generated: '2026-07-27' method: searched source: >- Derived from openapi/ (both harvested Consumer Data Standards documents), conventions/agl-energy-conventions.yml, authentication/agl-energy-authentication.yml, errors/agl-energy-problem-types.yml and live probes on 2026-07-27; the CDR claims are grounded in the ACCC CDR Register entry for brand "AGL" (https://api.cdr.gov.au/cdr-register/v1/all/data-holders/brands/summary, HTTP 200) and the Consumer Data Standards security profile. description: >- Which cross-cutting and industry standards AGL's API surface conforms to. The answer is unusually clean because AGL implements a single statutory specification and nothing else: the CDR Consumer Data Standards v1.36.0, with its FAPI 1.0 Advanced security profile, its CDR-URN error registry and its header-based versioning. Everything outside that regime — Green Button/ESPI, OpenADR, IEEE 2030.5, OCPP/OCPI, IEC CIM, RFC 9457, GraphQL, AsyncAPI — is absent, and was checked rather than assumed. standards: - id: cdr-consumer-data-standards name: CDR Consumer Data Standards (Energy + Common), v1.36.0 conforms: true evidence: >- Designated energy data holder on the ACCC CDR Register (brand AGL, id d177e382-b12d-ed11-a832-000d3a8830d6, public base URI https://public.cdr.agl.com.au). GET /cds-au/v1/discovery/status and /discovery/outages returned HTTP 200 with conformant data/links/meta envelopes and x-v: 1 on 2026-07-27. authority: Data Standards Body (Treasury), regulator ACCC - id: openapi-3 conforms: true evidence: Both contracts are OpenAPI 3.0.3 documents; 27 operations, unique operationIds, tagged, with 2xx and 4xx responses. - id: oauth2 conforms: true evidence: CDR security profile mandates OAuth 2.0 authorization code flow for consumer data sharing. Not declared in the OpenAPI (securitySchemes is empty in the DSB documents). - id: oidc conforms: true evidence: OpenID Connect is mandated by the CDR security profile. No anonymous /.well-known/openid-configuration is served (probed 404) — metadata is distributed via the CDR Register. - id: fapi-1-advanced conforms: true evidence: The CDR Security Profile is built on FAPI 1.0 Advanced — request object signing, PAR, private_key_jwt, mTLS-bound tokens. - id: rfc9126-pushed-authorization-requests conforms: true evidence: PAR is mandatory in the CDR security profile. - id: rfc8705-mtls-client-authentication conforms: true evidence: mTLS with CDR Register-issued transport certificates, sender-constrained access tokens. - id: mtls conforms: true evidence: All consumer-data traffic between an ADR and AGL runs over mutual TLS. - id: rfc4122-uuid-correlation conforms: true evidence: x-fapi-interaction-id is an RFC 4122 UUID echoed by the data holder. - id: pagination conforms: true evidence: page / page-size query params with links{self,first,prev,next,last} and meta{totalRecords,totalPages}; verified live at 1343 records over 135 pages. - id: rfc9457-problem-details conforms: false evidence: Errors are application/json with an errors[] array of CDR URN codes, not application/problem+json. See errors/agl-energy-problem-types.yml. - id: rfc8594-sunset-header conforms: false evidence: Version retirement is date-driven through the DSB Future Dated Obligations schedule; retired versions answer HTTP 406 Header/UnsupportedVersion rather than emitting Sunset headers. - id: idempotency conforms: false evidence: No idempotency-key header in the standard or either spec. The whole surface is read-only, so there is nothing to make idempotent. - id: webhooks conforms: false evidence: No webhook, callback or push surface. The CDR is pull-only; an ADR polls under a standing consent. - id: asyncapi conforms: false evidence: No event or streaming surface exists, so no AsyncAPI applies (not a penalty — there is nothing to describe). - id: graphql conforms: false evidence: /graphql on the CDR public base URI returned 404 on 2026-07-27. - id: json-api conforms: false - id: odata conforms: false - id: scim conforms: false - id: fhir conforms: false - id: green-button-espi conforms: false evidence: No Green Button / NAESB ESPI surface. Australia's consumer energy data layer is CDR only. - id: ieee-2030-5 conforms: false evidence: No IEEE 2030.5 (SEP2) surface published by AGL, despite AGL's DER and VPP footprint. - id: openadr conforms: false - id: ocpp-ocpi conforms: false evidence: No EV-charging roaming or charge-point protocol surface published. - id: iec-cim conforms: false - id: rfc9116-security-txt conforms: false evidence: No /.well-known/security.txt on any host (well-known/agl-energy-well-known.yml). A human Responsible Disclosure Policy does exist. regulatory: regime: Consumer Data Right (Competition and Consumer Act 2010, Part IVD) role: designated energy data holder register: https://api.cdr.gov.au/cdr-register/v1/all/data-holders/brands/summary rules: CDR Rules — accreditation, consent, Schedule 2 information security controls privacy: Privacy Safeguards administered by the OAIC secondary_data_holder: AEMO (NMI standing data, metering data) compliance_program: published_certifications: [] note: >- No trust centre, no SOC 2 / ISO 27001 / PCI DSS attestation page and no security compliance portal was found on any AGL host (probe-security-programs returned trust=none on 2026-07-27; www.agl.com.au answers 403 to every machine client). AGL's security obligations here are statutory — CDR Rules Schedule 2 and the Security of Critical Infrastructure Act regime for energy assets — rather than a published certification programme aimed at developers. No Compliance pointer is therefore claimed in apis.yml.