Skip to content

Authentication

The API uses a two-step process: a short-lived session token obtained with a username and password, and a permanent API token that is the one used in day-to-day requests.

Ventana de terminal
curl -X POST "https://api-dev.zonaparqueo.com/external/login" \
-H "Content-Type: application/json" \
-d '{
"username": "your_username",
"password": "your_password",
"version": "T-1.0.0"
}'
{ "login": "ok", "id": 4638, "token": "abc123...", "minutos": 60 }

The version field is required and identifies the integrating service version. If login is not ok, the credentials are invalid.

The session token from the previous step goes in the token header (not Authorization):

Ventana de terminal
curl -X POST "https://api-dev.zonaparqueo.com/external/generar-token-api" \
-H "Content-Type: application/json" \
-H "token: abc123..." \
-d '{
"nombre": "my-integration",
"expiracion": "2027-12-31 23:00:00"
}'
{ "token_id": "ABC123", "secret": "XYZ789", "usuario": 4638 }

Store token_id and secret: they cannot be read back except through GET /external/get-token-api using the same nombre.

Every other request carries:

Authorization: Token {token_id}:{token_secret}

For example:

Ventana de terminal
curl -X GET "https://api-dev.zonaparqueo.com/external/tramos" \
-H "Authorization: Token ABC123:XYZ789"

Reservations created by on-street personnel are registered under the integration’s operator client, because ZonaParqueo has no concept of an individual operator. That client identifier should be configured explicitly.