# Origin Energy — API surface > Origin Energy Limited is Australia's largest energy retailer, an ASX-listed integrated gas and > electricity company supplying roughly 4.5 million customer accounts. Its API posture is defined by > regulation rather than by a developer strategy: it is a designated energy data holder under > Australia's Consumer Data Right, and it runs its retail business on Octopus Energy's Kraken > platform. There is no self-serve developer signup on any Origin or Kraken host. > > This file is generated by API Evangelist from verified probes, not from marketing copy. Origin also > publishes its own site-wide llms.txt at https://www.originenergy.com.au/llms.txt (a Rank Math SEO > index of marketing pages, saved verbatim alongside this file); it contains nothing about the APIs. ## Access at a glance - Anonymous, no credentials: retail plan reference data at the AER Energy Made Easy CDR gateway, and the CDR discovery status/outages endpoints on Origin's public CDR base URI. - Accredited only: every byte of consumer usage, billing and DER data, behind mutual TLS with an ACCC CDR Certificate Authority client certificate plus consumer consent. - Partner/customer only: the Kraken GraphQL and REST APIs, behind an OpenID Connect bearer token that Origin provisions out of band. ## APIs - [Origin Energy CDR Energy API](https://consumerdatastandardsaustralia.github.io/standards/#energy-apis): Consumer Data Right resource endpoint at https://api.mydata.cdr.originenergy.com.au — mutual TLS, accredited data recipients only. - [Origin Energy CDR Public Discovery API](https://consumerdatastandardsaustralia.github.io/standards/#discovery-apis): anonymous status and outages at https://public.mydata.cdr.originenergy.com.au/cds-au/v1. - [Origin Energy Plan Reference Data](https://www.energymadeeasy.gov.au/): 3,595 electricity and gas plans, anonymous, at https://cdr.energymadeeasy.gov.au/origin/cds-au/v1. - [Origin Energy Kraken GraphQL API](https://developer.origin-kraken.energy/graphql/): https://api.origin-kraken.energy/v1/graphql/ — 187 queries, 374 mutations, 2,407 types. Introspection is open; data requires a bearer token. - [Origin Energy Kraken REST API](https://developer.origin-kraken.energy/rest/): https://api.origin-kraken.energy/v1/ — 27 operations across three namespaces (default, data-import, orders). - [Origin Energy Kraken External Events](https://developer.origin-kraken.energy/events/): 440+ versioned event types emitted to AWS EventBridge. - [Origin Energy Kraken Authorization Server](https://auth.origin-kraken.energy/.well-known/openid-configuration): OpenID Connect, 113 scopes, no dynamic client registration. ## Specs - [Kraken REST (default)](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/openapi/origin-energy-kraken-default-openapi.yml): OpenAPI 3.0.3, harvested from https://api.origin-kraken.energy/v1/schema - [Kraken REST (data import)](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/openapi/origin-energy-kraken-data-import-openapi.yml): OpenAPI 3.0.3, harvested from https://api.origin-kraken.energy/data-import/schema/ - [Kraken REST (orders)](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/openapi/origin-energy-kraken-orders-openapi.yml): OpenAPI 3.0.3, harvested from https://api.origin-kraken.energy/v2/orders/schema/ - [Kraken GraphQL SDL](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/graphql/origin-energy-kraken.graphql): harvested by anonymous introspection on 2026-07-27 - [CDR Energy API](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/openapi/consumer-data-standards-energy-api-openapi.json): OpenAPI 3.0.3 v1.36.0 — published by the Data Standards Body, not by Origin - [CDR Common API](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/openapi/consumer-data-standards-common-api-openapi.json): OpenAPI 3.0.3 v1.36.0 — published by the Data Standards Body, not by Origin ## Artifacts - [Authentication](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/authentication/origin-energy-authentication.yml): four surfaces, three auth models, no self-serve path - [OAuth scopes](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/scopes/origin-energy-scopes.yml): 113 Kraken scopes from the OIDC discovery document - [Conventions](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/conventions/origin-energy-conventions.yml): idempotency, pagination, tracing, versioning per surface - [Rate limits](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/rate-limits/origin-energy-rate-limits.yml): complexity 550, 100,000 nodes, hourly points allowances - [Error codes](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/errors/origin-energy-error-codes.yml): 878 Kraken KT-XX-NNNNN codes with messages - [Error envelopes](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/errors/origin-energy-problem-types.yml): three distinct error shapes, none RFC 9457 - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/lifecycle/origin-energy-lifecycle.yml): versioning, deprecation policy, status endpoint - [Changelog](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/changelog/origin-energy-changelog.yml): dated GraphQL changelog and announcements - [External events](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/asyncapi/origin-energy-kraken-external-events.yml): the event catalogue - [Tool crosswalk](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/mcp/origin-energy-tool-crosswalk.yml): GraphQL vs REST vs CDR divergence - [Data model](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/data-model/origin-energy-data-model.yml): CDR model and Kraken model - [Conformance](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/conformance/origin-energy-conformance.yml): what the surfaces do and do not conform to - [Domain security](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/security/origin-energy-domain-security.yml) - [Vulnerability disclosure](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/security/origin-energy-vulnerability-disclosure.yml): Bugcrowd VDP - [security.txt](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/well-known/origin-energy-security.txt) - [Agent skills](https://raw.githubusercontent.com/api-evangelist/origin-energy/refs/heads/main/skills/_index.yml): five packaged flows grounded in verified operation names ## Docs - [Kraken developer portal](https://developer.origin-kraken.energy/) - [GraphQL guides](https://developer.origin-kraken.energy/graphql/guides/basics/) - [REST guides](https://developer.origin-kraken.energy/rest/guides/api-basics/) - [Error codes reference](https://developer.origin-kraken.energy/graphql/reference/error-codes/) - [API announcements](https://developer.origin-kraken.energy/announcements/) - [Consumer Data Standards](https://consumerdatastandardsaustralia.github.io/standards/) - [CDR accreditation](https://www.cdr.gov.au/for-providers/accreditation) - [Origin CDR help](https://www.originenergy.com.au/help-support/account-management/consumer-data-right-cdr/consumer-data-right-cdr) ## Not available - No MCP server on any Origin or Kraken host (mcp.origin-kraken.energy does not resolve; /mcp returns 404). - No first-party SDK or client library in any public package registry. - No CLI, no Postman collection, no embeddable UI components. - No AsyncAPI document — the external-events schema endpoint returns HTTP 403 anonymously. - No sandbox, no test credentials, no self-serve signup. - No trust centre or published certification program. - No open grid, market, generation or system data — that is AEMO's, not Origin's.