To retrieve data from the Strava API, you must first authenticate with Strava. This page provides you with the
information required to set up authentication with Strava.
Step 1: Create an application in your Strava account#
First, create a new application in your Strava account. To do this:
Login to your Strava account
Go to settings –> My API Application
Create a new application in your account
The above image shows the Strava API create application page. Here, the website url is “localhost.” This value can be any if you authenticate to gain local access to your Strava data. But if you plan to build a web application, you should place the URL of your application in that field.#
An image from the Strava documentation page shows what your API page will look like after creating your app above. For the step below, you will need the Client ID value provided in your app.#
Once you have the URL value, you can display it in your web application to allow athletes to authorize your
application to read their data. If you are trying to authenticate locally,
paste the URL into your browser to support exchanging the
temporary code Strava provides for a temporary access token.
While the above URL, a local development URL, may look like a broken link in your browser, it is correct. Notice the code=longstringhere in the URL. Next, you will exchange that code value for a token.
The token is what you will
use to access your (or a user’s if they authenticate using your app)
Strava data.
Return to your Strava app on the Strava website and copy the Client Secret value.
Use the Client Secret value with the client_id value in client.exchange_code_for_token().
token_response=client.exchange_code_for_token(client_id=MY_STRAVA_CLIENT_ID,client_secret=MY_STRAVA_CLIENT_SECRET,code=code)# The token response above contains both an access_token and a refresh token.access_token=token_response["access_token"]refresh_token=token_response["refresh_token"]# You'll need this in 6 hours
The resulting access_token is valid until the specified expiration time; for Strava, this time is 6 hours,
specified as unix epoch seconds. You can see the expiration time by looking at the expires_at field of the returned token.
Alternatively, you or a user can explicitly revoke application access.
Tip
You can store this token value to access the account data for up to 6 hours into the future without requiring re-authorization. However, you must refresh the token after the 6-hour expiration period.
Once you have an access token, you can begin to interact with the Strava API
to access user data for the authenticated account.
fromstravalibimportClientclient=Client(access_token=STORED_ACCESS_TOKEN)client.get_athlete()# Get current athlete details
A token is valid for 6 hours. After that time period, you need to refresh it if you want to continue to interact with the Strava API. There are two ways that you can do this:
STRAVA_CLIENT_ID should always be an integer. STRAVA_CLIENT_SECRET is always a string.
Once you have setup the client_id and client_secret values in your environment, one way to retrieve them is to use the python_dotenv package.
The workflow will look something like this:
pipinstallpython-dotenv
# In this example you have stored your token refresh data in a `.json` fileimportjsonimportosfromdotenvimportload_dotenvfromstravalibimportClient# Open and access the toke_refresh data# You will populate this when you instantiate a client object belowjson_path=os.path.join("path","to","json")withopen(json_path,"r")asf:token_refresh=json.load(f)# Read the STRAVA_CLIENT_ID and STRAVA_CLIENT_SECRET environment variablesload_dotenv()print("Expires at",token_refresh["expires_at"])# Instantiate a client object, including your access_token, refresh_token, and token_expires values# These values, if available, will allow stravalib to check if it needs to refresh the token for you when it makes an API call using the client objectclient=Client(access_token=token_refresh["access_token"],refresh_token=token_refresh["refresh_token"],token_expires=token_refresh["expires_at"],)athlete=client.get_athlete()print(f"Hi, {athlete.firstname} Welcome to stravalib!")print(client.token_expires)
fromstravalibimportClient# Set STRAVA_CLIENT_ID and STRAVA_CLIENT_SECRET in your environment first.client=Client(refresh_token=STORED_REFRESH_TOKEN)client.deauthorize()
This uses Strava’s /oauth/revoke endpoint, which requires your application’s
client ID and secret as well as the athlete’s refresh or access token. Set
STRAVA_CLIENT_ID and STRAVA_CLIENT_SECRET before constructing the client,
as described in the automatic token refresh setup above. Credentials passed
to exchange_code_for_token() or refresh_access_token() are not stored for
later calls. Missing credentials or the absence of both tokens raises
ValueError before a request is sent.
The method prefers the refresh token because Strava may not recognize an
expired access token. If no refresh token is available, it uses the access
token. It sends the matching token_type_hint without refreshing the token
first and returns None on success. Revocation invalidates the associated
access and refresh tokens on Strava. Discard your stored tokens after success;
this method does not clear tokens held locally by the client or your application.
The method name remains deauthorize(); applications that previously supplied
only an access token must now also configure the client credentials.
Congratulations! You now know how to authenticate with the Strava API using stravalib.