Register
Create a Data application in the dashboard. Redirect URIs match exactly.
DevelopersAPI 1.0.0
Build private, read-only tools around the same Quko account permissions you already have. Read sessions, health data and analytics, and download the exact files produced by the web application. Only the owner of an application can authorize it.
https://cloud.quko.es/api/v1{ data, meta }One authorization code flow, one consistent response shape.
Create a Data application in the dashboard. Redirect URIs match exactly.
Use Authorization Code with PKCE S256, state, and—when using OIDC—a nonce.
Send a Bearer access token. Follow opaque cursors and retry idempotent jobs safely.
curl --request GET \
--url 'https://cloud.quko.es/api/v1/sessions?limit=25&important=true' \
--header 'Authorization: Bearer <access_token>' \
--header 'Accept: application/json'
import requests
response = requests.get(
"https://cloud.quko.es/api/v1/sessions",
headers={"Authorization": "Bearer <access_token>"},
params={"limit": 25, "important": "true"},
timeout=20,
)
response.raise_for_status()
page = response.json()
const url = new URL("https://cloud.quko.es/api/v1/sessions");
url.search = new URLSearchParams({ limit: "25", important: "true" });
const response = await fetch(url, {
headers: { Authorization: "Bearer <access_token>" },
});
if (!response.ok) throw new Error(`Quko ${response.status}`);
const page = await response.json();
Authorization Code is the only interactive grant; PKCE S256 is mandatory.
GET/.well-known/openid-configuration/apiDiscoveryGET/api/oauth/authorizeAuthorizationPOST/api/oauth/tokenCode + refresh exchangeGET/api/oauth/userinfoOIDC claimsPOST/api/oauth/revokeToken revocationPOST/api/oauth/introspectApproved confidential clientsGET/api/oauth/jwks.jsonJWT verification keysGenerate a local verifier, S256 challenge, state, nonce, and authorization URL. Nothing leaves this browser.
Select “Generate synthetic request”.These rules apply to every resource card below.
Lists accept limit up to 100 and the unmodified meta.next_cursor. Cursors expire and are resource- and subject-bound.
Ownership failures do not disclose whether another user’s identifier exists.
Send Idempotency-Key on creation and processing. Reuse it only for the identical operation.
Uploads, exports, and device operations return 202. Poll the status URL with bounded backoff.
{
"data": [{ "id": 482, "distance_m": 1000 }],
"meta": { "next_cursor": "eyJraW5kIjoic2Vzc2lvbiJ9…", "limit": 25 }
}{
"error": "invalid_request",
"error_description": "limit must be from 1 to 100",
"request_id": "req_synthetic_01"
}Allowlisted serializers are the boundary—not database models.
sessions:readdata, datapal, IMU matrices, or full-rate channelsThe original encrypted .qk file is the sole device portability exception. It is delivered once, unchanged and still encrypted; no Data endpoint decodes it or exposes its sensor arrays. Garmin-origin and other external-provider data never cross this API either.
Real session data (distance on the X axis) plotted with Chart.js. Scroll to zoom, drag to pan.
Edit a version-1 template and simulate the asynchronous web-equivalent export workflow.
JSON, PDF, full PDF, XLSX, FIT, and TCX are generated by the same builders as the Quko web app. Partner exports use those builders in privacy-safe mode.
Existing web permissions, no administrative side door.
Read-only under athlete:read. There is no route to grant access, change memberships, staff roles, or licences.
Read-only under sessions:read. The API cannot create, edit, merge, or delete a track.
Sanitized status under devices:read; manifests and one-time encrypted file portability under devices:files.
health:read is read-only, approved separately, and begins unchecked.
| Origin | Read | Rule |
|---|---|---|
| Quko / Kosoku heart rate | Yes | The authorizing person only |
| Manual Quko weight / lactate | Yes | Independent health consent |
| Garmin or other provider | Never | Permanent provenance exclusion |
| Another crew member | Never | Subject isolation |
The Quko Cloud replay scene (same K1 model, water, sky and lane buoys) driven by a synthetic privacy-reduced artifact—no metric, GPS, identity, stroke, health, equipment, device, timestamp, or source-index arrays.
Drag to orbit; wheel to zoom; the camera follows the lead boat. Playback, interpolation, seeking, camera motion, and comparison remain in this browser.
{
"schema": 1,
"frame_count": 900,
"model_class": "K1",
"quantization": { "position_m": 0.25, "orientation_deg": 2.0 },
"frames": [[x, 0, 0, roll, pitch, yaw, paddle_phase], …]
}
// delivered at 30 Hz; clients interpolate between framesA viewer can inspect or retain quantized visible transforms already received, much like analysing a screen recording. They cannot reconstruct sensor, GPS, health, stroke, or analytics arrays. Revocation blocks new access; it cannot recall information already displayed.
Loading the bundled OpenAPI 3.1 contract…