Lyft · Authentication Profile

Lyft Authentication

Authentication

Lyft secures its APIs with apiKey and http across 2 declared security schemes, as derived from its OpenAPI definitions.

TransportationMobilityRide HailingMicromobilityBike ShareScootersGBFSLogisticsTravel
Methods: apiKey, http Schemes: 2 OAuth flows: API key in: header

Security Schemes

bearerAuth http
scheme: bearer
clientToken apiKey
· in: header (Authorization)

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: probed
source: https://api.lyft.com/.well-known/oauth-authorization-server (live RFC 8414 metadata) + openapi/lyft-concierge-rides-api-openapi.yml,
  openapi/lyft-cost-estimates-api-openapi.yml, openapi/lyft-drivers-api-openapi.yml, openapi/lyft-eta-api-openapi.yml,
  openapi/lyft-profile-api-openapi.yml, openapi/lyft-ride-types-api-openapi.yml, openapi/lyft-rides-api-openapi.yml
summary:
  types:
  - apiKey
  - http
  api_key_in:
  - header
schemes:
- name: bearerAuth
  type: http
  scheme: bearer
  description: OAuth 2.0 access token obtained through the client credentials flow for the organization's concierge
    API client.
  sources:
  - openapi/lyft-concierge-rides-api-openapi.yml
  - openapi/lyft-cost-estimates-api-openapi.yml
  - openapi/lyft-drivers-api-openapi.yml
  - openapi/lyft-eta-api-openapi.yml
  - openapi/lyft-profile-api-openapi.yml
  - openapi/lyft-ride-types-api-openapi.yml
  - openapi/lyft-rides-api-openapi.yml
- name: clientToken
  type: apiKey
  in: header
  parameter: Authorization
  description: Client token for accessing public endpoints without user authorization. Passed as a Bearer token
    in the Authorization header.
  sources:
  - openapi/lyft-cost-estimates-api-openapi.yml
  - openapi/lyft-drivers-api-openapi.yml
  - openapi/lyft-eta-api-openapi.yml
  - openapi/lyft-profile-api-openapi.yml
  - openapi/lyft-ride-types-api-openapi.yml
  - openapi/lyft-rides-api-openapi.yml
oauth:
  issuer: https://api.lyft.com
  authorization_endpoint: https://api.lyft.com/oauth/authorize
  token_endpoint: https://api.lyft.com/oauth/token
  grant_types_supported:
  - authorization_code
  - client_credentials
  - refresh_token
  response_types_supported:
  - code
  token_endpoint_auth_methods_supported:
  - client_secret_basic
  - none
  code_challenge_methods_supported:
  - S256
  pkce: 'S256 required for public clients (code_challenge_methods_supported: [S256]); token_endpoint_auth_methods_supported
    includes "none", which is the public-client case PKCE protects'
  scope_count: 47
  scopes: scopes/lyft-scopes.yml
  discovery_document: well-known/lyft-oauth-authorization-server.json
  metadata_spec: RFC 8414
  source: https://api.lyft.com/.well-known/oauth-authorization-server
flows:
- name: client_credentials
  use: Two-legged, for public endpoints that need no user context (cost, eta, ridetypes, drivers). Matches the clientToken
    scheme in the specs.
  evidence: https://api.lyft.com/.well-known/oauth-authorization-server
- name: authorization_code
  use: Three-legged, for user-context endpoints (profile, rides) and the concierge surface.
  evidence: https://api.lyft.com/.well-known/oauth-authorization-server
- name: refresh_token
  use: Token renewal; the published vocabulary includes an "offline" scope.
  evidence: https://api.lyft.com/.well-known/oauth-authorization-server
openid_connect:
  scopes_advertised:
  - openid
  - profile
  - profile.email
  - profile.phone
  discovery_document_served: false
  evidence: GET https://api.lyft.com/.well-known/openid-configuration -> 404 on 2026-09-17, while the OAuth 2.0
    metadata document at the sibling path returns 200.
  note: OIDC scopes are advertised without an OIDC discovery document, so a client cannot resolve jwks_uri or userinfo_endpoint
    anonymously.
docs: null
docs_note: Lyft publishes no anonymously readable authentication reference. https://www.lyft.com/developers 302s
  to https://account.lyft.com/auth/email; developer.lyft.com (cited by every Lyft SDK README) is NXDOMAIN.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lyft-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.