Skip to content
Developers API v302
Developer documentation

Authentication

Authenticated v302 endpoints use a personal owner API token. The token identifies the account and grants access to its vehicle inventory and additional options.

Get a token

The token is issued automatically when a Vehicle Owner account is registered. There is nothing to generate and no call with the team is needed.

  1. Sign in to getrentacar.com as a Vehicle Owner.
  2. Open Settings → Additional options. The API access token field shows your token.
  3. Copy it immediately into your server-side secret storage.

The same section shows API user_id — the number that vehicle management methods expect in the user_id parameter. Copy it together with the token: the token alone is not enough to build a request.

Resetting a token immediately invalidates the previous token. Rotate it only after every integration has been updated.

API versions

This site is the human-readable guide to v302 and ships an interactive console for the documented methods. The v302 specification itself is published at GET /api/v302/openapi.yaml; /api/v302/openapi.json returns the same document as JSON.

The default API version is v306, and its OpenAPI specification is public as well, at GET /v306/openapi.yaml and GET /v306/openapi.json — note that these two paths carry no /api prefix. Treat the v306 specification as the current contract. Fleet submission clients can read the machine-readable contract at GET /api/v400/fleet/schema.

Documentation builds left over from earlier versions may still be reachable; they are not maintained.

Send the token

Use the standard Authorization request header:

Authorization: Bearer {YOUR_API_TOKEN}

Example:

curl --request GET \ --url "https://getrentacar.com/api/v302/vehicles/list?user_id=<USER_ID>&locale_id=40" \ --header "Accept: application/json" \ --header "Authorization: Bearer {YOUR_API_TOKEN}"

Security requirements

  • Never commit a token to Git or include it in screenshots, browser URLs, analytics, or logs.
  • Keep production and test credentials separate.
  • Send requests only over HTTPS.
  • Store tokens in an encrypted secrets manager or protected environment variable.
  • Rotate a token immediately if it may have been exposed.
  • Do not place the token in the query string. The legacy api_key parameter exists for compatibility but should not be used for new integrations.

Authentication errors

HTTP status Meaning Action
401 Token is absent or malformed Send Authorization: Bearer …
400 Token or owner context is invalid Verify the token and user_id
200 with is_success: false Account role or resource access is insufficient Verify ownership and owner permissions