# AutoFi > AutoFi ("The Sales Momentum Company") is an AI-powered automotive commerce platform connecting online and in-store car buying for dealerships, OEMs, lenders and marketplaces. It publishes a REST API — its Lending-as-a-Service surface — at api.autofi.com: JWT client-credential authorization, loan application creation with lender decisioning through RouteOne and DealerTrack, Dealmaker deal and credit-application creation, dealer lookup, cash/finance/lease payment estimation, and prequalification. A UAT sandbox at api-uat.autofi.com can simulate specific lender decisions. This document is generated by the API Evangelist enrichment pipeline; AutoFi serves no llms.txt of its own (https://www.autofi.com/llms.txt returns HTTP 404). ## APIs - [AutoFi API reference](https://api.autofi.com/api.html): OpenAPI 3.0.0, 11 operations across Authorization, Loan Applications, Dealers, Dealmaker, Calculate Payment and Prequalification. Redoc bundle; the spec is embedded in the page. - Production base URL: https://api.autofi.com - Test sandbox base URL: https://api-uat.autofi.com ## Operations - `POST /auth/token`: Exchange clientId + clientSecret for a JWT access token. - `POST /v1/loan-application`: Create a loan application and route it to lenders. - `GET /v1/loan-application/{loanApplicationId}`: Read application state, lender decisions and pricing stack. - `GET /v1/loan-application/{loanApplicationId}/externalResources`: DMS links (experimental). - `POST /v1/dealer/lookup`: Resolve AutoFi dealer codes from OEM brand and sales codes. - `POST /v1/dealmaker`: Create a Dealmaker deal (experimental). - `POST /v1/dealmaker/credit-application`: Create a Dealmaker credit application (experimental). - `POST /v1/estimate/cash`: Cash payment estimate. - `POST /v1/estimate/finance`: Finance payment estimate. - `POST /v1/estimate/lease`: Lease payment estimate. - `POST /v1/prequalification`: Soft prequalification returning a credit score range. ## Agent surfaces - [MCP server](https://www.autofi.com/wp-json/mcp/mcp-oauth-server): live, OAuth-protected (scope `mcp`). Discovered via RFC 9728 protected-resource metadata. This is a WordPress content surface on the marketing site, not a wrapper around the lending API. Anonymous `tools/list` returns 401. - [OAuth authorization server metadata](https://www.autofi.com/.well-known/oauth-authorization-server/): RFC 8414, authorization_code + refresh_token, PKCE S256. - [OAuth protected resource metadata](https://www.autofi.com/.well-known/oauth-protected-resource/): RFC 9728. - No A2A agent card is served on any AutoFi host. ## Specs and artifacts - [OpenAPI (harvested)](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/openapi/autofi-api-openapi.yml) - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/authentication/autofi-authentication.yml) - [Scopes](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/scopes/autofi-scopes.yml) - [Conventions](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/conventions/autofi-conventions.yml) - [Error catalog](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/errors/autofi-problem-types.yml) - [Webhook / callback catalog](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/asyncapi/autofi-webhooks.yml) - [Data model](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/data-model/autofi-data-model.yml) - [Sandbox](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/sandbox/autofi-sandbox.yml) - [Rate limits](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/rate-limits/autofi-rate-limits.yml) - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/lifecycle/autofi-lifecycle.yml) - [MCP](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/mcp/autofi-mcp.yml) - [Agent skills](https://raw.githubusercontent.com/api-evangelist/autofi/refs/heads/main/skills/_index.yml) ## Company - [AutoFi](https://autofi.com): AI-powered automotive sales and digital retailing platform. - [Platform](https://www.autofi.com/platform/): Product overview. - [News / Press](https://www.autofi.com/news/): Dated press coverage, partnership announcements, product news. - [Support](https://www.autofi.com/support/): Customer support. - [Book a demo](https://www.autofi.com/request-demo/): The commercial entry point — there is no self-serve signup or published pricing. - [Login](https://portal.autofi.com/login): Dealer/partner portal. - [Status](https://status.autofi.com): Atlassian Statuspage, including a "LaaS APIs" component. - [Trust portal](https://trust.autofi.com/): SafeBase; SOC 2, SOC 3, CCPA. Vulnerability reports to security@autofi.com. - [Terms and conditions](https://www.autofi.com/terms-and-conditions/) - [Privacy policy](https://autofi.com/privacy-policy/) - [GitHub](https://github.com/AutoFi): 4 public repositories, none a client library for the AutoFi API. ## Notes for agents - No SDK exists in any public package registry. Call the REST API directly. - No idempotency key is supported on any creation endpoint. - Event delivery is via a caller-supplied `callbackUrl` with no retry and no signature — poll `GET /v1/loan-application/{loanApplicationId}` to reconcile. - Credentials are issued by AutoFi to partners; there is no self-serve API signup. - Method: generated by the API Evangelist enrichment pipeline, 2026-08-14. Source: https://api.autofi.com/api.html