SA Power Networks · Authentication Profile

Sa Power Networks Authentication

Authentication

SA Power Networks secures its APIs with openIdConnect and oauth2 across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode and implicit flow(s).

EnergyAustraliaUtilitiesElectricityGridDistribution NetworkSmart MeteringSolarDEROpen Data
Methods: openIdConnect, oauth2 Schemes: 2 OAuth flows: authorizationCode, implicit API key in:

Security Schemes

meterdata-oidc openIdConnect
dapr-cognito oauth2
· flows: implicit

Source

Authentication Profile

sa-power-networks-authentication.yml Raw ↑
generated: '2026-07-27'
method: searched
source: >-
  live anonymous probing of SA Power Networks portal hosts on 2026-07-27, plus the
  OpenID Connect discovery document published by the meter-data community
docs: https://www.sapowernetworks.com.au/industry/access-your-clients-meter-data/
summary:
  types: [openIdConnect, oauth2]
  api_key_in: []
  oauth2_flows: [authorizationCode, implicit]
  applies_to: portal logins only
  note: >-
    SA Power Networks operates no API and therefore has no API authentication model.
    Both auth surfaces below are human browser logins in front of web applications:
    an AWS Cognito user pool for the DAPR network-visualisation map viewer, and a
    Salesforce Experience Cloud identity provider for the "Your Meter Data" portal
    used by Authorised Representatives. There is no client-credentials flow, no API
    key issuance, no documented token acquisition path for a machine consumer, and
    no published scope model of SA Power Networks' own design.
schemes:
- name: meterdata-oidc
  type: openIdConnect
  surface: '"Your Meter Data" portal (Authorised Representative access to a client''s metering data)'
  platform: Salesforce Experience Cloud
  openIdConnectUrl: https://customer.portal.sapowernetworks.com.au/meterdata/.well-known/openid-configuration
  issuer: https://customer.portal.sapowernetworks.com.au/meterdata
  discovery_status: 200
  endpoints:
    authorization: https://customer.portal.sapowernetworks.com.au/meterdata/services/oauth2/authorize
    token: https://customer.portal.sapowernetworks.com.au/meterdata/services/oauth2/token
    userinfo: https://customer.portal.sapowernetworks.com.au/meterdata/services/oauth2/userinfo
    revocation: https://customer.portal.sapowernetworks.com.au/meterdata/services/oauth2/revoke
    introspection: https://customer.portal.sapowernetworks.com.au/meterdata/services/oauth2/introspect
    registration: https://customer.portal.sapowernetworks.com.au/meterdata/services/oauth2/register
    end_session: https://customer.portal.sapowernetworks.com.au/meterdata/services/auth/idp/oidc/logout
    jwks_uri: https://customer.portal.sapowernetworks.com.au/meterdata/id/keys
  response_types_supported: [code, token, token id_token]
  id_token_signing_alg_values_supported: [RS256]
  token_endpoint_auth_methods_supported: [client_secret_post, client_secret_basic, private_key_jwt]
  scopes: scopes/sa-power-networks-scopes.yml
  gate: >-
    Registration is not self-serve. A third party must obtain the customer's consent,
    complete the Authorised Representative Registration form (PDF) and be confirmed
    eligible by SA Power Networks before an account exists to authenticate.
  evidence:
  - url: https://customer.portal.sapowernetworks.com.au/meterdata/.well-known/openid-configuration
    httpStatus: 200
    fetched: '2026-07-27'
    file: well-known/sa-power-networks-meterdata-openid-configuration.json
  - url: https://customer.portal.sapowernetworks.com.au/services/data
    httpStatus: 200
    fetched: '2026-07-27'
    note: >-
      Salesforce platform REST version index, 37 versions v31.0 (Summer '14) through
      v67.0 (Summer '26), served anonymously. Vendor platform plumbing exposed by the
      community host — not an SA Power Networks API, not documented by SA Power
      Networks, and every data path under it requires a session.
  - url: https://customer.portal.sapowernetworks.com.au/services/data/v60.0
    httpStatus: 401
    fetched: '2026-07-27'
    note: '[{"message":"Authorization required","errorCode":"INVALID_SESSION_ID"}]'
- name: dapr-cognito
  type: oauth2
  surface: DAPR Network Visualisation Portal (map viewer of network capacity and constraints)
  platform: AWS Cognito user pool (ap-southeast-2), portal hosted by Rosetta
  flows:
  - flow: implicit
    authorizationUrl: https://sapndapr.auth.ap-southeast-2.amazoncognito.com/login
    client_id: 4407rsobdsip2kthm31e9l6fd3
    redirect_uri: https://dapr.sapowernetworks.com.au/index.php
    scopes: [aws.cognito.signin.user.admin, email, openid, profile]
  discovery: none
  discovery_note: >-
    https://sapndapr.auth.ap-southeast-2.amazoncognito.com/.well-known/openid-configuration
    returns 404 — Cognito hosted-UI domains do not serve discovery, and the user pool
    ID needed to reach the real document is not disclosed. Re-verified 2026-07-27.
  gate: self-serve sign-up through the Cognito hosted UI
  evidence:
  - url: https://dapr.sapowernetworks.com.au/
    httpStatus: 200
    fetched: '2026-07-27'
    note: page body is a redirect shim to the Cognito hosted UI with response_type=token
  - url: https://sapndapr.auth.ap-southeast-2.amazoncognito.com/oauth2/userInfo
    httpStatus: 400
    fetched: '2026-07-27'
    note: 'returns {"error":"invalid_request"} — endpoint live, bearer token required'
absent:
- api_keys
- client_credentials
- mutual_tls
- developer_registration
- machine_consumer_path