Canada Energy Regulator · Authentication Profile

Canada Energy Regulator Authentication

Authentication

Canada Energy Regulator secures its APIs with none across 0 declared security schemes, as derived from its OpenAPI definitions.

EnergyCanadaRegulationsGovernmentPipelinesElectricityNatural GasCrude OilEnergy MarketsOpen DataGeospatial
Methods: none Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

canada-energy-regulator-authentication.yml Raw ↑
generated: '2026-07-27'
method: searched
source: live anonymous probes of every Canada Energy Regulator machine-readable surface, 2026-07-27
docs: https://www.cer-rec.gc.ca/en/about/open-government/
note: 'There is no OpenAPI on any CER host, so this profile was not derived from securitySchemes — it was established
  by probing each surface anonymously and recording what it accepted. The finding is that the Canada Energy Regulator
  requires no authentication anywhere on its public data estate: no API key, no OAuth, no OIDC, no mTLS, no bearer
  token was required or even offered. Access control is by open licence (OGL-Canada), not by credential.'
summary:
  types:
  - none
  anonymous: true
  api_key_in: []
  oauth2_flows: []
  registration_required: false
  terms_click_through: false
schemes: []
surfaces:
- name: CER ArcGIS Online feature services
  base: https://services5.arcgis.com/vNzamREXvX2WcX6d/arcgis/rest/services
  auth: none
  verified: '2026-07-27'
  evidence: GET /Incident_Data_English_20191007_View/FeatureServer/0/query?where=1=1&returnCountOnly=true&f=json returned
    {"count":1899} with no credential.
- name: CER Assessments on the Federal Geospatial Platform
  base: https://maps-cartes.services.geo.ca/server_serveur/rest/services/NRCan/CER_Assessments_EN/MapServer
  auth: none
  verified: '2026-07-27'
  evidence: MapServer ?f=json returned 200/3,005 bytes and WMS 1.3.0 GetCapabilities returned 200/7,019 bytes of valid
    XML, both anonymous.
- name: Open Government Portal CKAN Action API (operated by Treasury Board Secretariat, not the CER)
  base: https://open.canada.ca/data/api/3/action
  auth: none
  verified: '2026-07-27'
  evidence: GET /package_search?fq=owner_org:A3EE9522-882F-47B0-BA7D-83420DC8577C returned 83 datasets anonymously.
  caveat: A WAF in front of open.canada.ca rejects requests without a browser-like User-Agent, returning an HTML "Request
    Rejected" body under HTTP 200. This is not authentication, but it silently breaks naive clients and is the single
    most likely cause of a failed first integration.
- name: CER bulk CSV tree
  base: https://www.cer-rec.gc.ca/open/
  auth: none
  verified: '2026-07-27'
  evidence: A 10,110-byte LNG exports CSV was downloaded anonymously. The directory itself is not browsable (soft
    403 body under HTTP 200); individual file paths resolve.
credentialed_systems_not_apis:
- name: REGDOCS
  url: https://apps.cer-rec.gc.ca/REGDOCS/Home/Index
  http_status: 200
  note: Public regulatory document search UI. Browsable without login; no documented API and no machine authentication.
- name: Event Reporting System (ERS)
  url: https://apps.cer-rec.gc.ca/ERS/
  http_status: 200
  note: Inbound incident reporting for regulated companies. HTML session login for filers; no documented API auth.
    Its output is republished as the open Incidents dataset.
discovery_probes:
- url: https://www.cer-rec.gc.ca/.well-known/openid-configuration
  http_status: 200
  result: soft 404 — 4,405-byte CER HTML error page. No OIDC discovery document.
- url: https://www.cer-rec.gc.ca/.well-known/oauth-authorization-server
  http_status: 200
  result: soft 404, same page.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/canada-energy-regulator-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.