Research Note

API Change and Platform Dependency Research Note

An upstream API change can alter access, fields, authentication, rate limits, permitted uses, attribution, display, storage, downstream sharing, webhook behavior, and ter

Aug 4, 20261 min readBy Dalton Anderson
In this article

API Change and Platform Dependency Research Note

Finding

An upstream API change can alter access, fields, authentication, rate limits, permitted uses, attribution, display, storage, downstream sharing, webhook behavior, and termination rights. The dependent product must treat the change as a product, engineering, data, contract, privacy, support, and communication event.

Strava's current API agreement permits modification or discontinuation and imposes use restrictions. Garmin's June 30, 2025 guidelines apply attribution to primary displays, secondary screens, exports, APIs, social sharing, and materially influenced derived data. These are current records, not universal norms.

GitHub and Stripe demonstrate provider practices that reduce uncertainty through versioning, notices, migration guidance, testing, and limited rollback or support periods. A dependent team should not assume its provider offers the same protections.

Dependency model

Record the upstream provider, input, user journey, permitted use, technical path, data stored, downstream recipients, commercial contribution, failure signal, substitute, exit time, and owner.

Concentration is not the only risk. A dependency can be dangerous because access is revocable, the product cannot reproduce the input, migration takes too long, the user relationship belongs upstream, or contractual terms prevent the intended value.

Publication rule

Do not interpret a reader's contract or promise API continuity. Present adapt, negotiate, replace, narrow, and exit as product options that require technical, commercial, privacy, and legal review.

Sources

Follow the evidence.

  1. communityhub.strava.com: update regarding garmin attribution best practice 11916communityhub.strava.com
  2. developer.garmin.com: brand guidelinesdeveloper.garmin.com
  3. developer.garmin.com: Garmin Developer API Brand Guidelinesdeveloper.garmin.com
  4. developers.strava.com: getting starteddevelopers.strava.com
  5. developers.strava.com: webhooksdevelopers.strava.com
  6. developers.strava.com: guidelinesdevelopers.strava.com
  7. dockets.justia.com: 247832dockets.justia.com
  8. docs.github.com: breaking changesdocs.github.com
  9. docs.stripe.com: upgradesdocs.stripe.com
  10. garminrumors.com: Strava vs Garmin Lawsuit Segments 9 30garminrumors.com
  11. ico.org.uk: right to data portabilityico.org.uk
  12. patents.google.com: US9116922patents.google.com
  13. patents.google.com: US9297651patents.google.com
  14. patents.google.com: US9778053patents.google.com
  15. storage.courtlistener.com: gov.uscourts.cod.247832.19.0storage.courtlistener.com
  16. prsa.org: ethicsprsa.org
  17. reddit.com: setting the record straight about garminreddit.com
  18. strava.com: apistrava.com
  19. w3.org: prov ow3.org

From this episode

Two useful next steps.

Evergreen · 1 min

What to Do When an API Policy Changes

Preserve the old and new policy, map journeys and data, classify the change, choose adapt, negotiate, replace, narrow, or exit, then communicate clearly.

Episode Story · 1 min

Venture Step E086: Strava, Garmin, and Platform Power

Episode 86 argued that the Strava-Garmin dispute exposed API dependence and weak communication. The lawsuit later ended without a merits ruling.

Return to the episode