A rider’s own rides
What a rider leads, is going to, rode or saved, which of their friends are going, and anyone they flagged who’s going, is theirs. To read it, the rider signs in to Biiikes and says yes to your app. You then send their token instead of your key.
How signing in works
Section titled “How signing in works”Biiikes uses OAuth 2.1 with PKCE, the same sign-in AI assistants use.
- Your app is identified by a client ID metadata document: a JSON file at an
httpsaddress you control, naming your app and the addresses riders can be sent back to. Its address is yourclient_id. - Send the rider to Biiikes to sign in and approve, with
resource=https://biiikes.com/apiandscope=read. - Exchange the code for tokens. The access token lasts an hour; the refresh token gets you a new one, and is replaced each time you use it.
- Call the rider’s operations with
Authorization: Bearer <token>.
Biiikes publishes where everything is at
/.well-known/oauth-authorization-server,
and a request without a token gets a 401 that points there.
What a rider can see and end
Section titled “What a rider can see and end”A rider sees your app on their account under Apps and assistants, with when it connected and was last used, and can disconnect it at any time. Their token then stops working on its next request. A connection nobody uses for 30 days ends by itself.
Your app can only read. It can’t say a rider is going, save a ride or change anything.