# General Motors > General Motors operates a developer program for its connected-vehicle, fleet and > commercial data services (OnStar / GM Envolve). The APIs exist and GM markets them, but > the reference and any machine-readable contract are released only to approved commercial > customers and partners — the developer portal's own router guards /docs/* behind a > `requireCommercialAPIAccess` check. Nothing below is a contract; it is a map of what a > public visitor can actually reach. Generated by API Evangelist (https://apievangelist.com) on 2026-09-12 from https://raw.githubusercontent.com/api-evangelist/general-motors/refs/heads/main/apis.yml and the probe artifacts in this repository. This file is NOT published by General Motors. ## Status for agents - No OpenAPI, AsyncAPI, GraphQL SDL, Postman collection or JSON Schema is published at any public URL. Probed on 2026-09-12 against developer.gm.com, api.gm.com, api.onstarfleetintelligence.com, www.gm.com and gm.com. - No hosted MCP server and no A2A agent card. Probed; every /.well-known path either 404s or returns the developer portal's single-page-app shell. - The GM Developer Portal backend (https://developer.gm.com/v1) answers HTTP 403 to every request without a bearer token from GM's Microsoft Entra External ID tenant. The one exception is GET /v1/csrf-token, which answers 200 anonymously. - An agent cannot call a General Motors API today without a signed commercial agreement. ## Public entry points - [GM Developer Portal](https://developer.gm.com/): the front door. Public routes are /, /explore-apis, /app-gallery, /faqs, /contact-us and /view-document. - [API & Data Services](https://developer.gm.com/explore-apis): GM's public description of the commercial API catalog — "Available to approved customers and partners". - [Documentation](https://developer.gm.com/docs/api-data-services): the API reference. Requires sign-in AND approved commercial API access. - [FAQs](https://developer.gm.com/faqs) - [Contact / request access](https://developer.gm.com/contact-us): the sales motion that stands in for self-serve onboarding. - [GM News](https://news.gm.com/): company news and stories. - [GitHub organization](https://github.com/generalmotors): 47 public repos, overwhelmingly upstream mirrors and forks; no first-party API contract or SDK. ## Security - [Vulnerability Disclosure Program](https://hackerone.com/gm) on HackerOne — GM was the first major automaker to run one (2016). Safe harbor is stated. Also cyber@gm.com. - [GM Cybersecurity](https://www.gm.com/cybersecurity) - No /.well-known/security.txt is served on any GM host. ## Legal - [U.S. Consumer Privacy Statement](https://www.gm.com/privacy-statement) - The Developer Portal Website Terms of Use is a PDF served from the authenticated portal backend; there is no public URL for it. ## Client libraries There are no first-party GM SDKs. Every OnStar client library on npm or PyPI is a community project: onstarjs2 (2.16.6), node-red-contrib-onstar2 (3.2.1), onstarjs (2.5.3), and the abandoned PyPI `onstar` (0.1.2, 2019). ## Artifacts in this profile - packages/general-motors-packages.yml — registry search; no first-party SDK - well-known/general-motors-well-known.yml — /.well-known probe across five hosts - authentication/general-motors-authentication.yml — observed portal auth model - security/general-motors-vulnerability-disclosure.yml — HackerOne VDP - security/general-motors-domain-security.yml — TLS/DNS/mail posture - plans/general-motors-plans-pricing.yml — no published plans - rate-limits/general-motors-rate-limits.yml — no published limits