MyRenault app gateway (“myr”)¶
Note
This gateway is not used by renault-api. This page documents observed
behaviour of the official app, for reference only.
The official MyRenault mobile app (6.13.x–6.14.x) talks to two backends:
Backend |
Base URL |
Role |
|---|---|---|
Kamereon (legacy) |
|
Vehicle data, actions, notifications. This is what this library implements (see Renault endpoints). |
myr gateway |
|
App dashboard, remote-feature mapping, connected maintenance, KYC. |
The myr gateway was observed in official-app traffic (iOS 6.13.1, TLS capture)
and cross-checked against the Android APK 6.13.4 (com.renault.myrenault.one.fr,
jadx decompilation). Endpoint availability varies by model and contract: the
observations below come from three vehicles, all in country FR:
a 2025 Renault Espace VI E-Tech full hybrid (XHN1ML), referred to as the HEV;
a full-EV vehicle (XCB1VE);
a 2017 Renault ZOE (X101VE, TCU gen 2), referred to as the ZOE.
Unless stated otherwise, observations come from the HEV.
Authentication¶
The gateway accepts the same Gigya JWT used by Kamereon:
GET /myr/api/v1/... HTTP/1.1
Host: apis.renault.com
apikey: <kamereon api key>
x-gigya-id_token: <Gigya JWT>
apikeyis required (same key as Kamereon). Without it:401 {"errorCode": "10.01.02.01", "errorMessage": "Missing apikey."}.The JWT goes in the
x-gigya-id_tokenheader. The same legacy JWT sent asAuthorization: Beareris rejected (401err.func.wired.unauthorized)./ccx/garage-center/v1/...: the app authenticates with its OIDC access token here (see below). The legacy Gigya JWT inx-gigya-id_tokenwas verified accepted (200) on the ZOE; behavior on other vehicles is not established.
For reference, the official app itself sends an OIDC access token
(Authorization: Bearer at+JWT, TTL 300 s) minted by:
https://gigya-prod-eu1.idconnect.renaultgroup.com/oidc/op/v1.0/{gigya_api_key}/
with client_id: qiXX6GdXSgerKxYqvdAblK_M and scopes
openid email personId lang renaultGroupFull offline_access
(authorization_code + PKCE, no password grant). The {gigya_api_key} EU
value appears in the issuer path.
These constants are extracted from the app binaries. For first-party use of
/myr/api/v1/*, the legacy Gigya JWT in x-gigya-id_token is sufficient.
Endpoints¶
Verified live:
Method |
Path |
Notes |
|---|---|---|
GET |
|
Returns |
GET |
|
Observed |
GET |
|
Returns |
POST |
|
See POST /state below |
GET |
|
Vehicle-dependent: 200 with an empty body on the HEV, 404
( |
GET |
|
Returns |
Present in the APK but not verified live:
Method |
Path |
|---|---|
POST |
|
POST |
|
GET |
|
GET |
|
GET |
|
GET |
|
GET |
|
All of the paths above are still present in APK 6.14.2. That version also
contains the following apis.renault.com paths. They were found by string
extraction only, so the HTTP method was not determined, and they were not
verified live:
/mybrand/kyc/v1/links/mybrand/connected-vehicle/v1/vehicles/{vin}/certificates-status/mybrand/connected-vehicle/v1/vehicles/{vin}/release-notes/ccx/uac/v1/sessions/fcm-token(push-notification token registration)/s13/vkm/vk/v1/(virtual key base path)
POST /state¶
{
"uidveh": [202, 345],
"deliveryDate": "YYYY-MM-DD"
}
uidvehis a list of featureIds (same namespace as/remotesandapplicableFeatures) whose state is requested.deliveryDateis the vehicle delivery (in-service) date.The call is asynchronous: it returns
200with an empty body, and the data surfaces through the app afterwards. Transient502responses (errorCode 12.00.00.03) were observed on the Renault side.Response blocks (per the APK):
sohBlms(hybrid battery healthsoheRef/sohStatus),tirePressure(TPMS),mileage,connectedMaintenance.An
ACTIVATEDfeatureId does not guarantee its block is served: on a tested full-EV (XCB1VE) withuidveh: [345, 202, 831, 820, 204], onlymileagecame back (nosohBlms, notirePressure, no error). Themileageblock matches the Kamereon/cockpitvalue and timestamp.The APK filters the requested ids against
{820, 204, 831, 202, 345}before calling this endpoint, so those five ids are known-accepted (read-only queries: no physical action is triggered).Whether the app displays the battery-health block is decided by remote config, not by featureId 345 alone:
SOH_block_displayed, a server-providedSOH_UID_listof featureIds, and an optionalSOH_filter_vehicle_models. The vehicle-condition menu is shown for{820, 204, 831, 202}plusSOH_UID_list.
Vehicle-level attributes¶
connectedStatus.remoteSecurityProtocol(/connected-vehicles) is a per-vehicle attribute with valuesJWT,SRPorUNKNOWN:JWTon the HEV,SRPon the XCB1VE,UNKNOWNon the ZOE. On an SRP-protocol vehicle, direct Kamereon remote commands were refused (errorCode 6, CONTACT_SRC), while the APK carries SRP-6a remote-service actions (srp-initiates,srp-sets) as the alternative path.The three id representations coincide per vehicle, without any deviation (observed on the HEV and the XCB1VE):
connectedStatus.services(ids as strings),applicableFeaturesfiltered tostatus: ACTIVATED, and the/remotesid list. On the ZOE,applicableFeaturesis absent, andservicesmatches the/remotesid list. The app itself readsservicesonly (a plain presence check); the ACTIVATED filtering is done server-side.privacyModeStatus/privacyModeLastUpdatereflect the MyRenault privacy mode. Their position varies by vehicle: underconnectedStatuson the HEV and the ZOE, undervehicleDetailson the XCB1VE (Mégane E-Tech). When active, it cuts data reporting and is an explicit cause of unavailability, distinct from a contract or account/link issue.
featureIds¶
featureId values are shared by three sources that use the same namespace:
applicableFeatures (/connected-vehicles), featureId
(/remotes) and uidveh (POST /state).
Ids explicitly interpreted by the app 6.13.4 (evidence: jadx decompilation):
featureId |
Meaning |
|---|---|
97 |
Horn and lights ( |
202 |
Mileage ( |
345 |
Hybrid battery health, SOH ( |
299 |
Instant charge (legacy generation) |
362 |
Reachable area on the map ( |
366 |
Instant HVAC ( |
701 |
V2G (vehicle-to-grid) |
740 |
V2L (vehicle-to-load) |
743 |
Plug & Charge |
801 |
Virtual key ONBOARD pairing |
806 |
Instant HVAC with adjustable temperature (requires 806 + 366) |
820 (+ 204) |
Connected maintenance / vehicle alerts |
831 |
Tyre pressure (TPMS) |
833 |
Pause/resume instant charging |
952 / 953 |
EV programmes (variants, role not discriminated) |
954 |
HVAC preconditioning (EV programmes) |
955 |
Scheduled charge programmes + preconditioning; V2G section visibility |
2021 |
Cloud lock-status ( |
3205 |
V2G charge history |
Ids relayed by the app without interpretation (server-side semantics only):
4, 12, 21, 107, 200, 315, 323, 344, 419, 724, 729, 730, 748, 815, 818, 826,
830, 846, 847, 912, 920, 927, 966, 967, 2852, 3302, 1710040. Observed on the
tested HEV (28 ids ACTIVATED) and full-EV (21 ids, adding 315, 344
and 724); none of them has a literal reference in the APK 6.13.4, so their
semantics live server-side only, except 12 and 344 (see below).
The ZOE reports 12 ids in services and /remotes: 202, 288, 311, 315,
317, 319, 322, 362, 366, 408, 723, 725. The ids 288, 311, 317, 319, 322,
408 appear in none of the lists on this page.
The app maps featureIds to named flags in
com.renault.core.utils.ServiceMappingConfig (property names recovered from
the Kotlin metadata). Ids not already listed above:
featureId |
Property |
|---|---|
9 / 10 |
|
12 |
|
27 |
|
37 |
|
96 |
|
227 |
|
303 |
|
308 |
|
344 |
|
364 |
|
723 |
|
725 |
|
726 |
|
727 |
|
848 |
|
973 |
|
In the same class, 202 is cockpit and 362 is hasBatteryStatus.
When searching a jadx decompilation, note that jadx sometimes renders an
integer literal as an unrelated library constant of the same value (for example
202/204 as OneTrust PC_SHOWN_* codes, 344/364/952/953/955/973 as
Contentsquare Currencies.*), so a search for the plain number misses them.
Discovery method¶
Android APK 6.13.4 (XAPK from apkcombo, sha256
15e02d50c0b06f55b0c1f4a3824449f21ca2530124d3c6d74834d7956aef552c), decompiled with jadx 1.5.6. The app is native Kotlin plus a Flutter module and Cordova (ScanMy only); it is not React Native.iOS 6.13.1 traffic captured through a TLS proxy to confirm live hosts, paths, headers and payloads.
Android APK 6.14.2 (XAPK from apkcombo, sha256
6681863aa4074a035451bf9024c6f48b3a2bdc9e730020466e0a74ab423dcc55), checked by string extraction from the dex files (no decompilation).Direct read-only HTTP probes on the tested vehicles, cross-checked with the app’s own traffic for the HEV.