# Enterprise Mobility

**Canonical:** https://apis.io/providers/enterprise-mobility/  
**Website:** https://www.enterprisemobility.com/  
**APIs profiled:** 4

Enterprise Mobility is the Clayton, Missouri parent of Enterprise Rent-A-Car, National Car Rental and Alamo Rent a Car, and the largest car rental provider in the world — 90,000+ team members, 9,500+ rental branches across more than 90 countries and territories, a global fleet of over 2.4 million vehicles and $39 billion in 2025 fiscal-year revenue. Beyond leisure and corporate car rental it operates fleet management, flexible vehicle hire, carsharing, vanpooling, truck rental, car sales, vehicle subscription and the ARMS / Entegral replacement-rental technology used by insurers, collision repairers and dealerships. In the United States travel distribution chain it is a ground-transportation supplier whose inventory reaches buyers through GDS and OTA intermediaries, corporate travel programs and its own direct brand sites, rather than through any published public booking API. Its API posture is partner-gated and honestly so: EHI runs a real API Marketplace at developer.ehi.com with public marketing overviews for three business lines — Rental, Replacement Rental and Commute — but the API catalog, API specs, guides and release notes all sit behind Azure AD B2C sign-in and the portal states access is for "an Enterprise employee or trusted Partner" who should "contact your account manager ... to request access". No OpenAPI is published for those business lines; probes of /openapi.json, /swagger.json, /api-docs and /.well-known/ return AEM soft-404 HTML or 404. What is public is the plumbing around the gate: the production API gateway at api.ehi.com is a live Kong Gateway behind Imperva, the marketplace's own experience API publishes three POST endpoints in the portal's anonymous page source, the Azure AD B2C tenant serves two readable OpenID Connect discovery documents, and the sign-in link enumerates fourteen OAuth scopes covering catalog search, client-application registration and authorization requests. The published API License Agreement grants only a "limited, revocable, non-transferable, non-sublicensable, non-exclusive" right, restricts use to the licensee's internal purpose, states the licensee has no ownership rights in Renter Information, and on termination requires the licensee to "delete or return any copies of the APIs and Enterprise Content" — public docs shell, gated specs, no exit path.

## Kin Score — 27.8 / 100 (emerging)

Scored 2026-08-17 under rubric 0.11.0. Trend: flat (+0.0 from 27.8).

| Facet | Score |
|---|---|
| Discoverability | 72.2 |
| Contract Quality | 0.0 |
| Governance | 12.5 |
| Operational Transparency | 0.0 |
| Developer Ergonomics | 34.8 |
| Commercial Clarity | 21.1 |

Regulatory layer — **Insurance**: 72.7 (matched via tags).

## Agent readiness — 12.6 (agent-aware)

| Dimension | Value |
|---|---|
| Spec Presence | no |
| Agentic Access | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | no |
| Rate Limit Signal | no |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## APIs (4)

- **EHI Rental APIs** — The Rental business line of the EHI API Marketplace, covering Enterprise Rent-A-Car's network of neighborhood and airport branches. The public overview page describes the capabi...
- **EHI Replacement Rental APIs** — The Replacement Rental business line of the EHI API Marketplace, exposing the ARMS (Automated Rental Management System) and Entegral platforms to insurance providers, collision ...
- **EHI Commute APIs** — The Commute business line of the EHI API Marketplace, covering Commute with Enterprise vanpooling and rideshare-to-work programs sold to employers. The public overview page desc...
- **EHI API Marketplace Experience API** — The backend-for-frontend that powers the EHI API Marketplace itself, and the only Enterprise Mobility API surface with endpoints published anonymously. Three POST operations are...

## Security (3)

- **Enterprise Mobility Authentication** — openIdConnect/oauth2/http · 3 schemes
- **Enterprise Mobility Domain Security** — TLSv1.3 · HSTS · DMARC
- **Enterprise Mobility Vulnerability Disclosure** — Hackerone · security.txt · contact published

## Tags

Travel, United States, Car Rental, Ground Transportation, Mobility, Corporate Travel, Distribution, Fleet Management, Insurance Replacement Rental, Booking

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/enterprise-mobility/). Scores are computed from the provider's own public artifacts under a published rubric.
