Information
- OpenAPI version:
3.1.0
Group bike rides. Public reads need a developer key in the X-Api-Key header, or a rider’s sign-in token; a rider’s own layer needs their sign-in. The contract only grows within a major version: no field is removed, renamed, retyped or made nullable (ADR-0013). 2.0.0 is the one deliberate break: it requires the key (decision 1204).
OAuth 2.1 with PKCE, issued by this origin’s authorization server for the resource /api (ADR-0027).
Security scheme type: oauth2
Flow type: authorizationCode
Authorization URL: /oauth/authorize
Token URL: /oauth/token
Refresh URL: /oauth/token
Scopes:
A developer key, made on your Biiikes account under Developer keys and shown once (decisions 1202, 1204).
Security scheme type: apiKey
Header parameter name: X-Api-Key