Product

Strava BYO: why we don't ask for full OAuth

Most apps that touch Strava require deep OAuth access. We chose Bring-Your-Own — and here's the reasoning.

By Tom Riley 20 March 2026 5 min

Strava's full OAuth scope gives apps access to every activity, friend, club and segment in your account. For a planning tool, that's overkill — and a privacy ask we weren't willing to make.

Strava BYO uses a narrow read-only flow scoped to your activity feed. We can pull what you ran without browsing your social graph or seeing private routes you haven't published.

The trade-off is a slightly slower onboarding for power users. The win is that your Strava data stays your Strava data — and we sleep better at night.