Guaca

Terms of service

What you agree to by using this site.

Last updated 23 August 2026.

These cover guaca.bot: this site, and the connector account you can make on it. They do not cover the Guaca app. That is free software under AGPL-3.0, and your rights to it come from that license rather than from anything here.

What the service is

A token broker. You authorize a service, this origin keeps the grant, and a copy of Guaca you signed in can ask it for a short-lived access token. That is all it does. It exists because a service that only issues access to a registered application will not issue it to an app running on your own machine.

It is free. There is nothing to pay for, no plan, and no service level: it is one person's project, it is early, and it can be unavailable without warning.

The account

Give an address you control and enter the code that arrives. That first code creates the account; there is no separate sign-up and no password.

Anyone who can read that mailbox can sign in as you. Use an address you protect accordingly, and use one that is yours. Do not make an account if you are under 16.

What authorizing actually grants

Ticking a capability grants access to your account at that provider, at the scope printed on the card, to every machine you have signed in. Agents then act as you. Mail one sends comes from you. A commit one pushes is yours. Grant what you would grant a new colleague on their first day, and take it back when the work is done.

A sign-in starts in Guaca on your own machine and finishes in your browser. Only approve one you started that way. Nothing else can open that screen, and a link that arrived in a message did not come from your copy of the app.

Your agents are your responsibility

What they do with the access you granted is yours: what they send, what they change, what they spend, what they agree to on your behalf. Guaca stops and asks before acting as you, and that check is worth exactly as much attention as you give it.

This site issues a token you asked for, to a machine you signed in. It cannot see what is done with it and is in no position to judge it.

Using it fairly

  • Do not use it to break the law, or the terms of a provider you authorized.
  • Do not try to reach an account, a grant or a token that is not yours.
  • Do not automate the sign-in form or the API past what one person's use looks like.
  • Do not use a connector to send bulk or unsolicited mail.
  • Do not probe or attack the service. Security research is welcome if you say so first, at robert@madebywelch.com.

An account doing any of that is suspended or removed, without notice where it is doing damage.

The providers set their own terms

Google and GitHub decide what a scope allows, and can narrow it, revoke it or withdraw the application entirely. If they do, the connector stops working and there is nothing this site can do about it. Their terms and their privacy policies govern everything that happens on their side.

No warranty

The service is provided as it is, with no warranty of any kind: not that it will be available, not that it will keep working, not that a grant will survive, not that data will not be lost. Do not make it the only route to anything you cannot afford to lose.

Liability

To the fullest extent the law allows, the operator is not liable for loss or damage arising from this service, including anything an agent does with access you granted, and including a provider outage, a revoked grant or a token that stops working. Where the law does not allow that, liability is limited to the least the law permits. The service is given away for nothing, which is the context for that sentence.

Ending it

You can stop at any time. Disconnect each provider, which revokes the token at the provider as well as here, then ask for the account to be deleted; the privacy policy says how.

The operator can suspend or remove an account that breaks these terms, and can shut the service down altogether. If it shuts down, notice goes up here first, and the safe move is to revoke Guaca's access at each provider yourself rather than trust that anything here got the chance to.

Changes

The date at the top changes when this text does. Using the service after a change is accepting it. If a change is one you will not accept, disconnect your providers and ask for the account to be deleted.

Privacy

The privacy policy says what is stored, for how long, and who else sees it. It is part of these terms.

Contact

robert@madebywelch.com. Questions about these terms, abuse reports and security reports all go there.