Skip to main content
Documentation

Vehicles

vehicles.find_by_vin

Find a vehicle by its VIN
Read-onlyRead budget

REST

Shipping
POST /api/v1/vehicles/find_by_vin

MCP tool

Live
vehicles.find_by_vin

Exposed on: REST API · Shop MCP server · Claude connector · Dash (in-app copilot) · Zapier. Part of the Vehicles domain.

Operating contract

Exact VIN lookup across the whole shop. The VIN is normalised first, so spaces and lower case are fine.

A VIN IS SEVENTEEN CHARACTERS. Anything shorter is a partial scan, not a VIN, and this refuses it rather than matching something that happens to start the same way — a partial match here is how one car becomes three records.

found is null when the shop has never seen that VIN, which is a normal answer. When it is set, found.customer_id tells you whose garage it is already in — check that before creating anything.

Who may call it

Permission
customers.accessThe caller must hold Customers at the ACT level. A read-only dashboard grant on the same section is refused.
Plan
Every planNo plan gate. Available on every Service VIN plan.
Retries
naturalNaturally idempotent — running it twice leaves the same world as running it once. A retrying integration needs no key.
Rate class
readCounted against the read budget — the widest of the four.

Input

FieldTypeDescription
vinrequiredstringmax 24 chars, min 17 chars

The full 17-character VIN. Case and spacing do not matter.

Output

FieldTypeDescription
foundobject | null

found.idstring

found.customer_idstring

found.labelstring | null

found.yearnumber | null

found.makestring | null

found.modelstring | null

found.trimstring | null

found.colorstring | null

found.vinstring | null

found.license_platestring | null

found.mileagenumber | null

found.vehicle_typestring

found.created_atstring

Examples

Built from this capability's own schema — required fields and the ones carrying a default, and nothing invented. Paste one and it validates.

curl
export SERVICEVIN_API_KEY=svk_live_…

curl -X POST https://www.servicevin.com/api/v1/vehicles/find_by_vin \
  -H "Authorization: Bearer $SERVICEVIN_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"vin":"…"}'

TypeScript (fetch)
const res = await fetch("https://www.servicevin.com/api/v1/vehicles/find_by_vin", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.SERVICEVIN_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    "vin": "…"
  }),
});

// Success and failure are both envelopes. Switch on error.code, never
// on error.message — the codes are stable, the messages are for people.
const payload = await res.json();
if (!res.ok) throw new Error(payload.error.code);
const data = payload.data;

Python (requests)
import os, requests

res = requests.post(
    "https://www.servicevin.com/api/v1/vehicles/find_by_vin",
    headers={"Authorization": f"Bearer {os.environ['SERVICEVIN_API_KEY']}"},
    json={
    "vin": "…"
},
    timeout=30,
)
payload = res.json()
if not res.ok:
    raise RuntimeError(payload["error"]["code"])
data = payload["data"]

MCP tools/call — https://www.servicevin.com/api/mcp
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "vehicles.find_by_vin",
    "arguments": {
      "vin": "…"
    }
  }
}

Refusals

The four gates run in this order on every surface, and the order is not arbitrary — see Authentication.

StatusCodeWhen
404not_foundThe id is unknown, or the feature is not enabled for this account. Deliberately the same answer for both.
403forbiddenThis login does not hold customers.access.
422validation_errorAn argument was wrong. The message names the field.
429rate_limitedToo many read calls. Back off and retry.
500internal_errorSomething failed on our side. Nothing was changed.