generated: '2026-09-13' method: searched source: https://developers.hyundai.com/web/v1/hyundai/specification/account/account_token docs: - https://developers.hyundai.com/web/v1/hyundai/specification/account/account_authorize - https://developers.hyundai.com/web/v1/hyundai/specification/account/account_token - https://developers.hyundai.com/web/v1/hyundai/guide_api - https://developers.hyundai.com/web/v1/hyundai/guide_console provider: Hyundai providerId: hyundai api: Hyundai Developers Connected Car API note: >- Hyundai Developers uses the Hyundai integrated account (현대자동차 통합계정) as its identity provider and states plainly in its own console guide that "현대자동차 통합계정은 OAuth 2.0 을 지원하고 있습니다" — the integrated account supports OAuth 2.0. There is no published OpenAPI, so this profile is read from the provider's own API specification pages rather than derived from securitySchemes. schemes: - id: oauth2_authorization_code type: oauth2 flow: authorizationCode description: >- Three-legged authorization code flow against the Hyundai integrated account. The partner application redirects the vehicle owner to the authorize endpoint; the owner signs in, is shown their vehicle list, and consents per vehicle. Only vehicles the owner explicitly selects become readable. Shared vehicles are excluded from the list. authorization_url: https://prd.kr-ccapi.hyundai.com/api/v1/user/oauth2/authorize token_url: https://prd.kr-ccapi.hyundai.com/api/v1/user/oauth2/token authorize_parameters: - name: response_type required: true value: code - name: client_id required: true description: Client ID issued when the console project is registered - name: redirect_uri required: true description: >- Must match the Redirect URL registered in Console > Settings > Account API; a mismatch is rejected - name: state required: true description: >- CSRF state token generated by the application. The docs explicitly name cross-site request forgery as the threat and require Base64 or URL encoding when special characters are used. scopes_documented: false scopes_note: >- No scope parameter appears in the authorize request and no scope reference page exists. Authorization is granted per API at the project level (the console's API management page lists which APIs a project is approved for) and per vehicle at the consent step, not by OAuth scope string. scopes/ is therefore deliberately not written for this provider. - id: client_basic type: http scheme: basic description: >- The token endpoint authenticates the client with HTTP Basic over the base64(client_id:client_secret) pair issued at project registration. Content-Type must be application/x-www-form-urlencoded. applies_to: - POST /api/v1/user/oauth2/token - id: bearer_access_token type: http scheme: bearer bearer_format: opaque description: >- Every user, vehicle-profile, vehicle-status and warning-light operation is called with `Authorization: Bearer {access_token}`. applies_to: - GET /api/v1/user/profile - GET /api/v1/car/profile/carlist - GET /api/v1/car/profile/{carId}/contract - GET /api/v1/car/status/{carId}/* - GET /api/v1/car/status/warning/{carId}/* - GET /api/v1/car-service/terms/reject - id: admin_key_b2b type: apiKey in: header description: >- A separate server IP allow-list plus Admin Key is issued only to partners who have negotiated a B2B API contract. The console guide states these settings are shown "only when a separate API usage agreement has been arranged with us", so the B2B surface is not publicly documented. public: false grant_types: - value: authorization_code purpose: issue a new token pair - value: refresh_token purpose: refresh the access token - value: delete purpose: >- revoke/delete the token — a non-standard grant_type value used in place of an RFC 7009 revocation endpoint token: access_token: transport: Authorization Bearer header documented_lifetime: 24 hours example_expires_in: 7200 discrepancy: >- The specification prose states access_token is valid for 24 hours after issue, while every published success example on the same page returns expires_in: 7200 (2 hours). Recorded as published; not reconciled by the provider. Clients should trust expires_in, not the prose. refresh_token: documented_lifetime: 1 year returned_on: authorization_code grant only token_type: Bearer observed: - probe: GET https://prd.kr-ccapi.hyundai.com/api/v1/user/profile with no Authorization header date: '2026-09-13' status: 401 body: '{"errId":"...","errCode":"4010","errMsg":"Require authentication"}' note: >- Confirms the documented error envelope and the 4010 account-API error code on a live unauthenticated request. consent_model: description: >- Data access requires TWO consents layered on top of OAuth: the vehicle-access consent taken during login, and a separate Korean PIPA third-party-provision consent obtained through POST /api/v1/car-service/terms/agreement. Vehicle data calls fail with 4120 ("Pre-operation is required") until the third-party consent has been completed. principles_published: https://developers.hyundai.com/web/v1/hyundai/intro principle_quote: The customer owns the data and shares if only when the customer agrees.