> Your API is pretty strange. Some initial things that pop out on me:
> json=true to specify the content type. Ideally, this should be from the accept header, but at the very least it should be possible to only specify one content type. Right now, I can specify json=true&xml=true.
I agree, content type selection currently is very rudimentary and ability to combine parameters could be confusing. We want to distinguish between JSON, JSONP, XML and CSV. We could use text/plain MIME type for CSV, text/xml for XML, but are there standard MIME types for JSON and JSONP?
> Only using GET.
API is currently immutable towards analytics data, so only GET is used.
> Session management on the client. Why would I want to log someone out?
It's less of the session management and more security token management. Log out is to revoke specified security token. We should be more explicit about this.