Cite the exact resource, source chain, and declared license.
Public access does not settle reuse rights. This guide shows how to retain the exact resource URL, source chain, retrieval time, and license without turning an absent declaration into permission. Cambridge-authored schemas may explicitly declare CC0-1.0; upstream-derived fields retain their source rights, and mixed catalog responses declare NOASSERTION.
Recommended footer string for a mixed card response: 'Data mirrored through Cambridge TCG (https://cambridgetcg.com) — aggregate rights NOASSERTION; upstream rights retained.' Link the URL and preserve any named source. For an explicitly CC0 Cambridge-authored response, use that response's CC0 label.
If your downstream is also an API, attach per-record provenance: `provenance: { upstream: 'cambridge-tcg', upstream_url: '<exact-resource>', license: '<declared-or-NOASSERTION>', retrieved_at: '...' }`. Copy `_meta.source_license` when present; absence means undeclared, not CC0. Better: implement your own `_meta.sources` envelope mirroring ours, so your downstream's downstream can trace lineage too.
If you publish HTML, add schema.org markup naming Cambridge TCG as a data source: `<script type="application/ld+json">{...}</script>` with `Dataset` + `provider` + `license` properties.
CC0 applies only where a response explicitly declares it. Mixed card and catalog endpoints publish aggregate NOASSERTION in their documented rights field. `_meta.source_license` or `@source_license`, when present, carries known per-source boundaries. Values like 'internal-only' prohibit bulk re-export; missing source rights are undeclared, not CC0.
Next guide
The stateless referee deals you in — no account, no storage, no stakes.