> ## Documentation Index
> Fetch the complete documentation index at: https://developers.podero.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the pairing link of a virtual-key action

> Return the Tesla link that adds the Podero virtual key to the car of a `virtual_key_required` action. Both `cue_id` and `secret` come from the action's `resolution_link.url`. The `secret` is a signed token bound to the car's owner and expires 1 hour after it is issued. The caller must be the owner's own session or a token of the owner's organisation.

The request has no body. The action stays until a later read shows the key on the car, so the caller can get the link again. The route never closes the action.



## OpenAPI

````yaml https://app.podero.com/api/partners/v2.0/openapi.json post /api/partners/v2.0/cues/{cue_id}/virtual-key/resolve
openapi: 3.1.0
info:
  title: Podero Partner API
  version: '2.0'
  description: >-
    This API provides a unified interaction point for Podero's partner
    companies.


    The goal of this API is to give partners easily integratable endpoints that
    don't require extensive software

    development. For this reason, the endpoints focus around user and device
    management, setting of preferences

    and high level device controls.


    While direct control of devices is implemented for special use cases such as
    pause power, we abstract away low level

    direct device steering so developers and partners can focus on delivering
    maximum value to end users.


    ## Authentication


    Send an OAuth2 access token in the `Authorization: Bearer <access_token>`
    header of each request.

    A token request must have a JSON body. The token endpoints do not read a
    form-encoded body.


    Server-to-server integrations use the client credentials grant:


    ```http

    POST /oauth2/token/

    Authorization: Basic base64(<client_id>:<client_secret>)

    Content-Type: application/json


    {"grant_type": "client_credentials"}

    ```


    The response does not contain a refresh token. The access token expires
    after `expires_in` seconds (one hour).

    To renew it, send the same request again. Use one token for all requests
    until shortly before it expires.

    Do not request a new token for each request. If a request returns `401`, get
    one new token and send the request

    again once. If it returns `401` again, the token is valid but the
    application has no access to that resource,

    and a new token does not change that.


    Apps where a person signs in use the password grant at `POST
    /api/partners/v2.0/auth/token`, and renew the

    session with the `refresh_token` grant at the same endpoint.
  termsOfService: https://www.podero.com/terms-and-conditions
servers: []
security: []
paths:
  /api/partners/v2.0/cues/{cue_id}/virtual-key/resolve:
    post:
      tags:
        - Cues
      summary: Get the pairing link of a virtual-key action
      description: >-
        Return the Tesla link that adds the Podero virtual key to the car of a
        `virtual_key_required` action. Both `cue_id` and `secret` come from the
        action's `resolution_link.url`. The `secret` is a signed token bound to
        the car's owner and expires 1 hour after it is issued. The caller must
        be the owner's own session or a token of the owner's organisation.


        The request has no body. The action stays until a later read shows the
        key on the car, so the caller can get the link again. The route never
        closes the action.
      operationId: integrations_api_api_v2_cues_router_resolve_virtual_key
      parameters:
        - in: path
          name: cue_id
          schema:
            description: The action's ID
            format: uuid
            title: Cue Id
            type: string
          required: true
          description: The action's ID
        - in: query
          name: secret
          schema:
            description: Signed secret authorising the caller for this action
            title: Secret
            type: string
          required: true
          description: Signed secret authorising the caller for this action
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/VirtualKeyActionOutput'
      security:
        - OAuth2: []
components:
  schemas:
    VirtualKeyActionOutput:
      description: >-
        Response shape for resolving an action whose `code` is
        `virtual_key_required`.
      properties:
        redirect_url:
          description: >-
            The Tesla link that adds the Podero virtual key to the car. Open it
            on the phone that has the Tesla app, signed in as the account that
            owns the car. Do not store or log it: it carries the car's VIN.
          title: Redirect Url
          type: string
      required:
        - redirect_url
      title: VirtualKeyActionOutput
      type: object
  securitySchemes:
    OAuth2:
      type: oauth2
      flows:
        password:
          tokenUrl: /api/partners/v2.0/auth/token
          scopes: {}
        clientCredentials:
          tokenUrl: /oauth2/token/
          scopes: {}

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.