ECZ-ID API Trust
Terms
These terms apply to the ECZ-ID API Trust agent plugin — the package eczid-api-trust, version 0.1.1.
They are product-specific terms. They sit under the EcoCitizenz Terms of Service, which is the agreement between you and EcoCitizenz Ltd and which governs everything not addressed here.
- Applies to:
eczid-api-trust0.1.1- Effective date:
- 3 September 2026
In short
- The plugin is free to install and use. There is no fee, no subscription and no account.
- The package is open source under the MITlicence. You may read, copy, modify and redistribute it on that licence's terms.
- It reviews files, not APIs. It sends no request to any endpoint, and it is not a security scan or a penetration test.
- It does not certify compliance, security or safety, and it is not legal or regulatory advice.
- Its results are a starting point for your own review, not a conclusion you can rely on without looking.
- Governing law and the limits on our liability come from the EcoCitizenz Terms of Service. This page does not restate them differently.
How these terms fit together
The EcoCitizenz Terms of Service (last updated 31 August 2026) govern access to and use of EcoCitizenz websites, ECZ-ID products, TrustOps, the Resolver, developer tools, software, APIs and machine-facing interfaces. They expressly contemplate product-specific terms, and provide that where there is a conflict, the more specific agreed terms govern that particular service to the extent of the conflict.
This page is that more specific layer for this plugin. Read the two together. Where this page is silent — governing law, acceptable use in full, warranties, limitation of liability, changes, termination, contact — the EcoCitizenz Terms of Service applies unchanged, and nothing here is intended to broaden or narrow it.
Separately, the MIT licence granted with the source code governs your rights to copy, modify and distribute that code. Where the licence grants you a right, that right is not restricted by this page.
What the plugin is
ECZ-ID API Trust is a free, local, read-only evidence review distributed as an Agent Plugins 1.0.0 package. Installed in an agent host, it adds one skill. When invoked, it lists the file names and paths under a folder you choose and reports which classes of API evidence were observed, which were not, why each matters and what to review next, together with a deterministic Review Priority and the reasons for it.
It reads names and paths only, and does not open files — including the contracts and authentication configuration it reports on. Its behaviour is described in detail on the Privacy page, and the source is public.
The package also declares the ECZ-ID Verifier server, so that hosts which run local MCP servers can check a public proof reference the review found. That capability has its own terms, and it too writes no truth.
Not a scan, and not a test of your API
This clause exists because the wrong assumption here is the dangerous kind: relying on this plugin as though it had checked an API that it never contacted.
The review sends no request to any endpoint, in any environment. It is not a penetration test, a vulnerability scan, a dynamic security test, a conformance test or a monitoring tool, and it must not be used, relied on, resold or described as any of those. It cannot detect a vulnerability, an exposed operation, a broken authentication path or drift between a contract and a deployment, because it never looks at the running system and never opens the contract.
Nothing about installing or running it satisfies an obligation you have to test, secure, monitor or assess an API, whether that obligation comes from a customer, an insurer, a regulator or your own policy.
What you may do with it
You may install and run the plugin on your own machine and in your own agent host, for personal or business purposes, at no cost. You may run it against repositories you own or are authorised to review. You may share, publish or submit its output as you see fit — the output is yours.
Because the package is licensed under MIT, you may also read, copy, modify, merge, publish, distribute, sublicense and sell copies of it, subject to the licence conditions — principally that the copyright notice and permission notice are retained. The full text is in the repository licence file.
No account, registration, activation key or entitlement is needed, and none is created by using the plugin. Running a review does not create an ECZ-ID, an entitlement, a credential or any public proof.
Your responsibility
You choose which folder to review, and you are responsible for having the right to review it. You are responsible for what you do with the output, including any decision you take or communication you make on the strength of it.
The review is an input to your judgement, not a substitute for it. In particular:
- filename-and-path detection shows that a document exists where a reviewer would expect one; it cannot show that the document is current, complete, accurate or matched by what is deployed;
- EVIDENCE NOT OBSERVED is neutral. It means the review did not see it in the place it looked. It does not mean the evidence does not exist, and it does not mean anything is wrong;
- a result describes a folder at the moment it was reviewed. Re-check before relying on it;
- your own policy decides what evidence is sufficient for your purpose. The plugin does not decide that, and neither do we.
No certification, approval or advice
This is the most important clause on the page, and it is not boilerplate. Consistent with the EcoCitizenz Terms of Service, the plugin and its output do not:
- certify that an API, repository, product, service or organisation is safe or secure;
- certify compliance with any law, regulation, standard or scheme, or constitute regulatory approval, or approval by any authority, marketplace or platform;
- constitute an audit, an audit opinion, an assurance engagement or a security test;
- constitute legal, regulatory, financial, insurance or other professional advice;
- establish that an API is correctly secured, correctly documented, or that its declared surface matches its deployed one;
- guarantee that a consumer, platform, auditor or insurer will accept your evidence;
- replace your own due diligence, testing or security programme.
The Review Priority is an indication of how much attention an evidence review deserves, based only on what was observed locally by filename and path. It is not a score, a grade, a rating, a pass mark, a risk assessment or a determination of safety, approval or compliance.
Running a review creates no ECZ-ID, no API Passport, no entitlement and no public proof. An ECZ-ID API Passport is set up in TrustOps and read from the Resolver; it is a platform service, and this plugin is not a route to it beyond a link.
Acceptable use
The acceptable-use terms in the EcoCitizenz Terms of Service apply. In the specific context of this plugin, you must not:
- run it against systems or repositories you have no right to review;
- alter its output and present the altered version as the result of an ECZ-ID review;
- present a review as a certification, an audit, an approval or a statement of compliance, or otherwise misrepresent what it establishes;
- represent an expired, superseded or historical result as a current one;
- use the ECZ-ID name, logo or branding in a way that suggests endorsement, certification or a relationship that does not exist;
- imply that EcoCitizenz has verified, approved or is otherwise responsible for your product because you ran this plugin against it.
Intellectual property and licensing
The plugin package — its manifest, skill document, review script, evidence-class reference and documentation — is released under the MIT licence, copyright EcoCitizenz Ltd. That licence, and not this page, is what grants you rights in the code.
The MIT licence covers the code. It does not transfer or license the ECZ-ID and EcoCitizenz names, logos, branding or product marks, which remain the property of EcoCitizenz Ltd, nor the wider ECZ-ID services, schemas, verification formats and infrastructure, which are governed by the EcoCitizenz Terms of Service. You may say truthfully that your project uses this plugin. You may not use our marks to suggest endorsement or certification.
The output of a review that you run is yours. We assert no ownership over it and receive no copy of it.
Availability, changes and updates
The plugin is provided as it is, when it is available. We may change, update, re-version, rename, deprecate or withdraw it, and we may change the detectors, the guidance or the Review Priority rules in a future version. We do not guarantee uninterrupted availability of any distribution channel, and no service level applies to it.
The plugin runs on your machine, so a version you have already installed keeps working whether or not it is still distributed. Because it is MIT-licensed, a copy you hold remains yours to use under that licence.
Distribution through a marketplace or agent-plugin directory does not guarantee continued listing, ranking, visibility or recommendation, and does not imply that the operator of that marketplace has endorsed, certified or reviewed the product.
Agent hosts, marketplaces and other third parties
You run this plugin inside an agent host operated by a third party, and you may have obtained it through a third-party marketplace or directory. Those platforms are not operated by EcoCitizenz. Your use of them is governed by their own terms and privacy policies, and they may impose requirements of their own; where a marketplace's mandatory terms govern a transaction on that marketplace, those terms apply to it.
EcoCitizenz is not responsible for the availability, behaviour, security or data handling of any agent host or marketplace, and nothing on these pages is a commitment made on their behalf. Naming a platform here identifies the software involved; it does not indicate affiliation, sponsorship or endorsement in either direction.
Links from a review result to EcoCitizenz pages, or to public documentation elsewhere, are routing only. Setup, subscriptions and payment for paid ECZ-ID credentials happen in TrustOps under the EcoCitizenz Terms of Service. This plugin takes no payment and creates no entitlement.
Security research
EcoCitizenz supports good-faith security reporting. If you believe you have identified a vulnerability, report it through the route on the Support page rather than disclosing it publicly first.
When testing, you must not access customer data unnecessarily, destroy or alter data, disrupt production systems, perform denial-of-service testing, exploit a vulnerability beyond what is reasonably required to demonstrate it, or publicly disclose a vulnerability before reasonable coordinated disclosure where doing so would create material risk. These conditions are those set out in the EcoCitizenz Terms of Service.
Warranties and liability
The plugin package is distributed under the MIT licence, which provides the software as is and without warranty of any kind. That disclaimer applies to the code.
Beyond that, the warranty and liability terms in the EcoCitizenz Terms of Service apply, including the limits on liability and the exceptions to them. This page does not create a different liability position, and does not state a figure or a cap of its own — the Terms of Service is the place those are set.
Nothing on this page excludes or limits liability where it would be unlawful to do so, and nothing here affects rights you have under mandatory law, including consumer rights where they apply to you.
Governing law
The EcoCitizenz Terms of Service are governed by the laws of England and Wales, and set out the position on jurisdiction, including the protections that apply if you are a consumer. That governing-law position applies to these product terms as well. This page states no separate choice of law and no separate jurisdiction clause.
Questions about these terms
Write to support@ecocitizenz.com, naming ECZ-ID API Trust in the subject line. The publisher details are below.
Plainly, so there is no doubt
- Running this review does not make your API secure, and we never say that it does. It helps you see which evidence is where before a consumer or an auditor asks for it.
- This plugin never touched your API. Nothing it reports is a statement about the running service, and it must not be presented to anyone as though it were.
- EcoCitizenz has not certified, approved or audited your API, your repository or your organisation, and a review result must not be presented as though we had.
- A free VS Code extension, ECZ-ID API Security, covers similar ground on the Visual Studio Marketplace and Open VSX; that is a separate product with its own terms.
- No ECZ-ID product on this page is endorsed by, affiliated with or approved by any regulator, standards body, marketplace operator or AI platform.
Publisher
ECZ-ID API Trust is published by EcoCitizenz Ltd, trading as EcoCitizenz, company number 17348848, registered in England and Wales.
66 Paul StreetLondon EC2A 4NAUnited KingdomContact: support@ecocitizenz.com