Authentication
The API uses a two-step process: a short-lived session token obtained with a username and password, and a permanent API token that is the one used in day-to-day requests.
Step 1 — Log in
Section titled “Step 1 — Log in”curl -X POST "https://api-dev.zonaparqueo.com/external/login" \ -H "Content-Type: application/json" \ -d '{ "username": "your_username", "password": "your_password", "version": "T-1.0.0" }'{ "login": "ok", "id": 4638, "token": "abc123...", "minutos": 60 }The version field is required and identifies the integrating service version.
If login is not ok, the credentials are invalid.
Step 2 — Generate the API token
Section titled “Step 2 — Generate the API token”The session token from the previous step goes in the token header (not Authorization):
curl -X POST "https://api-dev.zonaparqueo.com/external/generar-token-api" \ -H "Content-Type: application/json" \ -H "token: abc123..." \ -d '{ "nombre": "my-integration", "expiracion": "2027-12-31 23:00:00" }'{ "token_id": "ABC123", "secret": "XYZ789", "usuario": 4638 }Store token_id and secret: they cannot be read back except through
GET /external/get-token-api using the same nombre.
Step 3 — Use the token
Section titled “Step 3 — Use the token”Every other request carries:
Authorization: Token {token_id}:{token_secret}For example:
curl -X GET "https://api-dev.zonaparqueo.com/external/tramos" \ -H "Authorization: Token ABC123:XYZ789"Operator client
Section titled “Operator client”Reservations created by on-street personnel are registered under the integration’s operator client, because ZonaParqueo has no concept of an individual operator. That client identifier should be configured explicitly.
