Pacific Gas and Electric · Authentication Profile

Pg And E Authentication

Authentication

Pacific Gas and Electric secures its APIs with oauth2 and mutualTLS across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorization_code, client_credentials, and refresh_token flow(s).

EnergyUnited StatesUtilitiesElectricityGasCaliforniaSmart MeteringGreen ButtonESPIEnergy DataGridDemand ResponseInvestor-Owned Utility
Methods: oauth2, mutualTLS Schemes: 2 OAuth flows: authorization_code, client_credentials, refresh_token API key in:

Security Schemes

mutual_tls mutualTLS
oauth2 oauth2
· flows: client_credentials, authorization_code, refresh_token

Source

Authentication Profile

Raw ↑
specification: API Commons Authentication
specificationVersion: '0.1'
provider: pg-and-e
providerId: pg-and-e
generated: '2026-09-17'
method: searched
source: https://www.pge.com/assets/pge/docs/save-energy-and-money/energy-savings-programs/OAuth_Authorization_ESPI.pdf
docs: https://www.pge.com/en/save-energy-and-money/energy-saving-programs/smartmeter/third-party-companies.html
modified: '2026-09-17'
note: >-
  Supersedes the 2026-07-11 derived artifact, which read a single authorizationCode flow out of the
  in-repo OpenAPI scaffold and missed the two facts that actually decide whether an agent can call
  this API: there are TWO token classes, and every call runs over MANDATORY mutual TLS with a
  CA-issued client certificate. Both are published anonymously by PG&E and both were confirmed live
  on 2026-09-17.
summary:
  types:
    - oauth2
    - mutualTLS
  oauth2_flows:
    - authorization_code
    - client_credentials
    - refresh_token
  transport_auth: mutual TLS 1.2 (client X.509 certificate)
  openid_connect: false
  openid_connect_evidence: >-
    /.well-known/openid-configuration returns HTTP 404 on www.pge.com, api.pge.com and
    sharemydata.pge.com (probed 2026-09-17). This is plain OAuth 2.0, not OpenID Connect.
schemes:
  - name: mutual_tls
    type: mutualTLS
    required: true
    scope: every call to api.pge.com, including the OAuth token endpoint
    requirement: >-
      A valid TLS 1.2 X.509 certificate issued by a recognized SSL provider. PG&E states
      "Self-signed certificates are not accepted and submission of a self-signed SSL certificate
      will delay the approval of your registration."
    evidence:
      - url: https://api.pge.com/GreenButtonConnect/espi/1_1/resource/Authorization
        status: 400
        body: '"Invalid Certificate"'
        fetched: '2026-09-17'
      - url: https://api.pge.com/GreenButtonConnect/espi/1_1/resource/ReadServiceStatus
        status: 400
        body: '"Invalid Certificate"'
        fetched: '2026-09-17'
    source: https://www.pge.com/en/save-energy-and-money/energy-saving-programs/smartmeter/third-party-companies.html
  - name: oauth2
    type: oauth2
    flows:
      - flow: client_credentials
        tokenUrl: https://api.pge.com/datacustodian/oauth/v2/token
        token_class: client_access_token
        description: >-
          Third-party-level token. Used for the third party's own resources — ApplicationInformation,
          the Authorization feed, ReadServiceStatus, and every Bulk resource
          (Batch/Bulk/{BulkID}, Batch/BulkRetailCustomerInfo/{BulkID},
          Batch/BulkRetailDRPrgInfo/{BulkID}).
      - flow: authorization_code
        authorizationUrl: https://api.pge.com/datacustodian/oauth/v2/Authorize
        tokenUrl: https://api.pge.com/datacustodian/oauth/v2/token
        token_class: access_token
        description: >-
          Per-customer token, issued after a PG&E customer authenticates on PG&E's own site and
          chooses what to share. Used for every customer-scoped resource under
          Subscription/{SubscriptionID}/... . Paired with a refresh token.
      - flow: refresh_token
        tokenUrl: https://api.pge.com/datacustodian/oauth/v2/token
        description: Refreshes the per-customer access token.
    scope_format: ESPI function-block string — see scopes/pg-and-e-scopes.yml
    revocation:
      operation: DELETE /GreenButtonConnect/espi/1_1/resource/Authorization/{AuthorizationID}
      token: client_access_token
      description: Cancels an individual customer authorization.
    evidence:
      - url: https://api.pge.com/datacustodian/oauth/v2/token
        method: GET
        status: 405
        body: '{"error":"invalid_request","error_description":"GET not permitted"}'
        fetched: '2026-09-17'
      - url: https://api.pge.com/datacustodian/test/oauth/v2/token
        method: GET
        status: 400
        body: '{"error":"invalid_request","error_description":"Missing grant_type"}'
        fetched: '2026-09-17'
      - url: https://api.pge.com/datacustodian/test/oauth/v2/authorize
        method: GET
        status: 400
        body: '{"error":"invalid_request","error_description":"client_id is empty"}'
        fetched: '2026-09-17'
    sources:
      - https://www.pge.com/assets/pge/docs/save-energy-and-money/energy-savings-programs/OAuth_Authorization_ESPI.pdf
      - https://www.pge.com/assets/pge/docs/save-energy-and-money/energy-savings-programs/Supported-APIs.pdf
onboarding:
  self_serve: false
  gate: application approval by PG&E under the CPUC framework
  registration_url: https://sharemydata.pge.com/
  prerequisites:
    - A 9-digit U.S. Employer Identification Number (EIN)
    - Business and technical contacts
    - A third-party notification URI for the ESPI push (FB 39) model
    - A CA-issued TLS 1.2 X.509 certificate (self-signed rejected)
  source: https://www.pge.com/en/save-energy-and-money/energy-saving-programs/smartmeter/third-party-companies.html
support: mailto:ShareMyData@pge.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/pg-and-e-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.