Authenticated v302 endpoints use a personal owner API token. The token identifies the account and grants access to its vehicle inventory and additional options.
Get a token
The token is issued automatically when a Vehicle Owner account is registered. There is nothing to generate and no call with the team is needed.
- Sign in to getrentacar.com as a Vehicle Owner.
- Open Settings → Additional options. The API access token field shows your token.
- Copy it immediately into your server-side secret storage.
The same section shows API user_id — the number that vehicle management methods expect in the user_id parameter. Copy it together with the token: the token alone is not enough to build a request.
Resetting a token immediately invalidates the previous token. Rotate it only after every integration has been updated.
API versions
This site is the human-readable guide to v302 and ships an interactive console for the documented methods. The v302 specification itself is published at GET /api/v302/openapi.yaml; /api/v302/openapi.json returns the same document as JSON.
The default API version is v306, and its OpenAPI specification is public as well, at GET /v306/openapi.yaml and GET /v306/openapi.json — note that these two paths carry no /api prefix. Treat the v306 specification as the current contract. Fleet submission clients can read the machine-readable contract at GET /api/v400/fleet/schema.
Documentation builds left over from earlier versions may still be reachable; they are not maintained.
Send the token
Use the standard Authorization request header:
Authorization: Bearer {YOUR_API_TOKEN}
Example:
curl --request GET \ --url "https://getrentacar.com/api/v302/vehicles/list?user_id=<USER_ID>&locale_id=40" \ --header "Accept: application/json" \ --header "Authorization: Bearer {YOUR_API_TOKEN}"
Security requirements
- Never commit a token to Git or include it in screenshots, browser URLs, analytics, or logs.
- Keep production and test credentials separate.
- Send requests only over HTTPS.
- Store tokens in an encrypted secrets manager or protected environment variable.
- Rotate a token immediately if it may have been exposed.
- Do not place the token in the query string. The legacy
api_keyparameter exists for compatibility but should not be used for new integrations.
Authentication errors
| HTTP status | Meaning | Action |
|---|---|---|
401 | Token is absent or malformed | Send Authorization: Bearer … |
400 | Token or owner context is invalid | Verify the token and user_id |
200 with is_success: false | Account role or resource access is insufficient | Verify ownership and owner permissions |