Short answer: the Strava API still works, but on 1 June 2026 it stopped being free, open-ended infrastructure. A Standard tier app now needs its developer to hold a Strava subscription, starts with exactly one athlete, can grow to ten without anyone at Strava looking at it, and needs a review to go further [1][2]. Routing Strava data through a third-party platform is no longer allowed at all [1][3]. Three club endpoints are already gone, and a base URL change and token migration are due by 1 June 2027 [1][4].
Strava’s stated reasons are blunt. Its developer count rose from 185,000 to 241,000 in a year, applications were up 448% year to date, and AI scrapers and intermediary platforms were degrading the service and breaking its terms [1]. The company has also confidentially filed for an IPO, which tends to focus attention on who gets to use the data [5].
This post lays out every change and its date, what each means for an app in production, and the alternatives if the API no longer fits what you are building.
What changed on 1 June 2026?
Strava replaced its old application queue with two tiers [1][2]:
- Standard. Every current and future app is placed here automatically. It covers people building for themselves or a small group, and apps up to 9,999 athletes once they pass review.
- Extended Access. For larger commercial apps. Every application is reviewed, and approved apps get higher rate limits, more athlete capacity, prioritised support and eligibility for Strava’s partner APIs.
Four rules came with the tiers:
- A subscription is required for Standard. From 1 June 2026 for new Standard developers and from 30 June 2026 for existing ones. Active developers without a subscription were sent a code for three months free. Extended Access developers are exempt [1]. Strava’s FAQ is explicit that the subscription is the fee: “there is no additional fee” for API access on top of it [2].
- Capacity is earned, not requested. New apps start at one athlete and self-upgrade to ten. Beyond that, see below.
- Intermediaries are out. Covered in its own section.
- The athlete’s own data stays free. Athletes can still download their data at any time, and device integrations such as watch sync are not affected [1][2].
How many athletes can an app serve, and how fast?
Capacity and rate limits now move together [4][6]:
| Stage | Athletes | Overall limit | Read limit | Review |
|---|---|---|---|---|
| Single Player mode (default) | 1, the developer | 200 per 15 min, 2,000 per day | 100 per 15 min, 1,000 per day | No |
| Self-service upgrade | Up to 10 | 400 per 15 min, 4,000 per day | 200 per 15 min, 2,000 per day | No |
| Standard after review | Up to 9,999 | Set by Strava | Set by Strava | Yes |
| Extended Access | 10,000 and above | Higher limits | Higher limits | Yes |
Three details matter in production:
- Limits are per application, shared by every connected athlete. A 10-athlete app polling each athlete every few minutes will hit 4,000 a day faster than it looks. Strava’s webhook events announce new and updated activities, so you fetch only what changed [6][11].
- Windows reset on the clock. The 15-minute window resets at :00, :15, :30 and :45, and the daily window at midnight UTC. Requests that fail the short-term limit still count against the daily one, and a breach returns HTTP 429 [6].
- Growth is at Strava’s discretion. Until an app passes review, no eleventh athlete can authenticate. Strava’s FAQ says it reviews “on a case by case basis” and that increased access “is not a guarantee” [2]. The policy says the same of rate limit increases [3]. Plan launches around that, not around a date.
Can I still use an aggregator or integration platform?
No. This is the change most likely to break a working product without a code change.
- The announcement: apps that route Strava data through third-party intermediary platforms “are no longer supported”, because those platforms prevent Strava from verifying how athlete data is accessed and used downstream. Direct integrations are not affected, and affected apps were emailed separately [1].
- The FAQ: entering your API credentials on a third-party intermediary is a “non-compliant use case” [2]. That closes the common workaround of registering your own Strava app and pasting its client ID and secret into someone else’s platform.
- The policy: section 5.16(a) prohibits operating as a “pass-through proxy, intermediary, or aggregator that re-exposes the Strava API Materials”, and section 5.10 bars transferring Strava data to third parties except as the agreement permits [3].
If your Strava data reaches you through a unified wearable API today, check with that vendor what Strava has told them, and read your own copy of the policy rather than theirs.
Which endpoints are gone?
From the changelog, effective 1 September 2026 [4]:
- Removed: Club Activities, Club Members and Club Admins. Strava said community use did not justify maintaining them [1].
- Restricted: Explore Segments, now available only to approved Extended Access apps with a qualifying use case. A Standard subscription does not unlock it [1][4].
- Still available: club details and the authenticated athlete’s own list of clubs. Neither replaces a club feed or roster.
Club leaderboards, team dashboards and segment discovery features built on those endpoints need a different design, not a patch.
What must change in code before June 2027?
Three migrations, with the hard deadline set in Strava’s announcement [1][4][7]:
- New base URL. The changelog lists
https://api-v3.strava.com, available from 4 January 2027, replacinghttps://www.strava.com/api/v3. Keep the current host until then. (The announcement writes the new host with awww.prefix; the changelog does not. Confirm against the docs when it goes live.) - Tokens in the header only. Resource requests must send
Authorization: Bearer <access_token>rather than passing tokens as form parameters, by 1 June 2027. - Revoke, not deauthorize.
POST /oauth/revokeis available now and becomes the only deauthorization endpoint on 1 June 2027. It uses HTTP Basic auth with your client ID and secret.
# Resource request, header token
curl -H "Authorization: Bearer $ACCESS_TOKEN" \
https://www.strava.com/api/v3/athlete/activities?per_page=30
# Revoke a user's grant (replaces oauth/deauthorize)
curl -X POST https://www.strava.com/oauth/revoke \
-u "$CLIENT_ID:$CLIENT_SECRET" \
-d token="$REFRESH_TOKEN" \
-d token_type_hint=refresh_tokenRevoke returns an empty HTTP 200 whether or not the token existed, and revoking a refresh token also revokes its access tokens [7]. Wire it into account deletion now, because the policy also sets a deletion deadline.
Which policy rules bite in production?
The API Policy effective 1 June 2026 is the document that governs your app [3]. Five clauses shape architecture more than any endpoint change:
- Show athletes only their own data. Sections 2.3 and 6.1 limit display of Strava data to the user it relates to. Leaderboards and coach views across users need careful reading or Strava’s written approval.
- Cache for seven days at most. Section 6.2 caps cached Strava data at seven days, and section 6.4 allows keeping data only as long as needed for the original purpose.
- Delete within 30 days of a revoked grant. Section 7.4 requires deletion “expeditiously” and in any event within 30 days when an athlete deauthorizes your app.
- No AI, including at inference. Section 5.3 prohibits using Strava data in any AI application, listing retrieval-augmented generation and “ingestion into a context window or working memory”, with an exception only for Strava’s own MCP. Strava first banned AI use of API data in November 2024 [10]. We compared this with Oura, Garmin and WHOOP in Can you feed wearable data to an AI?
- Attribute Garmin. Section 4.4 requires attribution to Garmin, in the form Garmin’s brand guidelines require, when you show data recorded on a Garmin device.
What are the alternatives if the API no longer fits?
1. Read Strava activities from the phone’s health store. Strava writes completed activities to Apple Health and Health Connect, so an app with the user’s permission can read them without a Strava developer account, subscription or athlete cap [8][9]. The trade-off is depth:
| Apple Health (iOS) | Health Connect (Android) | |
|---|---|---|
| What Strava writes | Activity type, time, distance, calories, route | Time, distance, calories |
| Which activities | All, but routes from other companies’ apps or devices are left out | GPS-based activities only |
| Heart rate | Not listed by Strava | Not listed by Strava |
| Needs | A native iOS app with HealthKit permission | A native Android app with Health Connect permission |
Indoor rides, treadmill runs and strength sessions logged in Strava do not reach Health Connect, and neither store gets segments, kudos or Strava’s social data. If an Apple Watch recorded the workout, its heart rate is already in Apple Health under the watch as the source.
2. Go to the device that recorded the activity. Most Strava uploads start on a Garmin, COROS, Wahoo, Polar or Apple Watch. Their own APIs or the phone’s health store often carry more than Strava passes on, including full heart rate streams. Garmin’s program has its own constraints, covered in Garmin paused its developer program.
3. Stay on the API and apply for Extended Access if Strava-specific data, such as segments or the social graph, is the product, and plan for the review to take as long as it takes.
A checklist for teams with a Strava integration
- Confirm your tier and capacity in the API settings dashboard, and that the account that owns the app holds an active subscription [1].
- Check your data path. If Strava data reaches you through any third party, get Strava’s position in writing before your users notice [1][2][3].
- Replace polling with webhooks and budget rate limits per app, not per user [6][11].
- Remove club and Explore Segments dependencies, which are already gone for Standard apps [4].
- Ship the header and revoke changes now and schedule the base URL switch for after 4 January 2027 [1][4][7].
- Audit storage and display against the seven-day cache, own-data display and 30-day deletion rules [3].
- Keep Strava data out of prompts, embeddings and model pipelines [3].
The short version
On 1 June 2026 Strava turned its API into a gated program: a subscription for Standard developers, 1 athlete by default, 10 without review, review beyond that, and no third-party intermediaries [1][2][3]. Club endpoints went on 1 September 2026, the new base URL arrives on 4 January 2027, and header tokens and oauth/revoke are mandatory from 1 June 2027 [1][4][7]. The policy limits display to each athlete’s own data, caching to seven days and AI use to none [3]. Teams that only need workouts can read what Strava writes to Apple Health and Health Connect, with less detail but none of the gates [8][9].
References
- Strava. An Update To Our Developer Program. Strava Community Hub, 1 June 2026. Retrieved 9 October 2026. https://communityhub.strava.com/insider-journal-9/an-update-to-our-developer-program-13428
- Strava. Strava API FAQ. Strava Community Hub. Retrieved 9 October 2026. https://communityhub.strava.com/developers-knowledge-base-14/strava-api-faq-12906
- Strava. API Policy, effective 1 June 2026, sections 2.3, 3.3, 3.6, 4.4, 5.3, 5.10, 5.16, 6.1, 6.2, 6.4 and 7.4. Retrieved 9 October 2026. https://www.strava.com/legal/api_policy
- Strava. Strava V3 API Changelog. Strava Developers. Retrieved 9 October 2026. https://developers.strava.com/docs/changelog/
- Fintool. Strava confidentially files for IPO, taps Goldman Sachs. January 2026. https://fintool.com/news/strava-ipo-confidential-filing-goldman
- Strava. Rate Limits. Strava Developers. Retrieved 9 October 2026. https://developers.strava.com/docs/rate-limits/
- Strava. Authentication: Deauthorization and Revoke. Strava Developers. Retrieved 9 October 2026. https://developers.strava.com/docs/authentication/
- Strava Support. Apple Health and Strava. Retrieved 9 October 2026. https://support.strava.com/en-us/articles/15402024-apple-health-and-strava
- Strava Support. Health Connect and Strava. Retrieved 9 October 2026. https://support.strava.com/en-us/articles/15401554-health-connect-and-strava
- Strava. Updates to Strava’s API Agreement. Strava press, 15 November 2024. https://press.strava.com/articles/updates-to-stravas-api-agreement
- Strava. Webhook Events API. Strava Developers. Retrieved 9 October 2026. https://developers.strava.com/docs/webhooks/