Hyundai · Authentication Profile

Hyundai Authentication

Authentication

Hyundai declares 4 security scheme(s) across its OpenAPI definitions.

AutomobilesCarsConnected VehiclesMobilityVehiclesAutomotiveTelematicsElectric VehiclesVehicle DataSouth Korea
Methods: Schemes: 4 OAuth flows: API key in:

Security Schemes

oauth2
http
scheme: basic
http
scheme: bearer
apiKey
· in: header ()

Source

Authentication Profile

hyundai-authentication.yml Raw ↑
generated: '2026-09-13'
method: searched
source: https://developers.hyundai.com/web/v1/hyundai/specification/account/account_token
docs:
  - https://developers.hyundai.com/web/v1/hyundai/specification/account/account_authorize
  - https://developers.hyundai.com/web/v1/hyundai/specification/account/account_token
  - https://developers.hyundai.com/web/v1/hyundai/guide_api
  - https://developers.hyundai.com/web/v1/hyundai/guide_console
provider: Hyundai
providerId: hyundai
api: Hyundai Developers Connected Car API
note: >-
  Hyundai Developers uses the Hyundai integrated account (현대자동차 통합계정) as its identity
  provider and states plainly in its own console guide that "현대자동차 통합계정은 OAuth 2.0 을
  지원하고 있습니다" — the integrated account supports OAuth 2.0. There is no published
  OpenAPI, so this profile is read from the provider's own API specification pages rather
  than derived from securitySchemes.
schemes:
  - id: oauth2_authorization_code
    type: oauth2
    flow: authorizationCode
    description: >-
      Three-legged authorization code flow against the Hyundai integrated account. The
      partner application redirects the vehicle owner to the authorize endpoint; the owner
      signs in, is shown their vehicle list, and consents per vehicle. Only vehicles the
      owner explicitly selects become readable. Shared vehicles are excluded from the list.
    authorization_url: https://prd.kr-ccapi.hyundai.com/api/v1/user/oauth2/authorize
    token_url: https://prd.kr-ccapi.hyundai.com/api/v1/user/oauth2/token
    authorize_parameters:
      - name: response_type
        required: true
        value: code
      - name: client_id
        required: true
        description: Client ID issued when the console project is registered
      - name: redirect_uri
        required: true
        description: >-
          Must match the Redirect URL registered in Console > Settings > Account API;
          a mismatch is rejected
      - name: state
        required: true
        description: >-
          CSRF state token generated by the application. The docs explicitly name
          cross-site request forgery as the threat and require Base64 or URL encoding
          when special characters are used.
    scopes_documented: false
    scopes_note: >-
      No scope parameter appears in the authorize request and no scope reference page
      exists. Authorization is granted per API at the project level (the console's API
      management page lists which APIs a project is approved for) and per vehicle at the
      consent step, not by OAuth scope string. scopes/ is therefore deliberately not
      written for this provider.
  - id: client_basic
    type: http
    scheme: basic
    description: >-
      The token endpoint authenticates the client with HTTP Basic over the
      base64(client_id:client_secret) pair issued at project registration. Content-Type
      must be application/x-www-form-urlencoded.
    applies_to:
      - POST /api/v1/user/oauth2/token
  - id: bearer_access_token
    type: http
    scheme: bearer
    bearer_format: opaque
    description: >-
      Every user, vehicle-profile, vehicle-status and warning-light operation is called
      with `Authorization: Bearer {access_token}`.
    applies_to:
      - GET /api/v1/user/profile
      - GET /api/v1/car/profile/carlist
      - GET /api/v1/car/profile/{carId}/contract
      - GET /api/v1/car/status/{carId}/*
      - GET /api/v1/car/status/warning/{carId}/*
      - GET /api/v1/car-service/terms/reject
  - id: admin_key_b2b
    type: apiKey
    in: header
    description: >-
      A separate server IP allow-list plus Admin Key is issued only to partners who have
      negotiated a B2B API contract. The console guide states these settings are shown
      "only when a separate API usage agreement has been arranged with us", so the B2B
      surface is not publicly documented.
    public: false
grant_types:
  - value: authorization_code
    purpose: issue a new token pair
  - value: refresh_token
    purpose: refresh the access token
  - value: delete
    purpose: >-
      revoke/delete the token — a non-standard grant_type value used in place of an
      RFC 7009 revocation endpoint
token:
  access_token:
    transport: Authorization Bearer header
    documented_lifetime: 24 hours
    example_expires_in: 7200
    discrepancy: >-
      The specification prose states access_token is valid for 24 hours after issue, while
      every published success example on the same page returns expires_in: 7200 (2 hours).
      Recorded as published; not reconciled by the provider. Clients should trust
      expires_in, not the prose.
  refresh_token:
    documented_lifetime: 1 year
    returned_on: authorization_code grant only
  token_type: Bearer
observed:
  - probe: GET https://prd.kr-ccapi.hyundai.com/api/v1/user/profile with no Authorization header
    date: '2026-09-13'
    status: 401
    body: '{"errId":"...","errCode":"4010","errMsg":"Require authentication"}'
    note: >-
      Confirms the documented error envelope and the 4010 account-API error code on a
      live unauthenticated request.
consent_model:
  description: >-
    Data access requires TWO consents layered on top of OAuth: the vehicle-access consent
    taken during login, and a separate Korean PIPA third-party-provision consent obtained
    through POST /api/v1/car-service/terms/agreement. Vehicle data calls fail with 4120
    ("Pre-operation is required") until the third-party consent has been completed.
  principles_published: https://developers.hyundai.com/web/v1/hyundai/intro
  principle_quote: The customer owns the data and shares if only when the customer agrees.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hyundai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.