generated: '2026-07-27' method: searched source: >- Derived from well-known/eon-next-openid-configuration.json, well-known/eon-next-security.txt, authentication/eon-next-authentication.yml and live anonymous probes on 2026-07-27, plus the standards search recorded in review.yml. Every "conforms: true" below is evidenced by a document fetched anonymously; every "conforms: false" was checked, not assumed. description: >- E.ON Next conforms to a short list of identity standards and to nothing else, because identity is the only surface it describes machine-readably. The authorization server at auth.eonnext.com is a conformant OpenID Connect Provider with RFC 8414 metadata, PKCE, device flow, CIBA, mTLS-bound tokens and DPoP advertised; www.eonnext.com serves an RFC 9116 security.txt. Everything on the API-contract side — OpenAPI, GraphQL, AsyncAPI, RFC 9457 problem details, webhooks, idempotency, rate-limit signalling — is absent, and every energy-sector data standard (Green Button/ESPI, CDR, OCPP/OCPI, OpenADR, IEEE 2030.5, IEC CIM) was searched for and not found. The only mandated standard E.ON Next actually implements is the GB Smart Energy Code / SMETS2 metering regime, which produces no supplier-published endpoint. standards: - id: openid-connect-discovery name: OpenID Connect Discovery 1.0 conforms: true evidence: >- https://auth.eonnext.com/.well-known/openid-configuration returned HTTP 200 with issuer, authorization_endpoint, token_endpoint, userinfo_endpoint and jwks_uri on 2026-07-27. - id: oidc name: OpenID Connect Core 1.0 conforms: true evidence: id_token signing algs RS256/PS256/HS256, standard claims set, end_session_endpoint, backchannel logout supported. - id: oauth2 name: OAuth 2.0 (RFC 6749) conforms: true evidence: authorization_code, client_credentials, refresh_token, implicit and password grants advertised. - id: rfc8414-authorization-server-metadata name: OAuth 2.0 Authorization Server Metadata conforms: true evidence: /.well-known/oauth-authorization-server returned HTTP 200, byte-identical to the OIDC discovery document. - id: rfc7517-jwks name: JSON Web Key Set conforms: true evidence: /.well-known/jwks.json returned two RSA signing keys with x5c chains (HTTP 200). - id: rfc7636-pkce name: Proof Key for Code Exchange conforms: true evidence: 'code_challenge_methods_supported: [S256, plain].' - id: rfc8628-device-authorization-grant conforms: true evidence: device_authorization_endpoint https://auth.eonnext.com/oauth/device/code and the urn:ietf:params:oauth:grant-type:device_code grant. - id: rfc8693-token-exchange conforms: true evidence: urn:ietf:params:oauth:grant-type:token-exchange advertised. - id: rfc8705-mtls-client-authentication conforms: true evidence: 'token_endpoint_auth_methods_supported includes tls_client_auth and self_signed_tls_client_auth; tls_client_certificate_bound_access_tokens: true.' - id: rfc9449-dpop name: OAuth 2.0 Demonstrating Proof of Possession conforms: true evidence: 'dpop_signing_alg_values_supported: [ES256].' - id: ciba name: OpenID Connect Client-Initiated Backchannel Authentication conforms: true evidence: backchannel_authentication_endpoint https://auth.eonnext.com/bc-authorize, poll delivery mode. - id: rfc7591-dynamic-client-registration conforms: partial evidence: >- registration_endpoint https://auth.eonnext.com/oidc/register is advertised but was not exercised; no third-party registration path is documented, so open registration is not claimed. - id: rfc9116-security-txt conforms: true evidence: PGP-signed /.well-known/security.txt on www.eonnext.com and eonnext.com (HTTP 200), Contact + Expires + Encryption + Preferred-Languages. No Policy field. - id: rfc9126-pushed-authorization-requests conforms: false evidence: No pushed_authorization_request_endpoint in the discovery document. - id: fapi-1-advanced conforms: false evidence: No PAR, no request_uri support, no FAPI profile advertised. This is a mainstream CIAM tenant, not a regulated data-sharing deployment. - id: openapi-3 conforms: false evidence: >- No OpenAPI anywhere. /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /docs, /redoc and /rapidoc were probed on api.eonnext.com and data.eonnext.com (all HTTP 403, AWS API Gateway) and on www.eonnext.com and auth.eonnext.com (404). - id: graphql conforms: false evidence: >- /graphql and /v1/graphql/ on api.eonnext.com and data.eonnext.com return the AWS API Gateway 403; no introspection is possible. The underlying Kraken platform is GraphQL-shaped, but nothing is exposed to third parties. - id: asyncapi conforms: false evidence: No event, streaming or webhook surface is published, so no AsyncAPI applies. Not a penalty — there is nothing to describe. - id: webhooks conforms: false evidence: No webhook catalogue, callback documentation or subscription surface found on any host. - id: rfc9457-problem-details conforms: false evidence: The only observable error body is the AWS API Gateway {"message":"Missing Authentication Token"}; not application/problem+json. - id: idempotency conforms: false evidence: No idempotency-key contract is documented; there is no public write surface. - id: rfc8594-sunset-header conforms: false evidence: No deprecation or versioning policy is published. - id: json-api conforms: false - id: odata conforms: false - id: scim conforms: false - id: fhir conforms: false - id: green-button-espi name: Green Button / NAESB ESPI conforms: false evidence: No Green Button or ESPI reference on any eonnext.com host, and no Green Button Alliance certification. Green Button is a North American standard. - id: cdr-consumer-data-standards name: Australian Consumer Data Right (energy) conforms: false evidence: E.ON Next is a GB entity; CDR designation and the Consumer Data Standards do not apply. - id: ocpp-ocpi conforms: false evidence: >- No charge-point or roaming protocol surface is published despite E.ON Next selling EV chargers and running the Next Drive EV tariff. - id: openadr conforms: false - id: ieee-2030-5 conforms: false - id: iec-cim-61968-61970 conforms: false regulatory: regime: >- Great Britain Smart Metering Implementation Programme — Smart Energy Code (SEC) and the licensed Data Communications Company (DCC), under Ofgem supply licence conditions. status: live-implemented (infrastructure obligation only) produces_supplier_api: false note: >- Britain mandated the metering pipes, not a consumer data right. SMETS2 meters and the DCC are live; no consumer data-portability API obligation exists for a GB supplier. DESNZ's "Developing an energy smart data scheme" call for evidence closed 10 March 2025 with no published government response, and no energy secondary legislation has been made under the Data (Use and Access) Act 2025. Third-party access to GB smart-meter data runs through the DCC "Other User" role and SEC party status, not through E.ON Next. compliance_program: published_certifications: [] note: >- No trust centre and no published SOC 2 / ISO 27001 / PCI DSS / CSA STAR attestation page was found on any E.ON Next host (probe-security-programs returned trust=none on 2026-07-27; www.eon.com group security pages answer 403 to machine clients). No Compliance pointer is claimed in apis.yml.