REST API
- Every core object readable and writable — requests, passes, meetings, scans, members, vehicles
- Token authentication with scoped, revocable credentials
- Pagination, filtering and since-cursors for incremental sync
- Rate limits published per tier, with headers on every response