Guides
Authentication
The 18 endpoints on this site need no credentials. There are no API keys to request and no Authorization header to send.
Public endpoints#
Every documented endpoint returns only what Rankd already shows to someone who is not signed in:
- Profiles only of people who chose to be discoverable.
- Ratings, reviews and lists only when they are public. Private and followers-only content is never returned, and is never counted in community numbers.
- Nothing personal: fields such as
community.myRatingare alwaysnull, and the feed is the community’s, not anyone’s own (meta.personalizedisfalse).
If you do send an Authorization header to a public endpoint and the token is not valid, it is ignored and the request is answered as a public one.
Everything else#
The rest of the Rankd API (someone’s own ratings, following, notifications, writing reviews and so on) belongs to Rankd’s own apps. It needs a Rankd session, which is issued only when someone signs in to a Rankd app. Called without one, it answers:
{
"error": {
"code": "unauthenticated",
"message": "A Rankd session or operator token is required."
}
}Rankd does not offer API keys, OAuth or any other way for a third-party app to act for a Rankd user today. Do not ask people for their Rankd password or copy a session token out of a Rankd app: sessions are short-lived, tied to Rankd’s apps, and using them elsewhere is not supported.
Calling from a browser#
The API does not send CORS headers, so a web page on another site cannot read its responses. Call it from your server, a serverless function or a native app, and pass the results to your page. Images at /v1/assets/… are the exception: they allow any origin, so you can use avatarUrl directly in an <img> tag.
The Try it panels on this site work because this site calls the API from its own server, with no credentials, and only for the documented endpoints.
Keeping it safe#
- Always use
https://. - Treat everything the API returns as untrusted text: escape display names, bios, list titles and review bodies before putting them in HTML.
- Cache what you can. Public content changes slowly, and caching keeps you well under the rate limit.