DVLA Authentication API
- URL
-
https://driver-vehicle-licensing.api.gov.uk/thirdparty-access - Spec
- https://developer-portal.driver-vehicle-licensing.api.gov.uk/apis/authentication-api/authentication-api.json
- Docs
- https://developer-portal.driver-vehicle-licensing.api.gov.uk/apis/authentication-api/authentication-api-description.html
api_key=<credential> This username and initial one-time password are issued by DVLA as part of secure API onboarding. Per the Authentication API guide, first-time setup is: receive username and one-time password from DVLA, change the one-time password using the Authentication API, then use the username and password to obtain JWTs. Access to these credentials comes through the relevant secure API onboarding process described in the DVLA API Developer Portal.
x-api-key: <credential> + DVLA JWT ID token Authorization: <credential> discovered Access is issued by DVLA during API onboarding. For secure APIs, the portal says a username, one-time password, API key and API URLs are supplied as part of onboarding; for VES and KADOE the individual API guide describes registration/apply steps. Start from the relevant API guide in the DVLA API Developer Portal; for KADOE use the Apply link, and for secure APIs follow DVLA onboarding so DVLA issues your x-api-key/X-API-Key.
Mint this token by calling the DVLA Authentication API. The guide states the secure pattern is two-step: authenticate with your DVLA-issued username and password to get a JWT ID token with a 1-hour expiry, then send that token in Authorization together with your API key when calling secure APIs.