Terms of Service
By using xrpl.to you agree to the following terms.
Non-refundable services
All services sold by xrpl.to are non-refundable, including Boosts, API subscriptions, token launches and any other paid feature.
Irreversible trades
Trades on the XRP Ledger DEX cannot be undone. No central authority can reverse, cancel or change a transaction.
What xrpl.to is
xrpl.to is a trading interface and data aggregator for the XRP Ledger. Every trade happens directly on the XRP Ledger DEX; xrpl.to provides the interface and does not control the ledger. The web wallet is self-custody: xrpl.to never holds its funds or trades for you.
Two services do hold XRP: the Telegram bot’s wallet, which is custodial and trades on your instructions, and the wallets a token launch or presale creates, until that launch completes.
Your responsibility
- You are responsible for your trading decisions and their outcomes.
- You are responsible for securing your wallet and seed.
- xrpl.to is not liable for losses from trades, market conditions or user error.
- A token being listed is not an endorsement. Do your own research.
API usage policy
Attribution is required
Any app, website, bot or dashboard that shows xrpl.to data must show a visible, clickable credit to xrpl.to on the same screen as that data — not in an about page or a footer. Use "Data by xrpl.to" linking to https://xrpl.to. This applies with no key, on the Free plan and on every paid plan.<a href="https://xrpl.to" target="_blank" rel="noopener">Data by xrpl.to</a>
- Redistribution needs permission. Storing our data and serving it again from your own API, dataset or public dashboard needs written permission first. Email us — the answer is usually yes.
- Indexers and aggregators: use the paginated list endpoints instead of fetching one item at a time, cache what you fetch, and honour Retry-After on a 429. A repeated 429 means back off, not retry. Get a key instead of running without one, so we can raise your limits instead of blocking you.
- Partner tier: 100 req/sec, 20M credits a month and direct support, free and by invitation, for integrations that credit us properly. Apply from the dashboard, email hello@xrpl.to or DM @xrplto.
Fair use and access
Prohibited conduct
Access to xrpl.to and its API is granted on the condition that you do none of the following. Doing any of them is unauthorised access: we will revoke keys, block traffic, and pursue it where the harm warrants it.
- Denial of service: flooding, deliberately exhausting rate limits or credits, or any traffic meant to degrade the platform for others.
- Exploiting a vulnerability: using something you found to reach, take or change data, accounts or funds that are not yours. Testing for one is welcome — see Reporting a vulnerability below. Found something? Report it, do not exploit it.
- Getting around controls: evading rate limits, authentication or the API key system; rotating IPs, keys or user agents to beat a limit; using a key issued to someone else.
- Creating accounts or keys automatically, or getting access under false pretences.
- Reselling or sublicensing API access without written permission.
- Interfering with other users: hijacking sessions or accounts, obtaining someone else's API key, or phishing wallet credentials through this site. Seeds are encrypted in each user's own browser and never reach our servers; trying to extract one from a user's device is prohibited all the same.
Reporting a vulnerability
Pentesting is encouraged: probe, scan and test xrpl.to and its API as hard as you like. Tell us what you find privately at hello@xrpl.to before disclosing it anywhere else, and give us reasonable time to fix it. Good-faith research reported this way is welcome and we will not pursue it. Contact details: /.well-known/security.txt.