Hi Strava Developer Team,
I’m building a mobile app called RunPass, a rewards program designed to encourage people to run more.
The concept is simple:
Users connect their Strava account to RunPass. When a user completes a qualifying run, RunPass uses the Strava API to confirm that the run was completed and automatically unlocks a reward for that user.
For example:
- A user connects their Strava account to RunPass.
- The user completes a run using Strava as they normally would.
- RunPass receives the activity notification through Strava’s API/webhooks.
- RunPass verifies that the activity meets the qualifying criteria.
- RunPass unlocks a reward for the user.
- The user chooses which participating business reward they want to redeem.
- The business only receives a RunPass reward/QR code and redemption status. Strava activity data is not provided to the business.
Strava would be used as the verification layer to confirm that a qualifying run has been completed.
We would not provide businesses with users’ routes, locations, pace, activity history, Strava profiles, or other Strava activity data. The purpose of the integration is solely to verify the completion of a run and trigger a reward for the authenticated user.
Could you please confirm whether this use of the Strava API is permitted under the current 2026 API Agreement and API Policy?
In particular, I would appreciate clarification on whether using a completed activity/webhook as an eligibility trigger for a user-selected reward is permitted, given the restrictions around advertising, promotions, third-party businesses, and derived Strava data.
I would like to confirm this before building the Strava-dependent part of the application.
