# FLO > FLO (founded 2009 as AddEnergie, headquartered in Quebec City) designs and manufactures Level 2 and DC fast EV charging hardware and operates one of the largest public charging networks in North America. FLO publishes **no first-party developer API**: there is no developer portal, no API reference and no OpenAPI, AsyncAPI or GraphQL document on any flo.com host. Its integration seams — OCPP 1.6J down to the station, OCPI sideways to peer networks, OpenADR 2.0 up to utility demand-response platforms — are all reached through commercial agreements. The only live, anonymously callable machine-readable surface in FLO's estate is the Shopify storefront MCP server on its hardware store. Source of truth for this profile: https://raw.githubusercontent.com/api-evangelist/flo-ev/refs/heads/main/apis.yml Generated by the API Evangelist enrichment pipeline on 2026-07-27. method: generated (no /llms.txt is published by FLO — https://www.flo.com/llms.txt returns 404). ## What an agent can actually call - [FLO Store MCP server](https://store.flo.com/api/mcp): live MCP endpoint (protocol 2025-06-18, serverInfo `storefront-renderer` 0.1.0). Five tools — `search_catalog`, `get_product_details`, `get_cart`, `update_cart`, `search_shop_policies_and_faqs`. `tools/list` and catalog search work anonymously; cart and customer operations need a Shopify Customer Account token. - [Store product feed](https://store.flo.com/products.json): public JSON list of FLO hardware and accessories. - [Store collection feed](https://store.flo.com/collections.json): public JSON list of store collections. - [Store protected-resource metadata](https://store.flo.com/.well-known/oauth-protected-resource): RFC 9728 document naming the authorization server for the MCP endpoint. - [Store OIDC discovery](https://store.flo.com/.well-known/openid-configuration): Shopify Customer Accounts, scopes include `customer-account-mcp-api:full`. - [Community OIDC discovery](https://network.flo.com/.well-known/openid-configuration): Salesforce Experience Cloud identity for FLO's login-gated partner/community portal. ## What an agent cannot call - There is no FLO charging API. No session, station-telemetry, roaming or demand-response endpoint is published. `api.flo.com`, `developer.flo.com`, `developers.flo.com`, `docs.flo.com`, `data.flo.com`, `ocpi.flo.com` and `status.flo.com` do not resolve. - `auth.flo.com` is a live AWS API Gateway that answers every path with `403 {"message":"Missing Authentication Token"}` — real infrastructure, no public route. - Charging session, usage and billing data is reachable only by the account holder at https://account.flo.com/ or by the station owner in the Owner's Portal. - Access to any FLO integration is a negotiated commercial arrangement (the EnergyHub OpenADR integration is the public example), not a signup form. ## Standards FLO names - [OCPP 1.6J](https://www.flo.com/products/hardware/smartdc/) — station-to-network, stated in FLO's own hardware spec sheets. - [OCPI](https://www.flo.com/insights/ev-charging-roaming/) — roaming between networks; no credentials/versions endpoint or party ID is published. - [OpenADR 2.0](https://www.flo.com/business/utilities/) — utility demand response; the page's phrase "Through OpenADR 2.0 or FLO's flexible API" is the only first-party mention of a FLO API anywhere. - [Plug and Charge / autocharge](https://www.flo.com/news/flo-enables-gm-plug-and-charge/) — driver authentication over CCS with GM vehicles. FLO does not name ISO 15118. ## Human surfaces - [Website](https://www.flo.com/) - [Account login](https://account.flo.com/) — drivers and station owners - [Support](https://www.flo.com/support/) and [help desk](https://helpdesk.flo.com/support/home) - [Product documentation](https://www.flo.com/business/product-documentation/) — hardware spec sheets, installation and user guides - [Partner networks](https://www.flo.com/company/partner-networks/) and [find a partner](https://www.flo.com/company/find-a-partner/) - [FLO for utilities](https://www.flo.com/business/utilities/) - [Store](https://store.flo.com/) - [Trust center](https://trust.flo.com/) — SOC 2 Type 2 (BARR Advisory, announced 2024-10-22) - [Blog](https://www.flo.com/ev-charging-insights/) · [News](https://www.flo.com/news-press/) - [Privacy policy](https://www.flo.com/privacy-policy/) · [Terms](https://www.flo.com/terms-conditions/) ## Artifacts in this repo - `mcp/flo-ev-mcp.yml` — MCP server manifest; `mcp/flo-ev-store-mcp-tools.json` — verbatim `tools/list` response with full input schemas - `well-known/flo-ev-well-known.yml` — /.well-known/ probe index across five hosts, plus the raw discovery documents - `authentication/flo-ev-authentication.yml` — identity profile (OIDC, OAuth 2.0, human auth surfaces) - `scopes/flo-ev-scopes.yml` — every OAuth scope advertised on a flo.com host (all platform-defined; FLO defines none) - `conformance/flo-ev-conformance.yml` — standards conformance, including the explicit negatives (no OpenAPI, no AsyncAPI, no security.txt, Green Button and CDR not applicable) - `errors/flo-ev-problem-types.yml` — the error envelopes FLO's live hosts actually return - `lifecycle/flo-ev-lifecycle.yml` — versioning, deprecation, SLA and status-page findings - `security/flo-ev-domain-security.yml` — TLS/HSTS/DNS posture and the certificate-transparency subdomain census - `security/flo-ev-trust-center.yml` — trust center and certifications - `skills/flo-ev-shop-flo-store.md` — agent skill for the storefront MCP server - `review.yml` — the full probe log behind the "no public API" finding