(d) excerpts of third-party documentation Discry quotes on the Site, including cached opening lines of llms.txt and AGENTS.md files and documentation text inside published traces. That text is published as evidence for a score, is attributed to its source, and is not licensed by Discry: it remains its author's property, as the Directory and Benchmark Policy sections 2.5 and 5.4 and the Crawler and Acceptable Use Policy section 7.3 state. Nothing here restricts any use of that text that its owner, or the law, already permits;
(e) the prose of the Site, the methodology pages, the report chapters, and the Fix Kit;
(f) the Badge SVG image itself, which is an embeddable asset governed by section 8; the Band and status values it displays are Index Data; and
(g) any personal data. Index Data describes companies and their documentation, and the export fields carry none.
13. The grant
13.1 Discry licenses Index Data to everyone under the Creative Commons Attribution 4.0 International Public License, CC BY 4.0, whose full text is at https://creativecommons.org/licenses/by/4.0/legalcode. That licence, not these Terms, is the grant. These Terms say how to satisfy its conditions in Discry's context (section 14) and add contractual conditions on Service access (section 16) that sit alongside it without narrowing it.
13.2 Database rights. To the extent Index Data is protected by a sui generis database right in the EU, UK, or elsewhere, that right is licensed under CC BY 4.0 section 4 together with copyright, subject to attribution.
13.3 Patents and trademarks are not licensed under CC BY 4.0 (section 2(b)) or by these Terms. You may use the word Discry to say where the data came from, which attribution requires; you may not use it, the Band names, or the mascot as a brand for your own product or benchmark, or in a way that suggests Discry endorses, certifies, or sponsors you (CC BY 4.0 section 2(a)(6)).
14. Attribution
14.1 The attribution string. CC BY 4.0 section 3(a) requires attribution in the manner the licensor requests. Discry requests this exact string, with the scan date filled from the record you are using:
Discry Index, Discry LLC, https://discry.ai, CC BY 4.0, scan date as shown
"Scan date as shown" means the scannedAt or generatedAt value carried by the record or export you used, written where a reader can see it. The link goes to https://discry.ai or to the specific profile, comparison, or export page the data came from. The manner of attribution Discry requests under CC BY 4.0 section 3(a)(1)(A)(i), reasonable to the medium, includes the scan date and, for an unscored row, the status as shown.
14.2 Where it goes. Wherever a reader of your work would look for a source: a caption, a footnote, a data-source line, a README, a dataset card, or a tooltip. For a whole-Index redistribution, in the dataset's metadata and any file that lists sources. For a single number quoted in prose, a link to the profile page with the words "Discry Index" and the date is enough.
14.3 Machine contexts. Where your work has no human-readable surface, such as a dataset served only by API, a vector store, or a retrieval corpus, carry the string, or at minimum the fields source: Discry Index, licence: CC BY 4.0, url: https://discry.ai, and the scan date, in the record's metadata. CC BY 4.0 section 3(a)(2) lets you meet the condition in any reasonable manner for the medium; this is what Discry considers reasonable for a machine medium.
14.4 Modifications. If you change Index Data, including by re-scoring, re-banding, filtering in a way that changes a ranking, combining it with your own measurements, or converting a Band to a scale of your own, say so next to the attribution ("adapted from", "modified") and keep any earlier modification notice (CC BY 4.0 section 3(a)(1)(B)). A changed number under Discry's name with no modification notice breaches the licence and section 16.
14.5 No endorsement. Attribution must not state or imply that Discry endorses, certifies, sponsors, or is connected with you or your work (CC BY 4.0 sections 3(a)(1)(A)(iii) and 2(a)(6)). "Data: Discry Index" is attribution. "Discry-certified" is not permitted.
14.6 Removal on request. If Discry asks, you must remove Discry's name from an adaptation to the extent reasonably practicable (CC BY 4.0 section 3(a)(3)).
15. Freshness and dating
15.1 Every export carries a generatedAt value and every profile a scannedAt value and an instrument version. A record is Discry's opinion as of that date and under that instrument, and no later.
15.2 The Index is refreshed continuously by an hourly wider scanner and an hourly publish job that commits to the Site's main branch; Fix Kit confirmation runs also publish. Between publish and the cache lifetimes in section 5.3, a record you receive may be more than an hour behind the latest scan.
15.3 Discry asks that, when you republish Index Data, you carry the date as part of the attribution in section 14.1, and that when you show a single score you show its date beside it or link to the profile page that does. A copy with the dates stripped is a changed record, and the modification notice in section 14.4 applies to it.
15.4 The Service serves no archive of past Index states; if you need a historical snapshot, keep your own and date it.
16. Conditions on use of Index Data
16.1 CC BY 4.0 lets you use Index Data for any purpose, including commercially. The conditions below are contractual conditions of Service access under Part A. Nothing in Part A, including sections 6, 8, and this section, narrows or conditions the licence in Part B; Part A governs use of the Service, not the licensed data. Part A binds only those who access the Service. A downstream recipient who obtains Index Data from someone else and never touches the Service holds CC BY 4.0 directly from Discry LLC, and the attribution conditions in section 14 are the only conditions on that recipient. Breaking a condition below ends Service access (section 9) and, where it is also an attribution breach, ends the CC licence as section 19 describes.
16.2 You may not:
(a) republish Index Data, in whole or in part, without the attribution in section 14, or strip, hide, or bury that attribution;
(b) present Index Data as your own measurement, or as the output of another benchmark, rating, or certification scheme, whether by relabelling, re-branding, or omission;
(c) present a modified score, Band, ranking, or status under Discry's name without the modification notice in section 14.4;
(d) use Index Data, alone or with other material, to train, fine-tune, or prompt a model or system whose purpose or effect is to reproduce, predict, or reverse-engineer the held-out task prompts, per-scan task selection, ground-truth accept-sets, or canary strings, or otherwise to game a Scan; or
(e) use Index Data to send unsolicited communications to listed companies or to build contact lists.
16.3 Permitted, for clarity: training or evaluating a model on Index Data for purposes other than 16.2(d); building a competing benchmark from your own measurements and comparing it to Discry's with attribution; caching, mirroring, and redistributing the whole Index with attribution; and quoting a single score with its date and source.
17. Where the licence is stated today
17.1 As of the effective date, the CC BY 4.0 marker appears in machine-readable form only in the JSON-LD Dataset block on the per-signal pages at /signals/:signal, and in prose in the State of Agent-Readiness report. The /data page, /api/v1/index.json, /api/index.csv, the per-slug routes, and the MCP tool responses do not yet carry a license field.
17.2 That gap does not narrow the licence. Index Data is licensed under CC BY 4.0 whether or not a given export says so, and these Terms are the authoritative statement of the licence for every surface in section 1.1. Discry will add a license field naming CC BY 4.0 and linking to these Terms to the machine exports and MCP responses; until it ships, a consumer relies on this section.
18. Third-party rights and objections to machine distribution
18.1 Company names and marks. Index Data names companies and their APIs, and the Site shows their marks, because that is the only way to say whose documentation was measured. This is nominative use. The marks are monochrome brand marks from an open icon set plus a curated override file, or a monogram where no mark exists, and none is licensed by Discry to anyone. When you redistribute Index Data you may use a company's name to identify the row; you may not use its mark without that company's permission.
18.2 Machine distribution is not a separate publication. A score published in the Directory is the same score served by the Service, the Badge, and the MCP tools; the machine surfaces are formats of the Directory, not a second decision to publish. A company that objects to its score, status, reason summary, or inclusion uses the Directory and Benchmark Policy routes: a Correction Request, a Rescan Request, or a Takedown Notice, sent to legal@discry.ai. No web form or endpoint exists for these yet; email is the route.
18.3 What a successful objection changes. When Discry corrects, rescans, or removes a row under the Directory and Benchmark Policy, the change reaches every machine surface at the next publish job and clears from caches within the lifetimes in section 5.3. Discry cannot alter Badges already in a consumer's cache before they expire, and cannot recall copies of Index Data that third parties received under CC BY 4.0 before the change. Those copies remain licensed but are dated (section 15), and a downstream consumer who republishes a superseded score is asked to carry its date as part of attribution (section 14.1). Discry states this limit rather than promise a recall it cannot perform.
18.4 Discry does not offer a listing that appears in the Directory but not in the Service, because the two are one dataset. A Takedown Notice that succeeds removes the row from both.
18.5 A row Discry could not score publishes an explicit status and, where relevant, a reason summary, never a fabricated Band. Discry asks that redistributors carry the status as shown, which section 14.1 includes in the requested attribution, and not convert it into a score or a lowest-Band label.
19. Termination and reinstatement of the data licence
19.1 The CC BY 4.0 licence ends automatically if you fail to comply with it, and reinstates automatically if you cure the failure within 30 days of discovering it, or when Discry expressly reinstates it (CC BY 4.0 section 6). These Terms do not change that mechanism.
19.2 Ending your Service access under section 9 does not, on its own, end the CC BY 4.0 licence on data you already hold (section 9.4). Only your own breach of the licence's conditions does that.
19.3 Discry may seek any remedy the law allows for a breach of CC BY 4.0 or of these Terms, whether or not the licence has reinstated.
Part C: General
20. Disputes
20.1 Any dispute arising from these Terms, the Service, or Index Data is governed by section 14 of the Terms of Use, which is incorporated here by reference and applies exactly as written there.
21. Changes to these Terms
21.1 Discry may change these Terms by publishing a new version with a new effective date and version number at the same address; the previous version is kept unchanged in Discry's legal archive and is available on request to legal@discry.ai. A change that introduces a limit, key, quota, or paid tier is made only by a new version (sections 1.5 and 4.3). Continued use of the Service after a new version's effective date is acceptance of it; data already received stays under the licence it was received under.
22. Contact
22.1 Questions about these Terms, attribution, a licence request outside CC BY 4.0, a Correction Request, a Rescan Request, or a Takedown Notice: legal@discry.ai. Postal address: Discry LLC, 418 Broadway, Suite 10855, Albany, NY 12207.
Machine-readable mirror: /legal/api-terms.md