PJM Browserless Authentication API
The REST authentication front door for every browserless/API integration with PJM eTools. A client POSTs to the PJM single sign-on service with X-OpenAM-Username and X-OpenAM-Password headers and receives a JSON tokenId, which is then presented as a pjmauth cookie on subsequent tool API calls, and released via a logout call. PJM has additionally moved custom-code REST clients onto PKI, requiring a two-way TLS client certificate against the access/authenticate/pjmauthcert endpoint alongside credentials. The service is ForgeRock OpenAM — verified live with HTTP 405 on GET https://sso.pjm.com/access/authenticate/ on 2026-07-27, confirming the documented POST-only endpoint.
Documentation
Documentation
https://www.pjm.com/markets-and-operations/etools/security.aspx
Authentication
https://raw.githubusercontent.com/api-evangelist/pjm/refs/heads/main/authentication/pjm-authentication.yml
Other Resources
Guide
https://www.pjm.com/-/media/DotCom/etools/pjm-browserless-authentication-guide.pdf
Guide
https://www.pjm.com/-/media/DotCom/etools/security/pki-authentication-guide.pdf
Sandbox
https://ssotrain.pjm.com/
AgentSkill
https://raw.githubusercontent.com/api-evangelist/pjm/refs/heads/main/skills/pjm-authenticate-browserless-etools.md