The Mobility House · Authentication Profile

The Mobility House Authentication

Authentication

The Mobility House declares 4 security scheme(s) across its OpenAPI definitions.

CompanyEnergyElectric VehiclesEV ChargingSmart ChargingEnergy ManagementVehicle-to-GridLoad ManagementFleetOCPPVDV 463ModbusGermany
Methods: Schemes: 4 OAuth flows: API key in:

Security Schemes

http
scheme: basic
Ocp-Apim-Subscription-Key apiKey
· in: header ()
none
http
scheme: basic

Source

Authentication Profile

the-mobility-house-authentication.yml Raw ↑
generated: '2026-08-30'
method: searched
source: 'https://vdv-docs.tmh.energy/initial-connection/initial-connection/ and
  https://tmh-help.freshdesk.com/en/support/solutions/articles/203000046009-chargepilot-charging-data-push-api
  and https://tmh-help.freshdesk.com/en/support/solutions/articles/203000046016-chargepilot-modbus-interface,
  fetched 2026-08-30. Derived nothing from OpenAPI: The Mobility House publishes no OpenAPI or Swagger
  document, so there are no securitySchemes to read.'
docs: https://vdv-docs.tmh.energy/initial-connection/initial-connection/
name: The Mobility House authentication profile
openapi_security_schemes: 0
schemes:
- id: vdv463-http-basic
  api: the-mobility-house-chargepilot-vdv-463
  type: http
  scheme: basic
  location: 'WebSocket upgrade request (Authorization header, credentials Base64-encoded)'
  description: 'Customers identify themselves during the VDV 463 WebSocket TLS handshake using HTTP
    Basic Authentication with a username and password issued by The Mobility House when the site is
    configured for VDV 463.'
  credential_issuance: 'Manual. The customer requests a ChargePilot site be enabled for VDV 463; The
    Mobility House configures the site, generates customer-specific credentials, and delivers them
    together with a recommended TMH certificate. There is no self-service key issuance.'
  transport_security: 'TLS mandatory — VDV 463 defines WebSocket Secure as the transport. The Mobility
    House additionally recommends pinning the certificate it supplies to prevent unauthorized access.'
  rotation: not documented
  scopes: none documented
- id: push-api-subscription-key
  api: the-mobility-house-chargepilot-charging-data-push-api
  type: apiKey
  in: header
  name: Ocp-Apim-Subscription-Key
  description: 'ChargePilot presents an Azure API Management subscription key to the customer-operated
    receiving endpoint when POSTing charging session data. The direction is inverted relative to a
    normal API key: the provider authenticates itself to the consumer.'
  credential_issuance: 'Agreed during Push-API onboarding with the customer success manager.'
  rotation: not documented
  scopes: none documented
- id: modbus-tcp-no-auth
  api: chargepilot-modbus-interface
  type: none
  description: 'The ChargePilot / TMH Controller Modbus TCP/IP server exposes no authentication. Access
    control is network-level only: the interface is deactivated by default, must be enabled by a
    customer success manager, is reachable on the local site network at a configurable IP with slave
    ID 1, and can be restricted to read-only (input registers) or read/write (input plus holding
    registers).'
  rotation: n/a
  scopes: n/a
- id: ocpp-station-auth
  api: chargepilot-ocpp
  type: http
  scheme: basic
  description: 'Charging stations connect into ChargePilot over OCPP. OCPP 1.6-J and 2.0.1 station
    authentication is defined by the OCPP standard rather than by a Mobility House-specific scheme;
    The Mobility House does not publish its per-station credential policy.'
  note: 'Recorded for completeness of the auth surface; not independently verified against a Mobility
    House document.'
oauth2: false
openid_connect: false
mutual_tls: 'partial — a TMH-issued certificate is recommended (not documented as required) on the
  VDV 463 connection.'
self_service_signup: false
signup_path: 'Sales / customer success. https://www.mobilityhouse.com/int_en/contact'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/the-mobility-house-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.