Ford · Authentication Profile

Ford Authentication

Authentication

Ford secures its APIs with oauth2, openIdConnect, and http across 3 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode flow(s).

AutomobilesCarsVehiclesConnected VehiclesAutomotiveTelematicsElectric VehiclesFleet
Methods: oauth2, openIdConnect, http Schemes: 3 OAuth flows: authorizationCode API key in:

Security Schemes

oauth2 oauth2
· flows: authorizationCode
bearerAuth http
scheme: bearer
applicationId apiKey
· in: header ()

Source

Authentication Profile

Raw ↑
generated: '2026-09-10'
method: searched
source: https://dah2vb2cprod.b2clogin.com/914d88b1-3523-4bf6-9be4-1b96b4f6f919/B2C_1A_signup_signin_common/v2.0/.well-known/openid-configuration
docs: https://developer.ford.com/apis
summary:
  types:
  - oauth2
  - openIdConnect
  - http
  oauth2_flows:
  - authorizationCode
  primary: OAuth 2.0 authorization code against Ford's own Azure AD B2C consumer tenant, with vehicle-owner
    consent captured as data categories
note: Upgraded from derived to searched on 2026-09-10 against Ford's own OpenID Connect discovery document,
  fetched anonymously. The B2C tenant (dah2vb2cprod, 914d88b1-3523-4bf6-9be4-1b96b4f6f919) is Ford's —
  it is the exact token endpoint Ford's FordConnect OAuth configuration names, and the same host the fordconnect.cv.ford.com
  account-linking bundle calls. Credentials (client id + two rotating secrets) are issued from the signed-in
  Ford Developer Marketplace account dashboard, not self-service at runtime.
schemes:
- name: oauth2
  type: oauth2
  flows:
  - flow: authorizationCode
    issuer: https://dah2vb2cprod.b2clogin.com/914d88b1-3523-4bf6-9be4-1b96b4f6f919/v2.0/
    authorizationUrl: https://dah2vb2cprod.b2clogin.com/914d88b1-3523-4bf6-9be4-1b96b4f6f919/b2c_1a_signup_signin_common/oauth2/v2.0/authorize
    tokenUrl: https://dah2vb2cprod.b2clogin.com/914d88b1-3523-4bf6-9be4-1b96b4f6f919/b2c_1a_signup_signin_common/oauth2/v2.0/token
    endSessionUrl: https://dah2vb2cprod.b2clogin.com/914d88b1-3523-4bf6-9be4-1b96b4f6f919/b2c_1a_signup_signin_common/oauth2/v2.0/logout
    jwks_uri: https://dah2vb2cprod.b2clogin.com/914d88b1-3523-4bf6-9be4-1b96b4f6f919/b2c_1a_signup_signin_common/discovery/v2.0/keys
    policy: B2C_1A_signup_signin_common
    scopes_supported:
    - openid
    response_types_supported:
    - code
    - code id_token
    - code token
    - code id_token token
    - id_token
    - id_token token
    - token
    - token id_token
    response_modes_supported:
    - query
    - fragment
    - form_post
    token_endpoint_auth_methods_supported:
    - client_secret_post
    - client_secret_basic
    id_token_signing_alg_values_supported:
    - RS256
    subject_types_supported:
    - pairwise
    claims_supported:
    - sub
    - idp
    - mtmId
    - userGuid
    - locale
    - jti
    - client_id
    - scope
    - iss
    - iat
    - exp
    - aud
    - acr
    - nonce
    - auth_time
  description: OAuth 2.0 authorization-code grant brokered through Ford Azure AD B2C; the user consents
    at https://fordconnect.cv.ford.com/common/login and the app receives a code it exchanges for a bearer
    token.
  sources:
  - well-known/ford-openid-configuration.json
- name: bearerAuth
  type: http
  scheme: bearer
  bearerFormat: JWT
  description: 'The access token from the B2C token endpoint is sent as an Authorization: Bearer header
    on FordConnect API calls.'
  evidence: https://api.vehicle.ford.com/api/fordconnect/vehicleinfo/v3/vehicles returned HTTP 401 to
    an unauthenticated GET on 2026-09-10, confirming a live bearer-gated surface.
  sources:
  - probe
- name: applicationId
  type: apiKey
  in: header
  x-header: Application-Id
  description: FordConnect additionally requires the partner application id issued in the developer account
    dashboard alongside the bearer token.
  confidence: medium
  note: Recorded from the credential surface Ford describes in the developer dashboard (Client ID / Secret
    1 / Secret 2 / Expiration). The exact header name is not restated in any anonymously reachable Ford
    page — treat as medium confidence until an authenticated docs read confirms it.
  sources:
  - https://developer.ford.com/assets/i18n/en.json
credentials:
  issued_from: https://developer.ford.com/my-developer-account/my-profile
  model: partner application registration; client id plus two rotatable secrets with an expiration date
  self_serve: false
  secret_rotation: two concurrent secrets supported ("Add Second Secret"), each with its own expiration
  redirect_uris: 1 required, maximum 5; https:// required except http:// for localhost
  source: https://developer.ford.com/assets/i18n/en.json
consent:
  model: vehicle-owner consent per data category, captured in the FordPass/Lincoln Way account-linking
    flow
  url: https://fordconnect.cv.ford.com/common/login
  http_status: 200
  categories: see scopes/ford-scopes.yml (14 data categories)
x-evidence:
- url: https://dah2vb2cprod.b2clogin.com/914d88b1-3523-4bf6-9be4-1b96b4f6f919/B2C_1A_signup_signin_common/v2.0/.well-known/openid-configuration
  http_status: 200
  fetched: '2026-09-10'
- url: https://fordconnect.cv.ford.com/common/login
  http_status: 200
  fetched: '2026-09-10'
- url: https://api.vehicle.ford.com/api/fordconnect/vehicleinfo/v3/vehicles
  http_status: 401
  fetched: '2026-09-10'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ford-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.