Skip to content

Overview

Group bike rides. Public reads need a developer key in the X-Api-Key header, or a rider’s sign-in token; a rider’s own layer needs their sign-in. The contract only grows within a major version: no field is removed, renamed, retyped or made nullable (ADR-0013). 2.0.0 is the one deliberate break: it requires the key (decision 1204).

Information

  • OpenAPI version: 3.1.0

OAuth 2.1 with PKCE, issued by this origin’s authorization server for the resource /api (ADR-0027).

Security scheme type: oauth2

Flow type: authorizationCode

Authorization URL: /oauth/authorize

Token URL: /oauth/token

Refresh URL: /oauth/token

Scopes:

  • read - The calendar, the rider's nights, which of their friends are going, and anyone they flagged who is going

A developer key, made on your Biiikes account under Developer keys and shown once (decisions 1202, 1204).

Security scheme type: apiKey

Header parameter name: X-Api-Key