# 4.screen > 4.screen GmbH (Munich, Germany) operates the Driver Interaction Platform — a two-sided > in-car marketplace connecting businesses with drivers in real time through the vehicle's > built-in navigation and infotainment screen. Its Mobility Experience Cloud (MXC) connects > by API to automaker vehicle backends. Generated by API Evangelist from probed public sources on 2026-09-05. This is an independent third-party profile; it is not published by 4.screen. Method: generated. Source: https://raw.githubusercontent.com/api-evangelist/4screen/refs/heads/main/apis.yml ## What you can and cannot call 4.screen has a real, production API at `https://api.4screen.com`. It is **entirely auth-gated**. Every anonymous request — including every OpenAPI, Swagger, springdoc and GraphQL path — returns: HTTP 401 {"httpStatus":401,"domain":"SYSTEM","errorCode":"AUTHENTICATION_FAILED", "message":"Full authentication is required to access this resource"} There is **no public API reference, no OpenAPI, no GraphQL SDL, no Postman collection and no SDK**. `docs.4screen.com` and `developer.4screen.com` do not resolve. An agent cannot integrate with 4.screen from public information alone; access begins with a sales conversation. ## Products (the four in-car placement formats) - [Branded Pins](https://4screen.com/branded-pins/): a business logo rendered on the in-car map at its location. - [Sponsored Search](https://4screen.com/sponsored-search/): paid ranking in in-car navigation search results. - [Recommendations](https://4screen.com/recommendations/): context-aware offers driven by vehicle signals. - [Detail Screen](https://4screen.com/detail-screen/): an interactive in-car promotion with engagement tracking. ## Audiences - [For automakers and mobility service providers (supply side)](https://4screen.com/4-automotives/): integrate the 4.screen API into infotainment systems. - [For businesses and brands (demand side)](https://4screen.com/in-car-marketing-for-businesses/): buy in-car placements. ## Authentication — the one machine-readable contract 4.screen publishes Self-hosted Keycloak, realm `fourscreen`, mounted under `/auth` on the API host. Discovery is served anonymously and is the only public contract: - [OpenID Connect discovery](https://api.4screen.com/auth/realms/fourscreen/.well-known/openid-configuration): HTTP 200, application/json. - [OAuth 2.0 Authorization Server Metadata (RFC 8414)](https://api.4screen.com/auth/realms/fourscreen/.well-known/oauth-authorization-server): HTTP 200, identical document. - [JWKS](https://api.4screen.com/auth/realms/fourscreen/protocol/openid-connect/certs): HTTP 200, RS256 signing keys. Issuer: `https://api.4screen.com/auth/realms/fourscreen` Token endpoint: `https://api.4screen.com/auth/realms/fourscreen/protocol/openid-connect/token` Machine-to-machine flow: `client_credentials`. Interactive flow: `authorization_code` + PKCE (S256). Also advertised: mutual-TLS client auth with certificate-bound tokens (RFC 8705), Pushed Authorization Requests (RFC 9126), the device grant (RFC 8628) and CIBA. First-party scopes: `demand-client-scope`, `supply-operations-client-scope`, `service_account`. Which operation needs which scope is **not published**. ## Security - [security.txt](https://4screen.com/.well-known/security.txt): RFC 9116, HTTP 200. Contact `infosec@4screen.com`. Also served on `api.4screen.com` and `portal.4screen.com`. - TLS 1.3 on both the marketing host and the API host. HSTS on `4screen.com` (max-age 31536000); **no HSTS on `api.4screen.com`**. SPF and DMARC (`p=reject`) present; no DNSSEC, no CAA. ## Company - [Website](https://4screen.com/) - [FAQ — the closest thing to integration documentation](https://4screen.com/faqs/) - [News](https://4screen.com/news/) - [Case studies](https://4screen.com/case-studies/) - [Contact](https://4screen.com/contact-us/) - [Customer portal (credentials required)](https://portal.4screen.com/) - [Status page (private — redirects to login)](https://status.4screen.com/) - [GitHub organization](https://github.com/4screen) — one repo, a fork of Elementary's dbt package. No first-party code. - [Privacy policy](https://4screen.com/privacy-policy/) - [Legal notice / Impressum](https://4screen.com/legal-notice/) — 4.screen GmbH, Sailerstraße 17, 80809 München; Amtsgericht München HRB 259171. - [Advertising conditions — Europe](https://4screen.com/advertising-conditions-europe/) - [Advertising conditions — US](https://4screen.com/advertising-conditions-us/) ## Not published No pricing or plans (contact-sales only, both sides). No rate limits. No SLA. No changelog. No versioning or deprecation policy. No public status page. No SDK on any registry. No MCP server. No A2A agent card. No AsyncAPI or webhook catalog. No `llms.txt` of their own — `https://4screen.com/llms.txt` returns HTTP 404.