Skip to content

A rider’s own rides

What a rider leads, is going to, rode or saved, which of their friends are going, and anyone they flagged who’s going, is theirs. To read it, the rider signs in to Biiikes and says yes to your app. You then send their token instead of your key.

Biiikes uses OAuth 2.1 with PKCE, the same sign-in AI assistants use.

  1. Your app is identified by a client ID metadata document: a JSON file at an https address you control, naming your app and the addresses riders can be sent back to. Its address is your client_id.
  2. Send the rider to Biiikes to sign in and approve, with resource=https://biiikes.com/api and scope=read.
  3. Exchange the code for tokens. The access token lasts an hour; the refresh token gets you a new one, and is replaced each time you use it.
  4. Call the rider’s operations with Authorization: Bearer <token>.

Biiikes publishes where everything is at /.well-known/oauth-authorization-server, and a request without a token gets a 401 that points there.

A rider sees your app on their account under Apps and assistants, with when it connected and was last used, and can disconnect it at any time. Their token then stops working on its next request. A connection nobody uses for 30 days ends by itself.

Your app can only read. It can’t say a rider is going, save a ride or change anything.