Skip to content

BMW cars cannot be authorised - issue with key exchange between evcc and BMW cardata #26347

Description

@ansgarherkert

Describe the bug

I and another evcc user (NaegeleF) cannot connect our BMW cars to evcc. We had some discussions with mfuchs1984 (discussion #26254 partially in German) but he also could not help. I therefore raise an issue now.

I have setup the cardata streams in the BMW website (in line with evcc documentation). The stream and API are shown as "active" on the BMW website.

I have configured my cars (I have 2 BMW i3s) in evcc.yaml. In the GUI I can then request to connect the cars. I get the key generated by evcc and then put this key in the BMW website for confirmation. The BMW site confirms that the login was successful.

When I return to evcc nothing has happened and I am still at the window from which the authorisation key can be requested. There seems to be an issue with the key exchange.

I have tried this with version 300.2 and the previous version (have just updated versions).
I have tried it from a direct install on Debian (Intel PC), a Docker container (Synology) and from a home assistant add-in install (Synology).
Same result in all cases.

The rest of the evcc system is working normal as expected.

Here some screenshots below.

Many thanks in advance for your help. Please let me know if I should provide additional data/info. This is my first issue raised and therefore might not have done everything as required.

I have not checked the lasted nightly build (although I have checked the box below). If I need to do this, I will do so but felt that this is not necessary as I used the last 2 production builds.

(Wenn Deutsch als Sprache bevorzugt wird, gerne weiter in Deutsch.)

Image

Image

Image

Image

Image

Steps to reproduce

  1. create BMW cardata config in evcc.yaml and setup cardata stream on BMW website
  2. in evcc attempt to authorise the car(s)
  3. get no result, only error in log file

Configuration details

vehicles:
- type: template
  template: cardata
  title: i3sAnsgar
  capacity: 39
  vin: WBY8P610207Kxxxxx # modified
  clientid: F2782EB7-9CE4-40C3-9B08-xxxxxxxxxx # modified
  name: ev2
- type: template
  template: cardata
  title: i3sMakiko
  capacity: 39
  vin: WBY8P610207Gxxxxx #modifed
  clientid: F2782EB7-9CE4-40C3-9B08-xxxxxxxxxx # modified
  name: ev1

Log details

Last trace from today created in homeassistant:

[httpd ] TRACE 2026/01/02 00:15:25 GET /providerauth/login
[providerauth] DEBUG 2026/01/02 00:15:25 login request for: F2782EB7-9CE4-40C3-9B08-D6832ABF59EF-528e4c2a
[cardata] TRACE 2026/01/02 00:15:25 POST https://customer.bmwgroup.com/gcdm/oauth/device/code
[cardata] TRACE 2026/01/02 00:15:25 client_id=***&code_challenge=Pb3ceyIG7YZgGVSONnR5EzTKi-s_Msf-t41L8mwg800&code_challenge_method=S256&scope=authenticate_user+openid+cardata%3Astreaming%3Aread+cardata%3Aapi%3Aread -- {"user_code":"Yfxr2xbh","device_code":"eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJodHRwczovL2Zvcmdlcm9jay1ncmVlbi5wcm9kLWdjZG0uZXUtY2VudHJhbC0xLmF3cy5jbG91ZC5ibXc6NDQzL2FtL29hdXRoMiIsIm5iZiI6MTc2NzMwOTMyNSwidXNlcl9jb2RlIjoiWWZ4cjJ4YmgiLCJpc3MiOiJodHRwczovL2Zvcmdlcm9jay1ncmVlbi5wcm9kLWdjZG0uZXUtY2VudHJhbC0xLmF3cy5jbG91ZC5ibXc6NDQzL2FtL29hdXRoMiIsImV4cCI6MTc2NzMwOTYyNSwiaWF0IjoxNzY3MzA5MzI1LCJqdGkiOiI4NTBmN2E2MC00Y2YzLTQwOGMtOTBmZi00MWM2NzVkNzFhYT
[cardata] TRACE 2026/01/02 00:15:30 POST https://customer.bmwgroup.com/gcdm/oauth/token
[cardata] TRACE 2026/01/02 00:15:30 client_id=***&code_verifier=ORO44Vzk_NL7deFLzPypwRYbqjIZ_jf83OH2OsnPcXM&device_code=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJodHRwczovL2Zvcmdlcm9jay1ncmVlbi5wcm9kLWdjZG0uZXUtY2VudHJhbC0xLmF3cy5jbG91ZC5ibXc6NDQzL2FtL29hdXRoMiIsIm5iZiI6MTc2NzMwOTMyNSwidXNlcl9jb2RlIjoiWWZ4cjJ4YmgiLCJpc3MiOiJodHRwczovL2Zvcmdlcm9jay1ncmVlbi5wcm9kLWdjZG0uZXUtY2VudHJhbC0xLmF3cy5jbG91ZC5ibXc6NDQzL2FtL29hdXRoMiIsImV4cCI6MTc2NzMwOTYyNSwiaWF0IjoxNzY3MzA5MzI1LCJqdGkiOiI4NTBmN2E2MC00Y2YzLTQwOGMtOTBmZi00MWM2NzVkNzFhYTUifQ.3zah_U_DuV5OF2i851G-AhLADljv2Ib5OpLGgeM6ChY&grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Adevice_code&scope=authenticate_user+openid+cardata%3Astreaming%3Aread+cardata%3Aapi%3Aread -- {"error_description":"The user has not yet completed authorization","error":"authorization_pending"}
[cardata] TRACE 2026/01/02 00:15:35 POST https://customer.bmwgroup.com/gcdm/oauth/token
[cardata] TRACE 2026/01/02 00:15:35 client_id=***&code_verifier=ORO44Vzk_NL7deFLzPypwRYbqjIZ_jf83OH2OsnPcXM&device_code=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJodHRwczovL2Zvcmdlcm9jay1ncmVlbi5wcm9kLWdjZG0uZXUtY2VudHJhbC0xLmF3cy5jbG91ZC5ibXc6NDQzL2FtL29hdXRoMiIsIm5iZiI6MTc2NzMwOTMyNSwidXNlcl9jb2RlIjoiWWZ4cjJ4YmgiLCJpc3MiOiJodHRwczovL2Zvcmdlcm9jay1ncmVlbi5wcm9kLWdjZG0uZXUtY2VudHJhbC0xLmF3cy5jbG91ZC5ibXc6NDQzL2FtL29hdXRoMiIsImV4cCI6MTc2NzMwOTYyNSwiaWF0IjoxNzY3MzA5MzI1LCJqdGkiOiI4NTBmN2E2MC00Y2YzLTQwOGMtOTBmZi00MWM2NzVkNzFhYTUifQ.3zah_U_DuV5OF2i851G-AhLADljv2Ib5OpLGgeM6ChY&grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Adevice_code&scope=authenticate_user+openid+cardata%3Astreaming%3Aread+cardata%3Aapi%3Aread -- {"error_description":"The polling interval has not elapsed since the last request","error":"slow_down"}
[cardata] TRACE 2026/01/02 00:15:45 POST https://customer.bmwgroup.com/gcdm/oauth/token
[cardata] TRACE 2026/01/02 00:15:45 client_id=***&code_verifier=ORO44Vzk_NL7deFLzPypwRYbqjIZ_jf83OH2OsnPcXM&device_code=eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJhdWQiOiJodHRwczovL2Zvcmdlcm9jay1ncmVlbi5wcm9kLWdjZG0uZXUtY2VudHJhbC0xLmF3cy5jbG91ZC5ibXc6NDQzL2FtL29hdXRoMiIsIm5iZiI6MTc2NzMwOTMyNSwidXNlcl9jb2RlIjoiWWZ4cjJ4YmgiLCJpc3MiOiJodHRwczovL2Zvcmdlcm9jay1ncmVlbi5wcm9kLWdjZG0uZXUtY2VudHJhbC0xLmF3cy5jbG91ZC5ibXc6NDQzL2FtL29hdXRoMiIsImV4cCI6MTc2NzMwOTYyNSwiaWF0IjoxNzY3MzA5MzI1LCJqdGkiOiI4NTBmN2E2MC00Y2YzLTQwOGMtOTBmZi00MWM2NzVkNzFhYTUifQ.3zah_U_DuV5OF2i851G-AhLADljv2Ib5OpLGgeM6ChY&grant_type=urn%3Aietf%3Aparams%3Aoauth%3Agrant-type%3Adevice_code&scope=authenticate_user+openid+cardata%3Astreaming%3Aread+cardata%3Aapi%3Aread -- {"fault":{"faultstring":"Invalid Access Token","detail":{"errorcode":"keymanagement.service.invalid_access_token"}}}
[cardata] ERROR 2026/01/02 00:15:45 error retrieving token: oauth2: cannot fetch token: 500 Internal Server Error Response: {"fault":{"faultstring":"Invalid Access Token","detail":{"errorcode":"keymanagement.service.invalid_access_token"}}}

What type of operating system or environment does evcc run on?

Linux

External automation

  • I have made sure that no external automation like HomeAssistant or Node-RED is active or accessing any of the mentioned devices when this issue occurs.

Nightly build

  • I have verified that the issue is reproducible with the latest nightly build

Version

0.300.2

Metadata

Metadata

Assignees

Labels

vehiclesSpecific vehicle support

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions