Get started/Authentication & scopes

Authentication & scopes

Every request needs a Bearer API key, scoped to exactly the resources it's allowed to touch.

Generate a key from Settings → API Keys. The full key is shown once — copy it somewhere safe, RideLoop only ever stores its hash after that.

const response = await fetch('https://your-rideloop-domain/api/v1/bookings?limit=…', {
method: 'GET',
headers: {
Authorization: 'Bearer rlk_...',
},
})
const data = await response.json()

Scopes

Each key is granted specific scopes when it’s created — a key with no matching scope for the endpoint it’s calling is rejected with a 403, regardless of what your plan otherwise allows. When creating a key, you pick access per resource:

  • Bookings — No access / Read only (bookings:read) / Read & write (also grants bookings:write). Write covers creating bookings and changing their status (including cancellation) — creating a Checkout session is intrinsic to booking creation, not a separate permission.
  • Fleet — No access / Read only (fleet:read).
  • Payment links — No access / Can create (payments:write). Kept separate from bookings:write deliberately — generating a payment link moves money against an existing booking, a more sensitive action than creating one.

Error responses

Every request goes through the same checks, in this order — see Errors & rate limits for the full error shape:

  • 401 — the key is missing from the Authorization header, or doesn’t match any active key.
  • 429 — the key has hit its rate limit (150 requests/minute, shared across every scope — see Errors & rate limits).
  • 403 — either your plan doesn’t include API access at all, or this specific key doesn’t carry the scope the endpoint needs.
  • 402 — only on a :write scope: your subscription has lapsed. Read access stays available regardless.