Skip to content

MYOB PayGlobal API Terms

These API Terms govern your use of the MYOB PayGlobal API. They form part of your MYOB PayGlobal Software and Services Agreement and apply once you order the API Service under an Order Form.

1. How these API Terms work

1.1 These MYOB PayGlobal API Terms (API Terms) apply when you order the API Service. They form part of your MYOB PayGlobal Software and Services Agreement with us (Agreement) from the start date of the Order Form for the API Service.

1.2 Words defined in the Agreement have the same meaning in these API Terms, unless we define them differently here. The rules of interpretation in the Agreement apply.

1.3 By signing an Order Form that includes the API Service, you and we agree to vary the Agreement so that these API Terms form part of it. If there is any inconsistency about the API Service, these API Terms prevail over the rest of the Agreement and over any Order Form, and the order of priority clause in the Agreement is varied accordingly.

1.4 We may change these API Terms from time to time by notifying you in writing. We will give you at least 30 days’ written notice if a change is likely to have a material detrimental impact on you, and you may then terminate the API Service before the change takes effect.

2. The API Service

2.1 If an Order Form says that we will provide the API Service, we will make the API available to you for the Tier stated in the Order Form, issue you with API Credentials and give you access to the API Documentation.

2.2 We grant you a non-exclusive, non-transferable, non-sublicensable and revocable right to access and use the API and the API Documentation for the Permitted Purpose only, for the term of the Order Form for the API Service, and subject to the Agreement.

2.3 The Permitted Purpose is using the API to exchange your Customer Data between the Software and a Connected System for the internal management and operation of your own business. It does not include using the API, the Software or API Data to provide any product or service to a Third Party.

2.4 You must use the API in accordance with the API Documentation, including any rate limits, quotas and security requirements set out in it.

2.5 The API Service does not change your Software Licence or your Number of Licensed Employees. Access to the API does not entitle any person to use the Software who is not licensed to do so.

3. Tiers, Call Allowance and API Fees

3.1 Your Tier is stated in the Order Form. Each Tier has a Call Allowance, set out in the Schedule. A separate Tier and Call Allowance applies to each database or site stated in the Order Form.

3.2 Each request to an endpoint of the API using your API Credentials is one API Call. Our records of API Calls are conclusive evidence of your usage, unless there is a manifest error.

3.3 If your API Calls exceed your Call Allowance in two consecutive calendar months, we may move you to the next Tier by giving you at least 30 days’ written notice stating your new Tier, Call Allowance and API Fees. The fee change mechanics and notice requirements in the Agreement do not apply to that Tier change.

3.4 If you do not want to move Tier, you may terminate the API Service by giving us written notice before the change takes effect, and we will refund any API Fees you have paid in advance for the period after termination.

3.5 You must pay us the API Fees set out in the Order Form. API Fees apply per database or site, are billed monthly and exclude GST, unless your Order Form states otherwise.

3.6 We may set and change rate limits, quotas, payload sizes and concurrency limits for the API, and will publish them in the API Documentation. We act reasonably in setting these.

4. Your obligations

4.1 You must not:

(a) exceed your Call Allowance other than as permitted by clause 3.3, or attempt to circumvent any rate limit, quota or other technical limit we apply;

(b) use the API, or allow the API to be used, for anything other than the Permitted Purpose;

(c) use the API to access, or attempt to access, any data other than your own Customer Data;

(d) extract, replicate or store API Data in bulk, or on a scheduled or continuous basis, beyond what your Integration needs for the Permitted Purpose; or

(e) operate or expose any protocol server, agent orchestration layer or other API-brokering layer, including any implementation of the Model Context Protocol, that proxies the API or that allows any Third Party, model or autonomous agent to call the API other than through your Integration for the Permitted Purpose.

4.2 API Credentials are Access Credentials for the purposes of the Agreement, and your obligations under the Agreement relating to the security and use of Access Credentials apply to them.

4.3 You must not use the API, the API Documentation or our Confidential Information to train, fine tune, adapt or evaluate any AI Model.

4.4 Security testing

(a) You must not, and must not permit any person to, conduct any penetration test, vulnerability scan, load test or other security or intrusion test on the API, or on any system of ours that you reach through the API, without our prior written approval.

(b) If we approve a test, you must conduct it in accordance with the scope, timing, method and environment we approve, and stop the test immediately if we ask you to.

(c) This clause does not limit any other provision of the Agreement. Nothing in these API Terms permits you to conduct security testing of the Software, the Online Services Environment or any other system of ours.

4.5 Vulnerabilities

(a) If, in the course of or as a result of using the API, you become aware of a vulnerability, defect or weakness in the security of the API or of any other system of ours, you must report it to us in writing as soon as possible to securityincidents@myob.com.

(b) You must treat that information as our Confidential Information, whether or not we have designated it as confidential and whether or not you discovered it independently of us.

(c) You must not disclose that information to any person other than us, and must not make it public, until we have remediated the vulnerability or we agree otherwise in writing. This does not prevent disclosure required by Applicable Law.

5. Nominated Integrator

5.1 You may engage a Third Party to build, operate or maintain your Integration, and give that Third Party access to the API on your behalf, if:

(a) you notify us in writing before you give them access and we accept them as a Nominated Integrator, which we will not unreasonably refuse;

(b) they access the API only to provide services to you for the Permitted Purpose, using API Credentials issued in your name or credentials we issue for that purpose; and

(c) you have a written agreement with them that limits their access to and use of API Data to what they need to provide those services, and that imposes confidentiality, privacy and security obligations at least as protective as those in the Agreement.

5.2 Access by a Nominated Integrator in accordance with clause 5.1 does not breach any provision of the Agreement that restricts you from giving a Third Party access to, or sub-licensing, the Software or Services.

5.3 You are responsible and liable for the acts and omissions of your Nominated Integrator in connection with the API as if they were your own.

6. API Data

6.1 You decide what API Data is transmitted between the Software and each Connected System, and in which direction. When you or your Nominated Integrator use the API to transmit API Data from the Software to a Connected System, you instruct us to disclose that API Data, and you are responsible for that disclosure.

6.2 We are not responsible or liable for API Data once it has left the Software, or for any Connected System, except to the extent that the loss is caused or contributed to by our breach of the Agreement or of Applicable Law.

6.3 Our data security obligations under the Agreement apply only to Customer Data stored in the Online Services Environment. They do not apply to API Data in a Connected System.

6.4 You must have the legal authority, consents and notices required under the Privacy Act and any other Applicable Law to collect API Data and to transmit it to or from each Connected System using the API, including where the Connected System or its provider is located outside Australia or New Zealand.

6.5 You acknowledge that API Data will usually include Personal Information and Employee Records, and may include bank account details, tax file numbers, IRD numbers, remuneration and leave information.

6.6 You must handle API Data in each Connected System in accordance with the Privacy Act and any other Applicable Law, and keep API Data secure in transit and at rest.

6.7 You must notify us in writing within 24 hours if any API Credential is or may have been compromised, if there has been unauthorised access to or use of the API, or if there is or may have been a Security Breach or an Eligible Data Breach involving API Data.

6.8 We may log, monitor and analyse your use of the API, including call volumes, endpoints called, response times and error rates, and may use that information to operate and secure the API, detect misuse, calculate API Fees, provide support and improve our products and services.

6.9 You must keep a reasonable level of audit logs of your API Calls and, on our reasonable request, provide them to us to assist in the investigation and resolution of any issues or incidents involving the API.

6.10 On reasonable written notice, and no more than twice in any 12 month period, you must give us the information we reasonably request to verify your compliance with these API Terms, including a description of your Integration, the endpoints and data fields it uses and the Connected Systems it connects to.

6.11 The API operates only as a transfer mechanism for API Data. We do not check, validate, cleanse, correct or verify the accuracy, completeness, quality, format, security or legality of any API Data transmitted using the API, and are not obliged to do so.

6.12 You are responsible for all Inbound Data, including its accuracy, completeness, quality, format, security and legality (including that it is free from any virus or other harmful code), and for ensuring that Inbound Data complies with the requirements of the API Documentation before it is transmitted to the Software.

6.13 We are not responsible or liable for any loss caused by Inbound Data, including any Inbound Data that is inaccurate, incomplete, malformed or unauthorised, except to the extent that the loss is caused or contributed to by our breach of the Agreement or of Applicable Law.

7. Availability, changes and suspension

7.1 We will use reasonable endeavours to make the API available. We do not commit to any level of availability, response time or throughput for the API. Unless your Order Form states otherwise, the API is not included in the target availability level for the Online Services under the Agreement, and unavailability of the API is not counted in the calculation of that availability level.

7.2 We may change, add to, replace, version or withdraw any part of the API, including individual endpoints and data fields. We do not guarantee that any change to, or version of, the API will be backward compatible with any earlier version, unless we state otherwise in writing. You must keep your Integration on a version of the API that we support. We are not responsible for any failure of your Integration caused by a change we make.

7.3 We may suspend, throttle or restrict your access to the API, or deactivate API Credentials, if your API Calls materially exceed your Call Allowance or any rate limit, or if we reasonably suspect a breach of these API Terms. Our rights under the Agreement to suspend the Services on security grounds, and to suspend or remove access for overdue amounts, also apply. We will limit any suspension to what is reasonably necessary and lift it as soon as we reasonably can.

8. Ending the API Service

8.1 The termination provisions of the Agreement apply to the Order Form for the API Service. The API Service also ends automatically if the Agreement ends, or if the Order Form for the Software to which the API Service relates ends.

8.2 We may terminate the API Service by giving you at least six months’ written notice if we stop offering the API generally.

8.3 On termination or expiry of the API Service you must stop making API Calls, we will deactivate your API Credentials, and you remain responsible for API Data already held in any Connected System.

8.4 API Fees already paid are not refundable, except as required by Applicable Law, clause 3.4 of these API Terms or the provisions of the Agreement that entitle you to a refund if you terminate because we change its terms.

8.5 Termination of the API Service does not affect the rest of the Agreement or any other Order Form.

9. Definitions

In these API Terms:

AI Model means any artificial intelligence, machine learning, neural network, large language model, foundation model or generative model, and any pre-trained, fine tuned, custom or composite model used with any of them, whether developed or hosted by you or a Third Party.

API means the application programming interface for the Software that we make available to you as part of the API Service, including the endpoints described in the API Documentation.

API Call means a request to an endpoint of the API, counted in accordance with clause 3.2.

API Credentials means the keys, secrets, tokens, certificates and other credentials we issue to you or your Nominated Integrator to access the API.

API Data means Customer Data that is accessed, retrieved, received, transmitted or derived through the API.

API Documentation means the technical documentation, specifications, security requirements and usage policies for the API that we publish or give to you from time to time, including the Swagger documentation. API Documentation is Documentation for the purposes of the Agreement.

API Fees means the Fees for the API Service set out in the Order Form. API Fees are Fees for the purposes of the Agreement.

API Service means the service described in clause 2.1.

Call Allowance means the maximum number of API Calls per calendar month for your Tier, as set out in the Schedule.

Connected System means any Other Application, system or environment outside the Software to or from which API Data is transmitted using the API, or in which API Data is stored or processed.

Inbound Data means API Data that you or your Nominated Integrator transmit, or cause to be transmitted, into the Software using the API.

Integration means the software, configuration and processes that you or your Nominated Integrator use to connect a Connected System to the API.

Nominated Integrator means a Third Party that you engage to build, operate or maintain your Integration and that we have accepted under clause 5.1.

Permitted Purpose has the meaning given in clause 2.3.

Tier means the API tier stated in the Order Form.

Schedule – Tiers and Call Allowances

Tier

Call Allowance (per calendar month)

API access

Core API (Tier 1)

Up to 50,000 API Calls

All endpoints published in the API Documentation

Extended API (Tier 2)

Up to 300,000 API Calls

All endpoints published in the API Documentation

API Fees for each Tier are set out in the Order Form. API Fees and Call Allowances apply per database or site.

Published July 2026.