Get started/Authentication & scopes
Every request needs a Bearer API key, scoped to exactly the resources it's allowed to touch.
Generate a key from Settings → API Keys. The full key is shown once — copy it somewhere safe, RideLoop only ever stores its hash after that.
const response = await fetch('https://your-rideloop-domain/api/v1/bookings?limit=…', {method: 'GET',headers: {Authorization: 'Bearer rlk_...',},})const data = await response.json()
Each key is granted specific scopes when it’s created — a key with no matching scope for the endpoint it’s calling is rejected with a 403, regardless of what your plan otherwise allows. When creating a key, you pick access per resource:
bookings:read) / Read & write (also grants bookings:write). Write covers creating bookings and changing their status (including cancellation) — creating a Checkout session is intrinsic to booking creation, not a separate permission.fleet:read).payments:write). Kept separate from bookings:write deliberately — generating a payment link moves money against an existing booking, a more sensitive action than creating one.Every request goes through the same checks, in this order — see Errors & rate limits for the full error shape:
Authorization header, or doesn’t match any active key.:write scope: your subscription has lapsed. Read access stays available regardless.