# Autopay > Autopay Technologies AS is a Norwegian parking platform. It runs free-flow ANPR (automatic > number-plate recognition) parking, EV charging and toll-road management for airports, > hospitals, hotels, business parks, shopping centres, municipalities and private toll roads, > and exposes fourteen REST APIs so operators, landlords, tenants, fleets, loyalty programmes > and third-party payment providers can integrate with it. The vehicle registration plate is > the join key across the whole platform. Generated by API Evangelist on 2026-09-06 from the provider's public developer portal. Autopay does not publish an llms.txt of its own — https://autopay.io/llms.txt returns the single-page app's HTML shell (HTTP 200, text/html), which is a soft 404, not a document. ## How to call it - Base URL: `https://api.autopay.io` - Auth: OAuth 2.0 client credentials. `POST https://api-auth.autopay.io/oauth/token` with a JSON body of `client_id`, `client_secret`, `audience` (always `https://api.autopay.io`) and `grant_type` (always `client_credentials`). Send the result as `Authorization: Bearer `. Note the body is JSON, not form-encoded. - Tokens last 10-24 hours (read `expires_in`). CACHE THE TOKEN. Minting a new token per request "may lead to termination of API access" — this is the provider's own wording. - Credentials are issued by a human and are bound to ONE operator. Multi-operator integrations hold one credential pair per operator. - Errors come back as `{"error_id": "...", "message": "...", "description"?: "..."}` — branch on `error_id`. The token endpoint is the exception and uses the OAuth `{"error","error_description"}` shape. - No idempotency key, no request-id header, no rate-limit headers, no 429, no sandbox. ## Documentation - [Developer portal](https://developer.autopay.io/): index of all fourteen API references - [Authentication](https://developer.autopay.io/authentication/): the token endpoint and its errors - [API Usage Agreement](https://developer.autopay.io/usage_agreement/): the terms every integrator accepts - [API Deprecation](https://developer.autopay.io/api_deprecation/): dated breaking changes, six months' notice - [Help centre](https://help.autopay.io/kb/en) - [Autopay Technologies](https://solutions.autopay.io/): the company site - [ISO certifications](https://solutions.autopay.io/about-us/iso-certifications): ISO 9001, ISO 14001, ISO 27001, GDPR ## APIs - [Accounting API](https://developer.autopay.io/accounting/): `GET /accounting/v1/invoices` — invoice and sales export for ERP reconciliation. Query by data-update time (`from`/`to`) OR invoice date (`invoice_date_from`/`invoice_date_to`), never both. Receipts and ANPR event images are JWT-protected (`receipt_url_with_auth`, `image_url_with_auth`) and expire — download them, do not store the URL. - [Booking API](https://developer.autopay.io/booking_api/): pre-book a permit for a vehicle. `GET /booking/v3/permit_definitions`, `GET /booking/v3/availability`, `GET /booking/v3/{id}/status`, `POST /booking/v3`, `PUT /booking/v3/{id}`, `DELETE /booking/v3/{id}`. Scope `permit_booking`. Status polling is limited to one call per 900 seconds per booking. - [Customer Club API](https://developer.autopay.io/customer_club_api/): loyalty membership. `POST /customer_club/v2/join`, `GET /customer_club/v2/status/{registrationId}`, `DELETE /customer_club/v2/leave/{registration_id}`, `POST /customer_club/v2/add_vehicle`, `DELETE /customer_club/v2/remove_vehicle/{vehicle_id}`, `GET /customer_club/v2/get_vehicle_id/{hashed_license_plate_number}`. Scope `customer_club`. - [Fleet API](https://developer.autopay.io/fleet-api/): company fleets. `GET|POST|DELETE /fleet/v2/vehicles`, `POST /fleet/v2/vehicles/detach`, `GET /fleet/v2/services` (+ `/by_updated_at`, `/by_end_time`), `GET /fleet/v2/vehicles/services`, `POST /fleet/v2/vehicles/disable_payments`. Cursor-paginated. - [Parking API](https://developer.autopay.io/parking_api/): entry webhook plus `PUT /parking/product/{parkingSessionId}` to change what a live session is charged. - [Payment API](https://developer.autopay.io/payment_api/): `POST /payment/v1/connect_parking` to take billing responsibility for a live session, `POST /payment/v1/manual_stop` when an exit event is missed. Autopay calculates the cost; the provider charges the customer. Both a success and a cancel callback are delivered to URLs you host. - [Permit Landlord API](https://developer.autopay.io/permit_landlord_api/): landlord-side permit definitions, tenants and allocations under `/permit/v2/landlord/{landlordId}/...`. - [Permit Operator API](https://developer.autopay.io/permit_operator_api/): `GET /permit/v1/landlords`. - [Permit Tenant API](https://developer.autopay.io/permit_tenant_api/): `GET /permit/v3/tenant_permit_allocations`, `GET /permit/v3/tenant_issued_permits`, `POST|PUT|DELETE /permit/v3/end_user_permit`. - [Price API](https://developer.autopay.io/price_api/): `PUT /price/v1/product/{id}` — REGULAR, DYNAMIC and ACCUMULATIVE_24H_MAX price types with weekday/duration restrictions. - [Statistics API](https://developer.autopay.io/statistics_api/): `GET /statistics/v1/parking` — parking statistics export, cursor-paginated. - [Status API](https://developer.autopay.io/status_api/): `GET /status/v1/zone/{zone_code}` and `/zone_details/{zone_code}` for live zone occupancy. Scope `zone_status`. - [Tap & Park API](https://developer.autopay.io/tapnpark_api/): `POST /tnp/validation` — validate a parking session for a vehicle. - [Vehicle API](https://developer.autopay.io/vehicle_api/): `GET /vehicle/v1/permit` — permit and active-session lookup for a plate in a zone. ## Events (Autopay calls you) - Parking entry webhook: fired when a vehicle enters a zone. Carries `event_id`, `parking_id`, `parking_session_id`, plate, zone, facility and time zone. Corrections are redelivered with the SAME `event_id` — upsert, do not append. Retried up to 50 times until a 2xx. - Payment success callback: final cost as net/VAT/gross in local currency. Charge the customer. - Payment cancel callback: the session errored, do not charge. - Fleet service webhook (Enterprise fleet profiles): a fleet vehicle parked or passed a toll road. - Payment callbacks retry with exponential backoff from 1s to hourly, for one week, and MAY be delivered more than once — de-duplicate on `parking_id`. ## Before an agent acts - `POST /payment/v1/connect_parking` is the one irreversible call on this surface. It claims a live session for billing; a second claim returns `server_communication_error`. Confirm the vehicle and the area code first, and never retry it blindly on a network error. - `POST /payment/v1/manual_stop` is not an undo — it closes the session and produces a real charge. - A booking can be deleted only while its status is `NOT_USED`; `USED` and `EXPIRED` bookings cannot be changed or deleted, and `valid_from` and the plate are frozen once it is `IN_USE`. - There is no staging environment. "There is no formal staging environment for the Payment API at present." - Plate country coding is inconsistent: ISO 3166-1 alpha-2 on the webhooks, alpha-3 on the Payment API. ## Commercial - No published pricing. Accounting, Booking, Parking and Fleet are each described as "a paid service" with access arranged through an Autopay representative. Fleet also gates its webhook behind an unpriced "Enterprise" fleet profile level. - No self-serve signup, no developer console, no free tier. - Breaking changes are published six months in advance on the deprecation page and emailed to the integrator's registered Technical Contact Person. Register one with partner-support@autopay.io. - Governing law: Norway. ## Contact - Technical and integration: partner-support@autopay.io - Sales: sales@autopay.io - Security: security@autopay.io (https://autopay.io/.well-known/security.txt) ## Not published Autopay does not publish an OpenAPI, AsyncAPI, GraphQL schema, Postman collection, SDK, CLI, MCP server, A2A agent card, changelog, status page, SLA or sandbox. The machine-readable artifacts in this repository are API Evangelist's independent reading of the public documentation, not Autopay's own.