cURL
curl -X GET "https://api.fitsociety.io/public/v1/capabilities" \
-H "Authorization: Bearer <access_token>"const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.fitsociety.io/public/v1/capabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/capabilities"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"data": {
"capabilities": {
"scopes": [
{
"value": "string",
"requiredConsents": [
"health"
],
"requiresConsent": "health"
}
],
"endpoints": [
{
"method": "string",
"path": "string",
"scope": "string"
}
]
}
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
}
}
}Public API client
List Public API capabilities
Requires platform:read. Lists available Public API scopes and OAuth Bearer resource endpoints, including Workout V2. Nutrition and AI endpoints are excluded from this v1 catalog.
GET
/
public
/
v1
/
capabilities
cURL
curl -X GET "https://api.fitsociety.io/public/v1/capabilities" \
-H "Authorization: Bearer <access_token>"const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.fitsociety.io/public/v1/capabilities', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.fitsociety.io/public/v1/capabilities"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text){
"data": {
"capabilities": {
"scopes": [
{
"value": "string",
"requiredConsents": [
"health"
],
"requiresConsent": "health"
}
],
"endpoints": [
{
"method": "string",
"path": "string",
"scope": "string"
}
]
}
},
"meta": {
"requestId": "4f849d7d-f4f1-45cc-b4b7-3984a3d17f83",
"rateLimit": {
"limit": 10,
"remaining": 9,
"resetSeconds": 1
}
}
}Authorizations
Public API access token issued by /public/v1/oauth/token. Example: Authorization: Bearer fspt_.... Each resource request rechecks the token company's current provider access. Disabling access blocks existing tokens with 403 auth.provider_unavailable.