generated: '2026-07-27' method: generated source: openapi/energy-queensland-cds-common-openapi.yml, openapi/energy-queensland-cds-energy-openapi.yml description: Recommended x-agentic-access execution contracts, classified heuristically from the OpenAPI. A governance starting point for exposing this API to AI agents — review and bind audience per deployment. See research/curity/agentic-governance/. summary: operations: 27 by_action_class: connected: 27 by_consequence: read: 27 human_in_the_loop_required: 0 anonymously_callable: 4 accreditation_gated: 23 operations: - path: /common/customer method: get operationId: getCustomer x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /common/customer/detail method: get operationId: getCustomerDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /discovery/outages method: get operationId: getOutages x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /discovery/status method: get operationId: getStatus x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/accounts method: get operationId: listEnergyAccounts x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/accounts/balances method: get operationId: listEnergyAccountBalancesBulk x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/accounts/balances method: post operationId: listEnergyAccountBalancesSpecificAccounts x-agentic-access: action-class: connected consequence: read subject: required audience: null token: max-ttl: 3600 audit: none note: Corrected from the heuristic classification. This is a POST only because the Consumer Data Standards use a request body to carry a list of account or service point ids; the operation retrieves data and creates, updates or deletes nothing. The whole CDR energy surface is read-only. - path: /energy/accounts/billing method: get operationId: listEnergyAccountBillingBulk x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/accounts/billing method: post operationId: listEnergyAccountBillingForSpecificAccounts x-agentic-access: action-class: connected consequence: read subject: required audience: null token: max-ttl: 3600 audit: none note: Corrected from the heuristic classification. This is a POST only because the Consumer Data Standards use a request body to carry a list of account or service point ids; the operation retrieves data and creates, updates or deletes nothing. The whole CDR energy surface is read-only. - path: /energy/accounts/invoices method: get operationId: listEnergyAccountInvoicesBulk x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/accounts/invoices method: post operationId: listEnergyInvoicesForSpecificAccounts x-agentic-access: action-class: connected consequence: read subject: required audience: null token: max-ttl: 3600 audit: none note: Corrected from the heuristic classification. This is a POST only because the Consumer Data Standards use a request body to carry a list of account or service point ids; the operation retrieves data and creates, updates or deletes nothing. The whole CDR energy surface is read-only. - path: /energy/accounts/{accountId} method: get operationId: getEnergyAccountDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/accounts/{accountId}/balance method: get operationId: getEnergyAccountBalance x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/accounts/{accountId}/billing method: get operationId: getBillingForEnergyAccount x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/accounts/{accountId}/concessions method: get operationId: getEnergyAccountConcessions x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/accounts/{accountId}/invoices method: get operationId: getEnergyAccountInvoices x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/accounts/{accountId}/payment-schedule method: get operationId: getEnergyAccountPaymentSchedule x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/electricity/servicepoints method: get operationId: listElectricityServicePoints x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/electricity/servicepoints/der method: get operationId: listElectricityDERBulk x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/electricity/servicepoints/der method: post operationId: listElectricityDERForSpecificServicePoints x-agentic-access: action-class: connected consequence: read subject: required audience: null token: max-ttl: 3600 audit: none note: Corrected from the heuristic classification. This is a POST only because the Consumer Data Standards use a request body to carry a list of account or service point ids; the operation retrieves data and creates, updates or deletes nothing. The whole CDR energy surface is read-only. - path: /energy/electricity/servicepoints/usage method: get operationId: listElectricityUsageBulk x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/electricity/servicepoints/usage method: post operationId: listElectricityUsageForServicePoints x-agentic-access: action-class: connected consequence: read subject: required audience: null token: max-ttl: 3600 audit: none note: Corrected from the heuristic classification. This is a POST only because the Consumer Data Standards use a request body to carry a list of account or service point ids; the operation retrieves data and creates, updates or deletes nothing. The whole CDR energy surface is read-only. - path: /energy/electricity/servicepoints/{servicePointId} method: get operationId: getElectricityServicePointDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/electricity/servicepoints/{servicePointId}/der method: get operationId: getElectricityDERForServicePoint x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/electricity/servicepoints/{servicePointId}/usage method: get operationId: getElectricityServicePointUsage x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/plans method: get operationId: listEnergyPlans x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none - path: /energy/plans/{planId} method: get operationId: getEnergyPlanDetail x-agentic-access: action-class: connected consequence: read subject: optional token: max-ttl: 3600 audit: none curated_by: API Evangelist curation_note: 'The mechanical heuristic classified the five POST operations as acting/write (one as physical, on a billing keyword match). All five were re-classified to connected/read after reading the specification: CDR energy exposes no write operation at all. Everything else is as derived. Consequence classes here are about DATA SENSITIVITY, not physical effect - nothing on this surface can switch, dispatch or control anything on the electricity network, because the network businesses (Energex, Ergon Energy Network) publish no API whatsoever.' access_note: Only four of the 27 operations (listEnergyPlans, getEnergyPlanDetail, getStatus, getOutages) are reachable by any agent without ACCC Consumer Data Right accreditation, mutual TLS and a per-consumer consent. The remaining 23 cannot be called by an autonomous agent at all unless it operates inside an accredited data recipient.