# Con Edison > Consolidated Edison Company of New York (CECONY) is the investor-owned electric, gas and steam > distribution utility serving New York City and Westchester County; with sibling utility Orange & > Rockland it forms the regulated utility core of Consolidated Edison, Inc. Its API surface splits in > two: a gated, standards-based Green Button Connect My Data (NAESB REQ.21 ESPI 1.1) customer-energy > API branded "Share My Data", and an open, anonymously readable ArcGIS REST surface carrying > distribution-grid hosting-capacity data. Open on the grid, accredited on the customer. Generated by API Evangelist from the Con Edison provider profile. Con Edison publishes no llms.txt of its own (https://www.coned.com/llms.txt returns HTTP 404, probed 2026-07-27). Everything linked below was fetched from Con Edison's own public surface or derived from artifacts it publishes. ## APIs - [Green Button Connect My Data API](https://www.coned.com/en/accounts-billing/share-energy-usage-data/become-a-third-party): ESPI 1.1 machine-to-machine API for customer-authorized electric and gas interval usage, usage summaries, billing and retail customer records. Base URI https://api.coned.com/gbc/espi/1_1 (test: https://apit.coned.com/gbc/espi/1_1). OAuth 2.0, Atom/ESPI XML, 37 documented paths. NOT self-serve. - [Hosting Capacity Map REST API](https://www.coned.com/en/business-partners/hosting-capacity): Esri ArcGIS REST feature services carrying CECONY and Orange & Rockland segmented and network hosting capacity, EV load-serving transformer capacity, 33kV feeders, non-wires-solutions networks, LSRV eligibility and disadvantaged-community layers. No key, no login, anonymous HTTP 200. ## Specs - [DCX GBC API V2 (Swagger 2.0)](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/openapi/con-edison-green-button-connect-my-data-swagger.json): Con Edison's own published contract, saved verbatim. 37 paths, basePath /gbc/espi/1_1, no securityDefinitions declared. - [Postman collection "GBC Certification Third party V3.3"](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/collections/con-edison-green-button-connect-my-data.postman_collection.json): 39 requests, published by Con Edison. - [Postman environment "GBC Certification_ThirdParty_Env v3.3"](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/collections/con-edison-green-button-connect-my-data.postman_environment.json): base_url https://apit.coned.com/gbc/espi/1_1, all secrets empty. - [OpenAPI Overlay](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/overlays/con-edison-green-button-connect-my-data-overlay.yaml): API Evangelist enhancements — real host, documented OAuth 2.0 security schemes, rate limit and ESPI extensions. The harvested spec itself is never mutated. ## Docs - [Become a Third Party (developer portal)](https://www.coned.com/en/accounts-billing/share-energy-usage-data/become-a-third-party) - [Third-Party Technical Onboarding Document v4.4 (PDF, last updated 2026-05-07)](https://www.coned.com/-/media/files/coned/documents/accountandbilling/share-my-data/onboarding-doc.pdf) - [Share My Data FAQ for Third Party Vendors (PDF)](https://www.coned.com/-/media/files/coned/documents/accountandbilling/share-my-data/faq.pdf) - [Third-Party Company Registration Form](https://www.coned.com/en/accounts-billing/share-energy-usage-data/become-a-third-party/registration-form) - [Access Customer Data (business partners hub)](https://www.coned.com/en/business-partners/access-customer-data) - [Hosting Capacity: About (states REST API access)](https://www.coned.com/en/business-partners/hosting-capacity/about) - [Hosting Capacity Web Application](https://experience.arcgis.com/experience/d9d758c7736b44909dc3781937ca2ed5) - [Green Button Download My Data](https://www.coned.com/en/save-money/make-better-energychoices-with-green-button) - [Orange & Rockland third-party registration](https://www.oru.com/en/accounts-billing/share-energy-usage-data/become-a-third-party) ## Artifacts - [Authentication profile](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/authentication/con-edison-authentication.yml): OAuth 2.0 authorization_code, refresh_token and client_credentials grants; Basic client auth at the token endpoint; 3600-second access tokens; 60-second single-use authorization codes. - [OAuth scopes](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/scopes/con-edison-scopes.yml): ESPI functional blocks (FB=1,3,4,5,7,8,10,15,16,35,51,53,56,57,58,60,67) with IntervalDuration, BlockDuration, HistoryLength and BR qualifiers. - [API conventions](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/conventions/con-edison-conventions.yml): Atom/ESPI media types, startIndex and published-min/published-max filtering, UTC and DST interval rules, powerOfTenMultiplier scaling, batch semantics. - [Error catalog](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/errors/con-edison-problem-types.yml): 400/401 only; vendor JSON envelope {"Message": "..."}; no RFC 9457. - [Rate limits](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/rate-limits/con-edison-rate-limits.yml): 50 token-endpoint calls per minute; no limit on other endpoints. - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/lifecycle/con-edison-lifecycle.yml): versioning, environments, registration and authorization lifecycles. No status page, no deprecation policy. - [Conformance](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/conformance/con-edison-conformance.yml): NAESB REQ.21 ESPI, Green Button CMD V3.3, RFC 6749/6750, Atom; no OIDC, no RFC 9457, no security.txt. - [Webhooks (batch notification)](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/asyncapi/con-edison-batch-notification-webhooks.yml): HTTP 202 then a notification POST to the third party's ThirdPartyNotifyUri carrying an XML BatchList; 2-day retention. - [Data model](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/data-model/con-edison-data-model.yml): the published Account/UsagePoint/Meter/MeterReading/IntervalBlock/CustomerAgreement graph with Con Edison's own cardinalities. - [Sandbox](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/sandbox/con-edison-sandbox.yml): supervised test environment at apit.coned.com and uat10.coned.com; no public test credentials. - [Domain security probe](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/security/con-edison-domain-security.yml) - [Well-known probe](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/well-known/con-edison-well-known.yml): verified absence — no /.well-known/ documents on any host. - [MCP candidate tool list](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/mcp/con-edison-mcp.yml): 37 candidate tools derived from the Swagger definition. No Con Edison MCP server exists. - [Agent skills](https://raw.githubusercontent.com/api-evangelist/con-edison/refs/heads/main/skills/_index.yml) ## Access - Green Button Connect My Data is free of charge but NOT self-serve: registration, a signed Data Security Agreement, a technical onboarding form and 30 to 60 days of supervised certification testing precede production credentials. Con Edison states plainly that it "is unable to support API development for third parties." - Customer consent is per-account and revocable; authorizations auto-revoke after 365 days of third-party inactivity. History is capped at two years; real-time electric data covers the last 24 hours at 45-minute latency and is explicitly not billing quality. - The Hosting Capacity ArcGIS services require no authentication at all and are "provided for informational purposes only" — not a substitute for the interconnection application process. - Technical contact: dlsharemydatatech@coned.com. Program contact: ShareMyData@coned.com.