fbq

Carsan for AI agents

Carsan rents cars in Los Angeles and Miami. An agent can search cars, check dates, and get prices without an account.

With an API key that the customer creates, the agent works on that customer's account. Payment, card addition, extension, and identity verification always stay with the customer.

What an agent can do

Without a key

  • Search cars by city (la, miami) and dates.
  • Read car details.
  • Get a price quote for dates and options.

With the customer's API key

  • Read the profile, verification status, trips, trip costs, invoices, and the saved card's brand and last four digits.
  • Get customer links for payment, card addition, and extension.
  • Create and cancel reservations under the normal rules (booking_write keys only).

Customer only

  • Sign up, start and complete identity verification (KYC).
  • Pay, add a card, and confirm an extension in the Carsan app.
  • Create and revoke API keys.

Continue with the customer's account

  1. The customer signs up at app.carsan.com.
  2. The customer opens Settings → API Keys and creates a key. read_only reads the account; booking_write also creates and cancels reservations.
  3. The customer gives the key to the agent. It is shown once.
  4. The agent sends it as Authorization: Bearer carsan_YOUR_API_KEY or X-API-Key: carsan_YOUR_API_KEY.

An API key is not driver approval. The customer starts and completes verification personally.

Customer actions

For payment, card addition, or extension the API returns a Carsan link. The link executes nothing and carries no key.

Payment link response (sample)

{
  "data": {
    "action": "pay_reservation",
    "status": "requires_user_action",
    "url": "https://app.carsan.com/trips/00000000-0000-4000-8000-000000000001?intent=pay&payment_type=reservation"
  }
}
  1. Give the url to the customer.
  2. The customer opens it, logs in if needed, reviews current details, and confirms.
  3. Read GET /my/reservation/00000000-0000-4000-8000-000000000001 again to report the actual result. A generated or visited link is not completion.