generated: '2026-07-27' method: searched source: >- https://www.hydroone.com/saving-money-and-energy/green-button note: >- Asserted from Hydro One's published Green Button pages and third-party terms, from the Ontario regulation that binds Hydro One, and from the observed live CMD authorization surface. No conformance claim here rests on a self-declared compliance badge alone; each entry carries its evidence. Hydro One publishes no machine-readable API contract, so nothing was derived from a specification. standards: - id: green-button-connect-my-data conforms: true evidence: >- Live OAuth 2.0 authorization surface at https://www.hydroone.com/green-button-cmd-home (HTTP 200) carrying NAESB ESPI function-block scope syntax, plus a published third-party vendor onboarding form, terms and connectivity-testing programme. - id: green-button-download-my-data conforms: true evidence: >- Hydro One's Green Button page states Download My Data is "available now", offering up to 24 months of billing, consumption and transaction data in "industry-standard XML" from within My Account (https://www.hydroone.com/myaccount/green-button-download-my-data, HTTP 302 to authentication). - id: naesb-req21-espi conforms: true version: '3.3' evidence: >- Ontario's Energy Data regulation ties Green Button implementations to NAESB REQ.21 ESPI; the observed authorization request uses ESPI function-block (FB=) scope syntax. Hydro One does not itself publish a version number — 3.3 is the version named in the Green Button Alliance's Ontario certification announcement. - id: espi-atom-xml conforms: true evidence: ESPI payloads are Atom-based XML; Hydro One describes "industry-standard XML". - id: oauth2-authorization-code conforms: true evidence: >- Observed response_type=code authorization request with a Hydro One-issued client_id and a third-party redirect_uri; terms describe issuance of Client ID and Client Secret. - id: tls-required conforms: true evidence: >- Conditions of Participation require the vendor to "implement Transport Layer Security for all exchanges with HONI". - id: mutual-certificate-exchange-rsa2048 conforms: true evidence: >- Conditions of Participation require unexpired, unrevoked RSA certificates with a public key length of at least 2048 bits from a HONI-supported CA. - id: oauth2-discovery-rfc8414 conforms: false evidence: '/.well-known/oauth-authorization-server returns HTTP 500 (SharePoint error page).' - id: openid-connect conforms: false evidence: '/.well-known/openid-configuration returns HTTP 500; no OIDC discovery document is served.' - id: openapi conforms: false evidence: >- No OpenAPI or Swagger definition exists on any Hydro One host. /openapi.json and /swagger.json return HTTP 200 with text/html (the SharePoint catch-all page), not JSON. - id: rfc9457-problem-details conforms: false evidence: No error contract is published; the API surface itself is unpublished. - id: rfc9116-security-txt conforms: false evidence: '/.well-known/security.txt returns HTTP 500.' - id: api-catalog-rfc9727 conforms: false evidence: '/.well-known/api-catalog returns HTTP 500.' - id: ocpp conforms: false - id: ocpi conforms: false - id: openadr conforms: false - id: ieee-2030-5 conforms: false - id: iec-cim-61968-61970 conforms: false regulatory: - id: ontario-reg-633-21 name: O. Reg. 633/21 (Energy Data), Electricity Act, 1998, s. 25.35.8 url: https://www.ontario.ca/laws/regulation/210633 applies: true applies_evidence: >- Hydro One Networks Inc. is a licensed Ontario electricity local distribution company and therefore falls inside the class the regulation binds. obligation: >- Implement Green Button Download My Data and Connect My Data and have those implementations certified by the Green Button Alliance (deadline 01 November 2023). regulator: https://www.oeb.ca/consumer-information-and-protection/green-button certifications: - id: green-button-alliance-certification claimed: false verified: false note: >- The Green Button Alliance announcement of 55 certified Ontario utility platforms (NAESB REQ.21 ESPI v3.3) does not name individual utilities, the GBA certified-products registry paths probed all returned HTTP 404, and the GBA Green Button Directory pages fetched do not name Hydro One. Hydro One makes no certification claim on its own site. Recorded as unverified, not as absent. compliance_program_published: false compliance_program_note: >- Hydro One publishes no trust centre, no SOC 2 / ISO 27001 / PCI attestation page, and no vulnerability disclosure policy. Probes of /security, /cyber-security, /responsible-disclosure and /report-a-vulnerability returned HTTP 404, and /.well-known/security.txt returned HTTP 500. No `Compliance` pointer is emitted. related: - authentication/hydro-one-authentication.yml - scopes/hydro-one-scopes.yml - lifecycle/hydro-one-lifecycle.yml