# Measurabl > ESG (environmental, social and governance) data and sustainability management platform for > commercial real estate. Owners, investors, asset managers and capital-markets participants use it > to collect utility and waste data, account for carbon, track green building certifications and > ratings, comply with local building performance ordinances, model CRREM transition risk, and > report at building, fund and portfolio level. Five REST APIs are published as OpenAPI 3.0.1 at > api.measurabl.com, all JSON:API over OAuth 2.0 client credentials. Generated by API Evangelist on 2026-08-01. Measurabl publishes no llms.txt of its own — every host probed returned 404 (api., www., support., measurabl.com), and app.measurabl.com is a single-page app whose catch-all answers 200 HTML for every path. This file is generated from the harvested specs and the repo's artifacts. ## Access model API access is **not self-serve**. It requires Premium Tier entitlement (or partner status acting on behalf of a customer), and the client key and secret are issued by a Measurabl Customer Delivery Manager. **There is no sandbox or test environment** — integrations are built against live data. ## APIs - [Measurabl Core API](https://api.measurabl.com/api-docs/index.html?urls.primaryName=Measurabl+Core+API+Docs): Read and write portfolios, buildings, spaces, funds, energy/water meters and readings, waste meters and readings, certifications, certification types and ratings. 57 operations, base path /core/v0. - [ESGx Buildings API](https://api.measurabl.com/api-docs/index.html?urls.primaryName=ESGx+Buildings+V0+Docs): Asset-level energy estimates, carbon estimates, certification lookups, ordinance lookups and CRREM lookups, individually or as async batches with CSV upload and export. 39 operations, base path /insights/v0. - [ESGx Securities API](https://api.measurabl.com/api-docs/index.html?urls.primaryName=ESGx+Securities+V0+Docs): Listed real estate ESG reports with company-level and building-level data sets. 8 operations, read-only, base path /insights/v0. - [ESGx Securities Compliance Files API](https://api.measurabl.com/api-docs/index.html?urls.primaryName=ESGx+Securities+Compliance+Files+V0+Docs): List and download compliance files for the ESGx Securities datasets. 3 operations, read-only. - [Partner API](https://api.measurabl.com/api-docs/index.html?urls.primaryName=Partner+API+V0+Docs): Read-only partner projection — portfolios, buildings, and monthly utility data. 3 operations, base path /partners/v0. ## Specs - [Core OpenAPI 3.0.1](openapi/measurabl-core-openapi.yml) - [ESGx Buildings OpenAPI 3.0.1](openapi/measurabl-esgx-buildings-openapi.yml) - [ESGx Securities OpenAPI 3.0.1](openapi/measurabl-esgx-securities-openapi.yml) - [ESGx Securities Compliance Files OpenAPI 3.0.1](openapi/measurabl-esgx-securities-compliance-files-openapi.yml) - [Partner OpenAPI 3.0.1](openapi/measurabl-partners-openapi.yml) - Verbatim harvested originals: `openapi/_original/*.json` ## How the APIs behave - **Auth**: OAuth 2.0 client credentials, single token endpoint `https://api.measurabl.com/token`. Applied to all 110 operations. The flow declares an **empty scopes map** — authorization is entitlement-based, not scope-based. - **Media type**: `application/vnd.api+json`. Every response is a [JSON:API](https://jsonapi.org/) document. The specs point integrators at JSON:API's third-party client libraries rather than at a Measurabl SDK. - **Pagination**: `page` (default 1) and `size` (default 25, max 200); `pageSize` on some ESGx collections. JSON:API `links` with first/last/prev/next. **Requesting a page past the last page returns 404, not an empty collection.** - **Filtering**: RSQL-style `filter` query parameter — `yearbuilt==1969`, `updatedAt=ge=2022-11-01T00:00`. - **Async work**: create-then-poll. POST the estimate/lookup/batch, then GET it until `status` is `JOB_SUCCESS`. - **Downloads**: exports and datasets answer `302` with a `Location` header to a pre-signed URL; meter reading bills use `303`. - **Errors**: JSON:API error objects (`errors[]` with id/status/code/title/detail/source.pointer). **Not RFC 9457 problem+json.** - **Rate limits**: per endpoint per 5-minute window — 1000 GET; 200 writes on meter endpoints; 100 writes elsewhere. **No rate-limit response headers are published.** - **Idempotency**: none. No Idempotency-Key header or parameter exists. Retried POSTs create duplicates. - **Events**: none. No webhooks, no streaming, no AsyncAPI. Change detection is polling with an `updatedAt` filter. ## Derived artifacts (API Evangelist) - [Authentication profile](authentication/measurabl-authentication.yml) - [OAuth scopes](scopes/measurabl-scopes.yml) — declared, but empty - [API conventions](conventions/measurabl-conventions.yml) - [Error catalog](errors/measurabl-problem-types.yml) - [Rate limits](rate-limits/measurabl-rate-limits.yml) - [Data model](data-model/measurabl-data-model.yml) - [Lifecycle](lifecycle/measurabl-lifecycle.yml) - [Changelog](changelog/measurabl-changelog.yml) - [Conformance](conformance/measurabl-conformance.yml) - [Trust center](security/measurabl-trust-center.yml) - [Domain security](security/measurabl-domain-security.yml) - [Well-known probe results](well-known/measurabl-well-known.yml) - [Packages](packages/measurabl-packages.yml) — no first-party SDK exists - [MCP candidate tool surface](mcp/measurabl-mcp.yml) — derived, no server published - [Agent skills](skills/_index.yml) - [OpenAPI overlays](overlays/) ## Docs - [API docs portal (Swagger UI)](https://api.measurabl.com/api-docs/) - [Getting started guide](https://support.measurabl.com/hc/en-us/articles/34695708902541-Measurabl-API-Getting-Started-Guide) - [Authentication](https://support.measurabl.com/hc/en-us/articles/15889532915085-How-do-I-authenticate-with-Measurabl-s-Core-API-) - [Usage / rate limits](https://support.measurabl.com/hc/en-us/articles/15889355100429-Core-API-Usage-Rate-Limits) - [Pagination and filtering](https://support.measurabl.com/hc/en-us/articles/15889550313101-Core-API-Pagination-Filtering-Requests) - [Core API FAQs](https://support.measurabl.com/hc/en-us/articles/7686912783373-Core-API-FAQs) - [Measurabl API FAQ](https://www.measurabl.com/measurabl-api-faq/) - [Release notes](https://api.measurabl.com/release_notes) - [Code samples (Node + Python)](https://github.com/Measurabl/measurabl_api_code_samples) - [Help center](https://support.measurabl.com/hc/en-us) ## Company - [Website](https://www.measurabl.com/) - [Platform](https://www.measurabl.com/platform/) - [Security and compliance](https://www.measurabl.com/security/) — SOC 2 Type 2, ISO 27001:2013, GDPR - [Blog](https://www.measurabl.com/blog/) - [Privacy policy](https://www.measurabl.com/privacy-policy/) - [Partner network](https://www.measurabl.com/measurabl-partner-network/) - [GitHub](https://github.com/Measurabl) - [Sign up](https://app.measurabl.com/users/auth/identities?screen_hint=signup) ## Known gaps - **No operationId on any of the 110 operations** — blocks operation-level referencing from Arazzo, agent skills and SDK generators. - **No `servers` array in any of the five specs** — the base URL cannot be resolved from the document alone. - **Six CRREM paths are published as empty path items** with no HTTP operations declared, so the CRREM transition-risk capability is visible in the spec but not callable from it. - **No `/.well-known/` document of any kind**, no security.txt, no OAuth authorization-server metadata. - **No vulnerability disclosure channel** — the security page describes an internal vulnerability management program but names no way for an outside researcher to report a finding. - **No status page** and no public SLA. - **No release notes since 2023-12-18**, and none ever for the four non-Core APIs. - **No first-party SDK** on npm, PyPI, RubyGems, Packagist or NuGet.