All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
- SonarCloud cleanup — all open findings resolved: refactored
AuthenticateAsync(cognitive complexity 76 → ~6) andMonitorDrivingTelemetryAsyncinto focused helper methods (S3776); split the authentication-callback dispatcher into small helpers (FillCallbackInput,IsCallbackType,SetFirstInput, …) to stay under the complexity limit (S3776); replaced the duplicated"application/json"literal with aJsonMediaTypeconstant (S1192); moved theStartClimateControlAsyncoverloads next to each other in both the interface and implementation (S4136); rewrote the nested ternary inGetLockStatusAsync(S3358) and rebuilt the door collection with a plain loop so the analyzer stops flaggingdoors.Count > 0as constant (S2583); dropped the overlapping default value from theMyToyotaClient(ToyotaApiSettings, HttpClientHandler)constructor (S3427); and explicitly annotated the public OneApp client key as non-secret for S6418. The demo app no longer uses hard-coded credential paths (S1075), usesStringBuilderfor password input (S1643), simplifies a loop withWhere(S3267), and is now astaticclass (S1118). GetTripsAsyncnow accepts an optionalTripQueryOptionsobject instead of four loose parameters (route,summary,limit,offset), keeping the signature under the S107 parameter-count limit. Existing callers that passcancellationTokenby name remain source-compatible; the docs and demo were updated.- Upgraded NuGet packages to latest stable (Microsoft.Extensions.* 10.0.11, System.IdentityModel.Tokens.Jwt 8.22.0, Microsoft.NET.Test.Sdk 18.9.0). xUnit remains on the v3 line (3.2.2) to keep the plain
dotnet test(VSTest) workflow; the xUnit v3 4.0 line requires the Microsoft.Testing.Platform runner and is noted as a follow-up. - Replaced the static
config.json-backedConstantswith injectableToyotaApiSettings(endpoints/URLs/key now configurable via DI with baked-in defaults). - TLS/SSL certificate validation is now enabled by default; opt out per client via
UseBypassSslValidation(true)orToyotaClientOptions.BypassSslValidation. - Token-expiry timestamps now use UTC.
- Removed dead code: unused
PostAsynchelper and the unimplementedIToyotaRestClient/ToyotaApiResponse. - Restored the public OneApp client key as
Constants.PUBLIC_API_KEY. It is not a credential (it ships with the official Toyota app); the SonarCloud S6418 finding is explicitly suppressed with justification in the source, and the key remains overridable viaToyotaApi:ApiKeyor theTOYOTA_API_KEYenvironment variable. - Migrated the endpoints Toyota retired in 2026-07 (the old
/v1/global/remote/*read routes are SigV4-fenced and returnAPIGW-403 Unauthorized):GetRemoteStatusAsyncnow readsGET /v1/vehicle/statusand returns the new directly-typed payload (doors/windowsper component) instead of the old category/section/value blob.- Climate reads moved to
/v1/vehicle/climate-settings,/v1/vehicle/climate-status; the wake moved to/v1/remote/refresh-climate-status. - Climate actuation moved to
POST /v2/remote/climate-control. GetLockStatusAsyncnow derives door lock/open states from the/v1/vehicle/statuspayload (the dedicated/v1/global/remote/lock-statusroute was retired).- Reworked the trips payload models:
payloadis now an object{from, to, trips, summary, _metadata, route}(tripid,summarywithstartLat/startLon/startTs/endTs,scores,behaviours,hdc, typedroutepoints, pagination metadata) instead of the old flat list. - Removed the obsolete
GetVehicleAssociationAsync()/GetDrivingStatisticsAsync()APIs (the backend returns HTTP 403APIGW-403); their settings, models and tests were removed from the public surface.
ToyotaApiSettingsoptions class andToyotaApiconfiguration section.- Offline unit tests (settings defaults, DI registration, request building) that do not require live credentials.
RefreshRemoteStatusAsync()—POST /v1/remote/status"wake" that mirrors the official MyT app before reading vehicle status (populates the gateway cache and reduces429 APIGW-403).VehicleRemoteStatusRefreshEndpointsetting (/v1/remote/status).MonitorDrivingTelemetryAsync()— adaptive battery SOC/range + geo-location monitor. Polls fast while driving (optional wake), moderate while charging, and minimal — reading cached gateway data and never waking the vehicle — while parked, protecting the 12V battery when the car isn't on a charger.SendChargingCommandAsync()— charging commands viaPOST /v1/global/remote/electric/command(CHARGE_NOW/RESERVE_CHARGE/SET_CHARGING_TIME).StartClimateControlAsync(vin, ClimateControlSettings)— full preset body forPOST /v2/remote/climate-control; request bodies now omitnullmembers. Richer EV payload (fuelLevel,fuelRange,lastUpdateTimestamp,remainingChargeTime,nextChargingEvent, …).
- Duplicate/private request plumbing consolidated into a single
SendCoreAsynchelper; request/response objects are disposed. - A missing or explicitly-emptied API key now throws a clear configuration exception instead of silently omitting the
x-api-keyheaders and surfacing a confusing401 Unauthorizedfrom the gateway.
1.1.0 - 2025-06-29
- Trips API —
GetTripsAsync()to retrieve trip history with date range, route, and summary options - Climate Control —
GetClimateSettingsAsync(),GetClimateStatusAsync(),RefreshClimateStatusAsync(),StartClimateControlAsync(),StopClimateControlAsync() - Remote Commands —
SendRemoteCommandAsync()withRemoteCommandTypeenum supporting door lock/unlock, engine start/stop, hazard lights, headlights, and trunk - Vehicle Association —
GetVehicleAssociationAsync()for authenticated user's vehicle associations - Driving Statistics —
GetDrivingStatisticsAsync()for eco-scores, fuel consumption, and driving metrics - Lock Status —
GetLockStatusAsync()for door, trunk, and window lock states - Response models for all new endpoints
SendRequestWithBodyAsynchelper for POST requests with JSON payloads- Integration tests for all new API methods
- Unit test for
RemoteCommandTypeenum values - OSS directory structure with
docs/,CONTRIBUTING.md,SECURITY.md,CHANGELOG.md - GitHub issue and PR templates
- Upgraded test project to xUnit v3 (removed xUnit v2 workarounds)
- Removed unused
Microsoft.CodeAnalysis.*testing packages from test project
1.0.0 - 2025-06-28
- Initial release
- Toyota Connected Services authentication (OpenID Connect flow with ForgeRock AM)
- Token caching with automatic refresh
- Fluent client configuration (
UseCredentials,UseLogger,UseTimeout,UseTokenCaching) - Vehicles —
GetVehiclesAsync()to list all vehicles on the account - Electric Status —
GetElectricAsync()for battery level, charging status, EV range - Electric Realtime —
GetElectricRealtimeStatusAsync()to trigger live status from vehicle - Location —
GetLocationAsync()for GPS coordinates and display name - Health Status —
GetHealthStatusAsync()for engine oil and warning indicators - Telemetry —
GetTelemetryStatusAsync()for odometer and distance-to-empty - Notifications —
GetNotificationsAsync()for notification history - Remote Status —
GetRemoteStatusAsync()for combined remote vehicle status - Service History —
GetServiceHistoryAsync()for maintenance records - Comprehensive response models for all Toyota API endpoints
- Console demo application with interactive credential input
- Unit and integration test suite