General Motors · Authentication Profile

General Motors Authentication

Authentication

General Motors publishes no authentication documentation for its connected-vehicle / fleet APIs — the reference that would describe it sits behind the portal's commercial-access gate. What IS publicly verifiable is how the GM Developer Portal's own API backend authenticates, established here by probe rather than by documentation.

General Motors declares 2 security scheme(s) across its OpenAPI definitions.

AutomobilesCarsVehiclesConnected VehiclesTelematicsFortune 100
Methods: Schemes: 2 OAuth flows: API key in:

Security Schemes

oauth2
csrf

Source

Authentication Profile

general-motors-authentication.yml Raw ↑
specification: API Evangelist Authentication Profile
specificationVersion: '0.1'
provider: General Motors
providerId: general-motors
generated: '2026-09-12'
method: probed
source: https://developer.gm.com/config/index.js
description: >-
  General Motors publishes no authentication documentation for its connected-vehicle / fleet
  APIs — the reference that would describe it sits behind the portal's commercial-access
  gate. What IS publicly verifiable is how the GM Developer Portal's own API backend
  authenticates, established here by probe rather than by documentation.
scoring_note: >-
  NO `Authentication` pointer is wired into apis.yml for this file, on purpose. The rating's
  authentication_documented check asserts that the PROVIDER documents authentication for its
  API; GM does not. This artifact records what we were able to observe, not a published auth
  guide, and crediting it would be a false claim made on GM's behalf.
schemes:
- id: entra-external-id-bearer
  type: oauth2
  applies_to: https://developer.gm.com/v1 (GM Developer Portal backend)
  flow: authorization_code (MSAL browser client, PKCE)
  identity_provider: Microsoft Entra External ID (CIAM)
  issuer: https://450fd55c-b136-4d90-9e9f-a59b07772fab.ciamlogin.com/450fd55c-b136-4d90-9e9f-a59b07772fab/v2.0
  client_id: def7864f-a5b6-4d80-b024-592df723ad5a
  redirect_uri: https://developer.gm.com/
  scopes_supported:
  - openid
  - profile
  - email
  - offline_access
  token_endpoint: https://450fd55c-b136-4d90-9e9f-a59b07772fab.ciamlogin.com/450fd55c-b136-4d90-9e9f-a59b07772fab/oauth2/v2.0/token
  jwks_uri: https://450fd55c-b136-4d90-9e9f-a59b07772fab.ciamlogin.com/450fd55c-b136-4d90-9e9f-a59b07772fab/discovery/v2.0/keys
  bearer: 'Authorization: Bearer <id token>'
  ownership_note: >-
    The issuer is a Microsoft-hosted CIAM host, not a GM host. It is attributed to GM because
    developer.gm.com serves the tenant id, client id and redirect URI itself, unauthenticated,
    from its own /config/index.js — the portal names this tenant as its authority.
- id: csrf-double-submit
  type: csrf
  applies_to: https://developer.gm.com/v1 (state-changing requests)
  header: X-XSRF-TOKEN
  token_endpoint: https://developer.gm.com/v1/csrf-token
  anonymous: true
  note: >-
    GET /v1/csrf-token answers 200 anonymously and returns {audience, token, headerName}.
    It is the only endpoint under /v1 that answers without a bearer token.
authorization:
  model: commercial-agreement
  note: >-
    Signing in is not sufficient. The portal's router guards /docs/* with
    requireCommercialAPIAccess, so the API reference is released per-account only after GM
    approves commercial API access.
observed:
- url: https://developer.gm.com/v1/csrf-token
  method: GET
  status: 200
  detail: anonymous; returns the CSRF token envelope
- url: https://developer.gm.com/v1/apis
  method: GET
  status: 403
  detail: empty body, istio-envoy upstream — bearer token required
- url: https://developer.gm.com/v1/graphql
  method: POST
  status: 403
  detail: '{"message":"Invalid or missing CSRF token. Call GET /v1/csrf-token first.","error":"CSRF_VALIDATION_FAILED"}'
- url: https://450fd55c-b136-4d90-9e9f-a59b07772fab.ciamlogin.com/450fd55c-b136-4d90-9e9f-a59b07772fab/v2.0/.well-known/openid-configuration
  method: GET
  status: 200
  detail: OpenID Provider Metadata for the tenant the portal signs in against
unknown:
- The authentication model for the OnStar / GM Envolve vehicle-data and fleet APIs
  (api.gm.com, api.onstarfleetintelligence.com) is not publicly documented.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/general-motors-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.