Getting started
1. Choose an API
Section titled “1. Choose an API”- Frontline (recommended). Native gRPC or gRPC-Web for rider apps, passenger displays, and maps: search stops, read arrivals, get route details, and stream live updates.
- GTFS-RT. Binary GTFS Realtime feeds over HTTP: trip updates and vehicle positions. Choose it if your system already consumes GTFS Realtime. It is polling-only, and you need the matching static GTFS identifiers from your MyBusz contact.
Both require an access token with the frontline:consumer scope, so one service
account can use either or both.
2. Get access
Section titled “2. Get access”Ask your MyBusz contact to create a service account with the frontline:consumer
scope. Decide its credential type first:
| Public key (recommended) | Client secret | |
|---|---|---|
| Setup | You send your public key; the private key stays with you | The admin sends you a generated secret |
| Token grant | urn:custom:nonce-challenge |
client_credentials |
| Frontline limit | 200 requests/minute | 60 requests/minute |
| GTFS-RT limit | 10 requests/minute per feed | 10 requests/minute per feed |
Service accounts use only these two credentials. Passwords, TOTP, and passkeys are for human accounts. See rate limits for details.
You will receive:
CLIENT_ID, plusCLIENT_SECRETfor a secret-based account.- The HTTPS origins for
AUTH_BASE_URLandFRONTLINE_BASE_URLorGTFS_BASE_URL. Set them without a trailing slash. - For Frontline: the consumer schema (
.protofiles) and whether to use native gRPC or gRPC-Web.
Keep secrets and private keys on a trusted server, never in a browser bundle or mobile app. See token safety.
3. Get an access token
Section titled “3. Get an access token”With a client secret:
curl --fail-with-body --silent --show-error \ --data-urlencode 'grant_type=client_credentials' \ --data-urlencode "client_id=${CLIENT_ID}" \ --data-urlencode "client_secret=${CLIENT_SECRET}" \ "${AUTH_BASE_URL}/connect/token"With a public key, follow the nonce-challenge flow. Its signed payload will change soon, in a breaking change.
A successful response is JSON with access_token, token_type, and expires_in
(currently one hour). Service accounts get no refresh token: request a new access
token before the old one expires. Never log the response.
--fail-with-body needs curl 7.76.0 or newer. These shell examples are for
diagnosis only; expanded arguments can expose secrets in process listings and
logs.
4. Make your first call
Section titled “4. Make your first call”- Frontline: find a stop, then read its arrivals.
- GTFS-RT: download a feed.
Identifiers in these guides, such as stop 90001234, service X42, and vehicle
EXM1234, are synthetic. Replace them with identifiers returned by the API.