Skip to content
ridekickDevelopersv1 · 2026-10-13

Authentication

The reads accept the buyer's own signed-in Ridekick session. A connected assistant's grant is accepted on the two reads. There is no API key.

Send the session you signed in with

Sign in at ridekick.com, then send the session cookie with each request. Every read is scoped to that buyer.

Send an assistant's token

A buyer's assistant sends the access token the buyer gave it, as Authorization: Bearer <token>. The reads need the offers:read scope. The token is judged on its own: a cookie sent beside it is not read. A token that is not valid is refused with 401 unauthenticated and a WWW-Authenticate challenge. A token without the scope is refused with 403 insufficient_scope. See Errors.

Any other Authorization header is refused

Any other non-blank Authorization header is refused before the session is read, even with a cookie beside it. The answer is 401 unauthenticated.

What a read leaves behind

Each read an assistant makes leaves one audit record. It names what was read (a count, or the request's id), not the offers' contents. If the record cannot be saved, the read is refused with 503 unavailable and returns nothing. The buyer's own reads leave no such record.

An assistant does not show a new tool

ChatGPT reads our list of tools once, when the connector is added. Refreshing the connector does not read it again, and neither does disconnecting and reconnecting. If a new tool, or a change in what the buyer's account may use, is missing, the connector can be deleted in ChatGPT and added again. The earlier connection stays in Ridekick Settings until it is disconnected there. Last checked 2026-10-07 on a buyer's account.

Last updated