Research Note

API Change and Platform Dependency Research Note

An upstream API change can alter access, fields, authentication, rate limits, permitted uses, attribution, display, storage, downstream sharing, webhook behavior, and ter

Aug 4, 20261 min readBy Dalton Anderson
In this article

API Change and Platform Dependency Research Note

Finding

An upstream API change can alter access, fields, authentication, rate limits, permitted uses, attribution, display, storage, downstream sharing, webhook behavior, and termination rights. The dependent product must treat the change as a product, engineering, data, contract, privacy, support, and communication event.

Strava's current API agreement permits modification or discontinuation and imposes use restrictions. Garmin's June 30, 2025 guidelines apply attribution to primary displays, secondary screens, exports, APIs, social sharing, and materially influenced derived data. These are current records, not universal norms.

GitHub and Stripe demonstrate provider practices that reduce uncertainty through versioning, notices, migration guidance, testing, and limited rollback or support periods. A dependent team should not assume its provider offers the same protections.

Dependency model

Record the upstream provider, input, user journey, permitted use, technical path, data stored, downstream recipients, commercial contribution, failure signal, substitute, exit time, and owner.

Concentration is not the only risk. A dependency can be dangerous because access is revocable, the product cannot reproduce the input, migration takes too long, the user relationship belongs upstream, or contractual terms prevent the intended value.

Publication rule

Do not interpret a reader's contract or promise API continuity. Present adapt, negotiate, replace, narrow, and exit as product options that require technical, commercial, privacy, and legal review.

Sources

Follow the evidence.

  1. patents.google.com: US9116922patents.google.com
  2. communityhub.strava.com: update regarding garmin attribution best practice 11916communityhub.strava.com
  3. developer.garmin.com: Garmin Developer API Brand Guidelinesdeveloper.garmin.com
  4. storage.courtlistener.com: gov.uscourts.cod.247832.19.0storage.courtlistener.com
  5. docs.stripe.com: upgradesdocs.stripe.com
  6. docs.github.com: breaking changesdocs.github.com
  7. reddit.com: setting the record straight about garminreddit.com
  8. dockets.justia.com: 247832dockets.justia.com
  9. prsa.org: ethicsprsa.org
  10. w3.org: prov ow3.org
  11. developers.strava.com: guidelinesdevelopers.strava.com
  12. patents.google.com: US9778053patents.google.com
  13. ico.org.uk: right to data portabilityico.org.uk
  14. garminrumors.com: Strava vs Garmin Lawsuit Segments 9 30garminrumors.com
  15. developers.strava.com: getting starteddevelopers.strava.com
  16. developers.strava.com: webhooksdevelopers.strava.com
  17. strava.com: apistrava.com
  18. developer.garmin.com: brand guidelinesdeveloper.garmin.com
  19. patents.google.com: US9297651patents.google.com

From this episode

Two useful next steps.

Evergreen · 1 min

What to Do When an API Policy Changes

Preserve the old and new policy, map journeys and data, classify the change, choose adapt, negotiate, replace, narrow, or exit, then communicate clearly.

Episode Story · 1 min

Venture Step E086: Strava, Garmin, and Platform Power

Episode 86 argued that the Strava-Garmin dispute exposed API dependence and weak communication. The lawsuit later ended without a merits ruling.

Return to the episode
API Change and Platform Dependency Research Note