# Application Marketplace

> Connect third-party apps to Road on a customer's behalf, over standard OAuth 2.1 and OpenID Connect.

> **Preview / beta**
>
> The Application Marketplace is under active development. The APIs, schemas and dashboard surfaces described here are not yet considered stable, and breaking changes may occur without long deprecation windows. If you are integrating today, please coordinate with Road so we can keep you informed of changes that affect you.

The Road Application Marketplace lets a third-party application connect to Road on a customer's behalf, read their charging data, and build on top of the platform. The application authorises against a provider, the customer consents to a set of scopes, and from then on the application calls the Road API with an access token issued for that customer.

The protocol is plain OAuth 2.1 and OpenID Connect: Authorisation Code flow with PKCE, standard discovery, token, userinfo and JWKS endpoints, and RS256-signed ID tokens. There is nothing Road-specific to implement, so an off-the-shelf OAuth/OIDC client library will do. [Authenticating your application](/docs/platform/integrations/marketplace/authentication) covers discovery, the flow and token exchange in full.

## How this documentation is organised

This page explains the concept. The following pages cover each part of the integration in detail:

- [Registering an application](/docs/platform/integrations/marketplace/registration) covers the three ways to obtain a client (curated templates, provider installations, and dynamic self-registration) and how to get set up.
- [Authenticating your application](/docs/platform/integrations/marketplace/authentication) covers the OAuth flow itself: discovery, public vs confidential clients, PKCE, the authorisation request, and token exchange.
- [Consent, grants and data sharing](/docs/platform/integrations/marketplace/consent-and-sharing) covers what the customer consents to, how they manage connected applications, and how they choose which data to share.
- [Using the API](/docs/platform/integrations/marketplace/using-the-api) covers calling the API with an access token, refreshing tokens, and handling errors.
- [ERE integration](/docs/platform/charge-point-operation/ere-integration) covers reading charging data for Emission Reduction Units end to end.

## Enabled per provider

The marketplace is made up of three independent capabilities, each enabled separately per provider in the provider's configuration:

- **Curated templates** lets a provider install Road-vetted catalogue applications.
- **Provider installations** lets a provider define and register their own applications.
- **Dynamic registration** lets applications self-register against the provider (RFC 7591).

A provider may have any combination of these switched on. If the capability you need is not available for the provider you are integrating with, it has not been enabled. To request access, contact us at <ere.marketplace@road.io>.

## Still in preview

The marketplace is being actively extended. Expect additional scopes and related functionality to be added over time. The data-sharing model is intentionally generic so that new scoped APIs can adopt it as they land. Treat the current surface as a preview and check back for changes.

## Reference application

> Reference implementation
>
> A working Next.js application exercising the full flow (PKCE, token exchange, refresh, and ERE reads) is published at [github.com/e-flux-platform/example-3rd-party-marketplace-app](https://github.com/e-flux-platform/example-3rd-party-marketplace-app). The repository README has the context needed to get started. You will need credentials and the provider's discovery URL; see [Registering an application](/docs/platform/integrations/marketplace/registration).

## Get in touch

To list a curated application, enable a capability for a provider, or discuss an integration, contact us at <ere.marketplace@road.io>.
