REST over HTTPS, JSON, key-authenticated. Base URL, scopes, pagination, error codes, and the one non-obvious thing — keys bypass user permissions.