Hyundai · Authentication Profile
Hyundai Authentication
Authentication
Hyundai declares 4 security scheme(s) across its OpenAPI definitions.
AutomobilesCarsConnected VehiclesMobilityVehiclesAutomotiveTelematicsElectric VehiclesVehicle DataSouth Korea
Methods:
Schemes: 4
OAuth flows:
API key in:
Security Schemes
oauth2
http
scheme: basic
http
scheme: bearer
apiKey
· in: header ()
Source
Authentication Profile
generated: '2026-09-13'
method: searched
source: https://developers.hyundai.com/web/v1/hyundai/specification/account/account_token
docs:
- https://developers.hyundai.com/web/v1/hyundai/specification/account/account_authorize
- https://developers.hyundai.com/web/v1/hyundai/specification/account/account_token
- https://developers.hyundai.com/web/v1/hyundai/guide_api
- https://developers.hyundai.com/web/v1/hyundai/guide_console
provider: Hyundai
providerId: hyundai
api: Hyundai Developers Connected Car API
note: >-
Hyundai Developers uses the Hyundai integrated account (현대자동차 통합계정) as its identity
provider and states plainly in its own console guide that "현대자동차 통합계정은 OAuth 2.0 을
지원하고 있습니다" — the integrated account supports OAuth 2.0. There is no published
OpenAPI, so this profile is read from the provider's own API specification pages rather
than derived from securitySchemes.
schemes:
- id: oauth2_authorization_code
type: oauth2
flow: authorizationCode
description: >-
Three-legged authorization code flow against the Hyundai integrated account. The
partner application redirects the vehicle owner to the authorize endpoint; the owner
signs in, is shown their vehicle list, and consents per vehicle. Only vehicles the
owner explicitly selects become readable. Shared vehicles are excluded from the list.
authorization_url: https://prd.kr-ccapi.hyundai.com/api/v1/user/oauth2/authorize
token_url: https://prd.kr-ccapi.hyundai.com/api/v1/user/oauth2/token
authorize_parameters:
- name: response_type
required: true
value: code
- name: client_id
required: true
description: Client ID issued when the console project is registered
- name: redirect_uri
required: true
description: >-
Must match the Redirect URL registered in Console > Settings > Account API;
a mismatch is rejected
- name: state
required: true
description: >-
CSRF state token generated by the application. The docs explicitly name
cross-site request forgery as the threat and require Base64 or URL encoding
when special characters are used.
scopes_documented: false
scopes_note: >-
No scope parameter appears in the authorize request and no scope reference page
exists. Authorization is granted per API at the project level (the console's API
management page lists which APIs a project is approved for) and per vehicle at the
consent step, not by OAuth scope string. scopes/ is therefore deliberately not
written for this provider.
- id: client_basic
type: http
scheme: basic
description: >-
The token endpoint authenticates the client with HTTP Basic over the
base64(client_id:client_secret) pair issued at project registration. Content-Type
must be application/x-www-form-urlencoded.
applies_to:
- POST /api/v1/user/oauth2/token
- id: bearer_access_token
type: http
scheme: bearer
bearer_format: opaque
description: >-
Every user, vehicle-profile, vehicle-status and warning-light operation is called
with `Authorization: Bearer {access_token}`.
applies_to:
- GET /api/v1/user/profile
- GET /api/v1/car/profile/carlist
- GET /api/v1/car/profile/{carId}/contract
- GET /api/v1/car/status/{carId}/*
- GET /api/v1/car/status/warning/{carId}/*
- GET /api/v1/car-service/terms/reject
- id: admin_key_b2b
type: apiKey
in: header
description: >-
A separate server IP allow-list plus Admin Key is issued only to partners who have
negotiated a B2B API contract. The console guide states these settings are shown
"only when a separate API usage agreement has been arranged with us", so the B2B
surface is not publicly documented.
public: false
grant_types:
- value: authorization_code
purpose: issue a new token pair
- value: refresh_token
purpose: refresh the access token
- value: delete
purpose: >-
revoke/delete the token — a non-standard grant_type value used in place of an
RFC 7009 revocation endpoint
token:
access_token:
transport: Authorization Bearer header
documented_lifetime: 24 hours
example_expires_in: 7200
discrepancy: >-
The specification prose states access_token is valid for 24 hours after issue, while
every published success example on the same page returns expires_in: 7200 (2 hours).
Recorded as published; not reconciled by the provider. Clients should trust
expires_in, not the prose.
refresh_token:
documented_lifetime: 1 year
returned_on: authorization_code grant only
token_type: Bearer
observed:
- probe: GET https://prd.kr-ccapi.hyundai.com/api/v1/user/profile with no Authorization header
date: '2026-09-13'
status: 401
body: '{"errId":"...","errCode":"4010","errMsg":"Require authentication"}'
note: >-
Confirms the documented error envelope and the 4010 account-API error code on a
live unauthenticated request.
consent_model:
description: >-
Data access requires TWO consents layered on top of OAuth: the vehicle-access consent
taken during login, and a separate Korean PIPA third-party-provision consent obtained
through POST /api/v1/car-service/terms/agreement. Vehicle data calls fail with 4120
("Pre-operation is required") until the third-party consent has been completed.
principles_published: https://developers.hyundai.com/web/v1/hyundai/intro
principle_quote: The customer owns the data and shares if only when the customer agrees.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/hyundai-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.