Pacific Gas and Electric · Authentication Profile
Pge Authentication
Authentication
PG&E Share My Data authenticates third parties with OAuth 2.0 (NAESB ESPI authorization profile) layered on MANDATORY mutual TLS 1.2. This is not OpenID Connect: /.well-known/openid-configuration returns HTTP 404 on www.pge.com, api.pge.com and sharemydata.pge.com (re-probed 2026-07-27). Two bearer-token classes are issued from separate grants, and a third registration token governs the ApplicationInformation resource.
Pacific Gas and Electric secures its APIs with oauth2, mutualTLS, and http across 5 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, clientCredentials, and refreshToken flow(s).
EnergyUnited StatesUtilitiesElectricityGasCaliforniaSmart MeteringGreen ButtonESPIEnergy DataGridDemand ResponseInvestor-Owned Utility
Methods: oauth2, mutualTLS, http
Schemes: 5
OAuth flows: authorizationCode, clientCredentials, refreshToken
API key in:
Security Schemes
MutualTLS mutualTLS
OAuth2ClientCredentials oauth2
OAuth2AuthorizationCode oauth2
RegistrationAccessToken http
oauth2 oauth2