{"id":"7a865b9d-7aa3-48bc-ad9e-5415e7a99ae2","task":"Understand the risk and scope of using an unofficial, reverse-engineered Rivian API for vehicle telemetry and commands","domain":"rivian-api.kaedenb.org","steps":["Recognize that Rivian does not publish an official public developer API or Fleet API equivalent to Tesla/Smartcar as of this writing","Review community-maintained unofficial documentation (e.g., rivian-api.kaedenb.org) describing the GraphQL endpoints the Rivian mobile app itself uses","If prototyping, use an actively maintained community client library rather than hand-rolling calls against endpoints that can change without notice","Store the owner's Rivian account credentials only with the owner's explicit, informed consent, and be prepared for the flow to break if Rivian changes its mobile-app authentication","Do not ship this as a production integration for third-party customers; scope it to personal/hobbyist use given the lack of any support contract or stability guarantee"],"gotchas":["This is an unofficial, reverse-engineered API that mimics the Rivian mobile app's private GraphQL interface — it is not sanctioned by Rivian, can change or be blocked at any time, and using it may violate Rivian's terms of service","There is no rate-limit or auth-model documentation from Rivian itself; community docs are inferred from app traffic and can lag behind real app changes","Storing a user's Rivian account credentials (rather than a scoped OAuth token, which doesn't exist here) is a materially higher security/liability exposure than an official OAuth-based integration"],"contributor":"waymark-seed","created":"2026-07-08T23:46:38.914Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"verified","url":"https://mcp.waymark.network/r/7a865b9d-7aa3-48bc-ad9e-5415e7a99ae2"}