How to give a shop access to your Tesla — and take it back

You have four options: leave an NFC key card, authorize a third-party app through Tesla’s own consent screen, turn on Valet Mode, or stay with the car. Only the app route is scoped, revocable from your phone, and visible to you afterwards.

Whatever you choose, know the exit before you choose it. Revocation lives in two places: your Tesla Account under Security > Third-Party Apps, and the car’s own Locks screen. Both are yours; neither belongs to the shop.

LAST REVIEWED AUGUST 16, 2026

What are the real ways to give a shop access to a Tesla?

There are four: leave an NFC key card, authorize a third-party app through Tesla's own consent flow, turn on Valet Mode, or stay with the car. Only the second one is scoped, time-boxed, and revocable from your phone; the key card is the most common and the least accountable.

In practice most shops still run on option one. If that is your visit, read what happens to your key card at the shop first — the card cannot be remotely wiped and leaves no per-card audit trail.

A fifth option people ask about does not belong on the table: handing over a phone key. A phone key is a Bluetooth pairing between one handset and one car, so it cannot be granted remotely, and a shop tablet running a web app is not one. What a shop app actually holds is a virtual key plus a scoped third-party app authorization — option two, under a different name.

What does authorizing a third-party app actually grant?

Tesla's OAuth flow grants named scopes and nothing more: vehicle_device_data for vehicle data, vehicle_location for location and geofences, vehicle_cmds for commands, vehicle_charging_cmds for charging, and offline_access for refresh tokens. An app cannot escalate its own scopes — widening access requires the owner to grant again.

Tesla describes named permissions in its authentication overview. Check why location is requested, who can view it, and when collection ends. GuestLot shows the last-reported authorized position with a timestamp during the visit, and the owner report remains private until the shop enables sharing.

What is a Tesla virtual key and why does the shop need one?

Signed vehicle commands require the owner to add the app's virtual key to the car through a tesla.com/_ak/<domain> link or QR code. Tesla describes this as requiring a trusted user-in-the-loop, preventing even Tesla's backend from accessing these capabilities. In plain terms: a shop can never unilaterally instrument a customer's car.

Tesla’s virtual-keys developer guide states that signed commands require a trusted user-in-the-loop, “preventing even Tesla’s backend from accessing these capabilities” (developer.tesla.com). This is the structural fact that makes shop-side Tesla software honest: there is no path where a service writer instruments your car without you tapping approve.

How do I revoke a shop's access to my Tesla?

Review the third-party app in your Tesla account and revoke its permission. Also check the car's key list and remove any shop key that should no longer work. App authorization and paired keys are different controls; closing a GuestLot visit alone does not prove both have been removed.

Revoke the app

Remove the key from the car

Both routes are documented in Tesla’s Fleet API FAQ (developer.tesla.com). Doing both is not paranoid; it is just thorough.

How long does an authorization last if I do nothing?

Token expiry and the owner's authorization are different things, and refresh behavior can extend a connection. Do not rely on token lifetime to end a shop visit. GuestLot closes the visit and discards its stored connection tokens; the owner should also review third-party app access and any paired keys in Tesla at pickup.

CONSENT WINDOW

Access live
CHECK-IN TUE 09:12PICKUP TUE 18:00

AUTO-REVOKE

The shape above is the one to ask for: a window with two ends. A shop that can only turn access on has not thought about the second half of custody. See the limits we publish for what that means in practice.

Can I authorize before the appointment instead of at the counter?

Yes, when the shop provides an invitation for the scheduled visit. Confirm connection status when the car arrives. GuestLot close-out discards its stored connection tokens; that does not remotely delete every Tesla permission or paired key. Review those separately at pickup.

What if I do not want to authorize anything?

That is a legitimate choice and a shop should have a plan for it. Leave the key card, insist on written intake with photos and an odometer reading, and expect the visit record to say that no telemetry was collected. Any shop that pressures you into connecting an app is telling you something about the shop.

A good shop treats a decline as normal. It should still be able to tell you when your car arrived, who had the key, and what the odometer read at both ends — from paper if necessary. If you want the shop-side version of this argument, read what happens when a customer car is damaged at a shop.

Sources

Keep reading