API

Free, keyless, CORS-enabled. No registration and no tiers. If you build something with it, we’d like to hear about it.

Look up a VIN

GET /api/v1/vin/{vin}

Add ?sticker=false to skip the label check and get decoded specifications only — it is faster and lighter.

Response

{
  "ok": true,
  "vin": "1G1FD1RSXP0160334",
  "vehicle": {
    "year": "2023",
    "make": "Chevrolet",
    "model": "Camaro",
    "trim": "2LT",
    "bodyClass": "Coupe",
    "engine": { "displacement": "3.6L", "cylinders": "6", "fuel": "Gasoline" },
    "plant": "LANSING, MICHIGAN, UNITED STATES (USA)"
  },
  "windowSticker": {
    "supported": true,
    "available": true,
    "bytes": 157032,
    "pdf": "https://windowsticker.org/api/sticker/1G1FD1RSXP0160334",
    "paint": { "color": "BLACK", "code": null }
  }
}

paint is the exterior color exactly as the label prints it. code is the factory paint code, set only where the label carries one: Toyota, and Hyundai or Genesis when paint is a priced option. Ford and Nissan labels give no color we can read, so the field is left out, as it is whenever there’s no label.

Get the PDF

GET /api/sticker/{vin}

Returns the original manufacturer PDF, or 404 with a reason when no label exists for that VIN. Append ?download=1 for an attachment disposition.

Toyota, Lexus, Nissan and Infiniti

Coverage for these four makes depends on a third party and could stop any day. Both endpoints return them like any other make. Please store what you get and ask for each VIN once.

MCP server

The same lookups, as tools an AI assistant can call. It’s a remote MCP server over Streamable HTTP, with no key and no sign-in:

https://windowsticker.org/mcp

In Claude, open Customize, then Connectors, choose + and Add custom connector, and paste the URL (the free plan allows one). In Claude Code, run claude mcp add --transport http windowsticker https://windowsticker.org/mcp. In ChatGPT (Plus, Pro, Business, Enterprise or Education, on the web), turn on Developer mode under Settings, then Security and login, and add a developer-mode app with the URL and No Authentication.

Telling us who you are works the same way as for the API, below. Where a client can’t add a header, put it on the URL: https://windowsticker.org/mcp?contact=you@example.com.

Tell us who you are

Optional, and you get something back. Send an X-Contact header — a domain or an email — or add ?contact= to the URL:

curl -H "X-Contact: tools@example.com" \
  https://windowsticker.org/api/v1/vin/5XXG64J20PG207906

We log the string, the day and the route, and lookups on /api/v1 and get_window_sticker send the string to the analytics service this site uses. No IP address, ever, and it goes nowhere else. In return you get an email before anything breaking ships, and a heads-up when a manufacturer goes dark — Ford stopped serving every VIN on 21 September and anyone building on it found out by watching their own error rate. Most of the API traffic here is anonymous, so we cannot warn most of it. contact@windowsticker.org reaches a person if you would rather just say hello, or tell us what is missing.

Fair use

There is no key and no daily quota. Each address gets 10 requests every 10 seconds under /api/; past that, it’s blocked for 10 seconds. Please don’t enumerate VINs at speed. Any new limit will be published here before it’s enforced.

Coverage

Factory PDFs exist for Ford, Lincoln, Chevrolet, GMC, Buick, Cadillac, Jeep, Ram, Dodge, Chrysler, Fiat, Alfa Romeo, Subaru, Kia, Hyundai, Toyota, Lexus, Nissan, Infiniti, Genesis. Every other VIN returns decoded specifications with supported: false. More on coverage.