Skip to content

Getting started

  • Frontline (recommended). Native gRPC or gRPC-Web for rider apps, passenger displays, and maps: search stops, read arrivals, get route details, and stream live updates.
  • GTFS-RT. Binary GTFS Realtime feeds over HTTP: trip updates and vehicle positions. Choose it if your system already consumes GTFS Realtime. It is polling-only, and you need the matching static GTFS identifiers from your MyBusz contact.

Both require an access token with the frontline:consumer scope, so one service account can use either or both.

Ask your MyBusz contact to create a service account with the frontline:consumer scope. Decide its credential type first:

Public key (recommended) Client secret
Setup You send your public key; the private key stays with you The admin sends you a generated secret
Token grant urn:custom:nonce-challenge client_credentials
Frontline limit 200 requests/minute 60 requests/minute
GTFS-RT limit 10 requests/minute per feed 10 requests/minute per feed

Service accounts use only these two credentials. Passwords, TOTP, and passkeys are for human accounts. See rate limits for details.

You will receive:

  • CLIENT_ID, plus CLIENT_SECRET for a secret-based account.
  • The HTTPS origins for AUTH_BASE_URL and FRONTLINE_BASE_URL or GTFS_BASE_URL. Set them without a trailing slash.
  • For Frontline: the consumer schema (.proto files) and whether to use native gRPC or gRPC-Web.

Keep secrets and private keys on a trusted server, never in a browser bundle or mobile app. See token safety.

With a client secret:

Terminal window
curl --fail-with-body --silent --show-error \
--data-urlencode 'grant_type=client_credentials' \
--data-urlencode "client_id=${CLIENT_ID}" \
--data-urlencode "client_secret=${CLIENT_SECRET}" \
"${AUTH_BASE_URL}/connect/token"

With a public key, follow the nonce-challenge flow. Its signed payload will change soon, in a breaking change.

A successful response is JSON with access_token, token_type, and expires_in (currently one hour). Service accounts get no refresh token: request a new access token before the old one expires. Never log the response.

--fail-with-body needs curl 7.76.0 or newer. These shell examples are for diagnosis only; expanded arguments can expose secrets in process listings and logs.

Identifiers in these guides, such as stop 90001234, service X42, and vehicle EXM1234, are synthetic. Replace them with identifiers returned by the API.