generated: '2026-07-27' method: derived source: >- Derived from the CAISO published interface documents and live behaviour captured in conventions/caiso-conventions.yml, errors/caiso-error-codes.yml and authentication/caiso-authentication.yml description: >- What the CAISO public API surface does and does not conform to. The one standard that genuinely governs it is the US federal open-access transparency regime — FERC Order Nos. 888/889 require transmission providers to operate an Open Access Same-time Information System, and oasis.caiso.com is CAISO's implementation of that obligation. On the technical side the payload format is IEC CIM-derived XML validated against CAISO-published XSDs, with a CSV alternative. Nothing else in the modern web-API standards stack is present: no OAuth 2.0, no OpenID Connect, no OpenAPI, no AsyncAPI, no JSON at all, no RFC 9457 problem details, no RFC 8594 sunset headers, no RFC 9116 security.txt. That is an accurate reflection of an interface designed in 2006 for regulated market transparency rather than for developer ergonomics. standards: - id: ferc-order-889-oasis conforms: true evidence: >- CAISO operates its Open Access Same-time Information System at oasis.caiso.com in satisfaction of FERC Order Nos. 888/889 and its FERC-approved tariff; the Download API returned real market data to anonymous requests on 2026-07-27. - id: iec-cim-xml conforms: true evidence: >- Interface Specification section 3.1 — OASIS returns XML "in CIM format" validated against oasisReport.xsd, oasisBid.xsd, oasiscbBid.xsd and oasisMaster.xsd; live payloads declare xmlns:m="http://www.caiso.com/soa/OASISReport_v1.xsd". - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document is published. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs and /redoc on oasis.caiso.com, www.caiso.com and developer.caiso.com on 2026-07-27 — all 404, or a SharePoint error page served with HTTP 200 on the developer host. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface exists; /asyncapi.yaml returns 404. - id: graphql conforms: false evidence: /graphql returns 404 on www.caiso.com; no GraphQL surface is documented. - id: mcp conforms: false evidence: No Model Context Protocol server is published; mcp.caiso.com does not resolve. - id: oauth2 conforms: false evidence: >- The public API is anonymous; participant systems use PKI client certificates. No authorization server document is served. - id: openid-connect conforms: false evidence: /.well-known/openid-configuration returns 404 on every CAISO host probed. - id: rfc9457-problem-details conforms: false evidence: >- Errors are returned as an ERROR block (ERR_CODE/ERR_DESC) inside a zipped CIM XML document with HTTP 200, not as application/problem+json. - id: rfc9116-security-txt conforms: false evidence: /.well-known/security.txt returns 404 on www.caiso.com and oasis.caiso.com. - id: rfc8594-sunset-header conforms: false evidence: >- No Sunset or Deprecation headers are emitted and no deprecation policy is published; the API Terms of Use reserve the right to make backwards-incompatible changes without notice. - id: rfc9727-api-catalog conforms: false evidence: /.well-known/api-catalog returns 404. - id: json-api conforms: false evidence: No JSON representation exists on either public interface. - id: http-conditional-requests conforms: false evidence: No ETag, Last-Modified or Cache-Control conventions are documented or observed. - id: rate-limit-headers conforms: false evidence: >- Throttling is signalled with HTTP 429 and an HTML body only; no RateLimit or Retry-After headers are returned. - id: green-button-espi conforms: false not_applicable: true evidence: >- Green Button / ESPI covers retail customer interval usage data. CAISO is a wholesale system and market operator with no retail customers and no customer-level data. See review.yml. - id: openadr conforms: false not_applicable: true evidence: >- No OpenADR, IEEE 2030.5, OCPP or OCPI reference was found on any CAISO public surface. compliance_programs: security_certifications_published: false note: >- CAISO publishes a corporate compliance program at https://www.caiso.com/legal-regulatory/compliance covering NERC reliability standards, tariff compliance and a compliance hotline — regulatory compliance for a grid operator, not an information-security certification posture. No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation is published, and no trust center exists.