Developers
A REST API for car photos
Post photo URLs and get studio renders back. Turn a walk-around video into a 360° spin, look a vehicle up by VIN, and have a signed webhook tell your system when the work is done.
- OpenAPI 3.1, no key to read it
- Scoped, revocable keys
- Signed webhooks

# one photo in, a finished image out
curl -X POST https://app.autorestage.com/api/v1/renders \
-H "Authorization: Bearer $AUTORESTAGE_KEY" \
-H "Content-Type: application/json" \
-d '{"background_id":"11475",
"images":[{"url":"https://you/front.jpg"}]}'
# 202 {"render_id":"sku_179…","status":"processing"}
Endpoints
Every endpoint, in one table.
Base URL https://app.autorestage.com/api/v1. JSON in, JSON out, and every endpoint is described in the OpenAPI spec.
| Method | Path | What it does |
|---|---|---|
| GET | /openapi.json | The machine-readable contract (OpenAPI 3.1). No key needed. |
| GET | /account | Which key this is, its scopes, and the account's balance. |
| GET | /credit | The balance and every line charged against it, up to 500 at a time. |
| GET | /backgrounds | The studios this key may render onto, with thumbnails. |
| POST | /images/validate | Free checks before you render: exterior or interior, body type, angle, tilt, and whether the car is cut off. Up to 20 images. |
| POST | /renders | Start a render: up to 50 public https image URLs and a background_id. Answers 202. |
| GET | /renders/{id} | Status and the finished images. |
| POST | /spins | Turn a walk-around video (a public https URL, up to 500 MB) into a spin of 12 to 72 frames. |
| GET | /spins/{id} | Every frame, a viewer URL for an iframe, and the video tour once it is made. |
| POST | /merchandise/process | Process a vehicle by VIN, stock number or registration: up to 200 photos and one video. |
| GET | /merchandise | One vehicle and everything made for it, found by VIN, stock number, registration or dealerVinId. |
Webhooks
Told when it is done, with proof it was us.
Register an endpoint in the console and every render and spin that finishes or fails is posted to it, signed with your secret. Or give a webhook_url on a single request.
render.succeeded,render.failed,spin.succeeded,spin.failed- Signed in
X-Spin-Signature: HMAC-SHA256 over the timestamp and the raw body - Tried again after 5 seconds, 30 seconds and 2 minutes if your endpoint is down
// The receiver's check, as our own tests run it.
const crypto = require('crypto');
function verify(secret, header, rawBody) {
const m = /t=(\d+),v1=([0-9a-f]+)/i.exec(header || '');
if (!m) return false;
const t = Number(m[1]);
if (Math.abs(Math.floor(Date.now() / 1000) - t) > 300) return false;
const want = Buffer.from(crypto.createHmac('sha256', secret)
.update(`${t}.${rawBody}`).digest('hex'));
const got = Buffer.from(m[2].toLowerCase());
return got.length === want.length && crypto.timingSafeEqual(got, want);
}
Safe to integrate
The details that save an incident.
The key goes in a header
Authorization: Bearer. A key sent in the query string is refused, because by then it is already in somebody's logs.Keys you can scope and revoke
Made in the console under Settings → Developers and shown once. Scopes:
renders:write,renders:read,backgrounds:read.Rate limits you can see
Every reply carries
X-RateLimitheaders, and a 429 says how long to wait inRetry-After. Reads and writes are counted apart.Retries that do not charge twice
Send an
Idempotency-Keywith a POST and a retry gets the first answer back instead of a second render.Only public https URLs
Image, video and webhook URLs must be public https addresses; private ones are refused.
Other accounts' work is invisible
A render that belongs to another account answers 404, the same as one that does not exist.
What it costs
The API comes with Lot and up.
API calls draw on the same balance as the console, and GET /credit lists every line charged against it. A job that fails on our side is given back. Each vehicle is up to 30 photos, a 360° spin and a video tour.
- 30photos restaged on a studio set
- 1360° spin, up to 72 frames
- 1video tour
Free trial
3 vehicles · no card
$0to start
Solo
40 vehicles a month · $39 a month
$0.98a vehicle
Lot
150 vehicles a month · $119 a month
REST API and webhooks start here.
$0.79a vehicle
Dealership
500 vehicles a month · $299 a month
$0.60a vehicle
Group
1,500 vehicles a month · $699 a month
A dealer group or a marketplace.
$0.47a vehicle
Questions
Asked by developers.
Where do I get an API key?
In the console, under Settings → Developers. A key is shown once, when it is made: give it only the scopes it needs, and revoke it there if it leaks.
Which plans include the API?
Lot and up. Every key has the same rate limits, with reads and writes counted apart. See pricing.
Is there a spec I can generate a client from?
Yes: an OpenAPI 3.1 document at app.autorestage.com/api/v1/openapi.json. It needs no key, so you can read it before you sign up.
How do I know when a render is finished?
Poll GET /renders/{id}, give a webhook_url on the request, or register a webhook in the console for every job. A webhook_url on one request is signed with your account's webhook secret when you have one; without one it arrives unsigned.
Can I look a vehicle up by VIN?
Yes. Process a vehicle by VIN, stock number or registration with POST /merchandise/process, then fetch it and everything made for it with GET /merchandise?vin=. A vehicle that belongs to another dealership answers 404.
Get a key, render a car.
Start with three free vehicles in the console. The API comes with the Lot plan and up.