# Ford Motor Company — API surface > Ford operates a partner-facing API program through the Ford Developer Marketplace at > developer.ford.com. The flagship surface is FordConnect, which lets an approved application read > connected-vehicle data and issue vehicle commands for enrolled Ford and Lincoln vehicles, with the > vehicle owner's consent captured per data category in the FordPass account-linking flow. Access is > not self-serve: an application is registered in a Ford developer account, data categories are > selected, and credentials (a client id plus two rotating secrets with expiry dates) are issued. > Ford publishes no OpenAPI, no prices, no rate limits, no changelog and no status page on any > surface reachable without signing in. This file was generated by API Evangelist on 2026-09-10 from Ford's own public developer surface. Ford does not publish an llms.txt; https://developer.ford.com/llms.txt returned 404. This is a third-party description. It is not published or endorsed by Ford. ## Authentication - [OpenID Connect discovery document](https://dah2vb2cprod.b2clogin.com/914d88b1-3523-4bf6-9be4-1b96b4f6f919/B2C_1A_signup_signin_common/v2.0/.well-known/openid-configuration): Ford's Azure AD B2C consumer tenant. OAuth 2.0 authorization-code grant; the only OIDC scope advertised is `openid`. Access tokens are RS256 JWTs sent as `Authorization: Bearer`. - [FordConnect account linking / consent](https://fordconnect.cv.ford.com/common/login): where the vehicle owner approves the data categories an application requested. - [Developer account dashboard](https://developer.ford.com/my-developer-account/my-profile): where client id and secrets are issued and rotated. Redirect URIs: 1 required, maximum 5, https only except http://localhost. ## Permissions — data categories, not OAuth scopes Ford grants access as fourteen named data categories, chosen at credential creation and consented to by the vehicle owner. They are: Charging Data, Driving Data, EV Data, Trip Data, Specialty Vehicle Manufacturer Data, Vehicle Data, Vehicle Health, Vehicle Location, Vehicle Security, Dynamic Charging, Vehicle Commands, Vehicle Basic Info, Customer Information, Rewards Information. - Full list with Ford's own definitions: `scopes/ford-scopes.yml` in this repository. ## Data dictionary Ford publishes definitions for 136 connected-vehicle signals — SPEED, TIRE_PRESSURE, XEV_PLUG_CHARGER_STATUS, SEAT_BELT_STATUS and so on — as its Data Category Dictionary. - Harvested verbatim: `vocabulary/ford-data-dictionary.yml` in this repository. ## Hosts - `https://api.vehicle.ford.com` — live FordConnect API host; real v3 paths answer 401 unauthenticated. This is the host Ford's own account-linking application calls. - `https://api.mps.ford.com` — the base declared in this repository's OpenAPI files and in Ford's historical FordConnect documentation. As of 2026-09-10 it returns HTTP 503 "no healthy upstream" from Apigee on every path. - `https://developers.saapi.ford.com` — Ford SA API Developer Portal; gated behind Microsoft Entra ID sign-in. ## Documentation - [Ford Developer Marketplace](https://developer.ford.com/): the developer portal. It renders client-side; API reference content and any OpenAPI live behind sign-in. - [API catalog](https://developer.ford.com/apis) - [WLTP Emissions API](https://developer.ford.com/emissions): retrieve WLTP emissions values for a given vehicle configuration. - [Use cases](https://developer.ford.com/use-cases) - [About the program](https://developer.ford.com/about-us) - [Contact](https://developer.ford.com/contact-us) ## Terms and policy - Ford Developer Programme Terms and Conditions (served in the portal's own content bundle). Notable: Ford may modify the documentation and materials **without prior notice** (11.2), may terminate access **with or without advance notice** (13.1), is **under no obligation** to provide support (7.1), and reserves the right to start charging for access without advance notice (13.1). - [Terms of service](https://www.ford.com/help/terms/) - [Privacy policy](https://www.ford.com/help/privacy/) ## Security - [Ford Vulnerability Disclosure Program (HackerOne)](https://hackerone.com/ford): coordinated disclosure, no bounty. Ford serves no security.txt on any host we could reach. ## What Ford does not publish - No public OpenAPI, AsyncAPI, GraphQL schema or Protobuf. The portal fetches swagger data from `/v1/api-catalog/apis/`, which is not served to anonymous callers. - No MCP server, no A2A agent card, no `/.well-known/api-catalog`, no `llms.txt`. - No first-party SDK on npm, PyPI, RubyGems or in github.com/Ford or github.com/FordLabs. - No pricing, no rate limits, no changelog, no status page, no deprecation policy.