# Red Energy > Red Energy Pty Ltd (ABN 60 107 479 372) is an Australian electricity and gas retailer, wholly owned by Snowy Hydro Ltd, serving more than a million residential and business customers across NSW, VIC, QLD, SA and the ACT. It publishes no developer portal and no proprietary API. Everything machine-readable about Red Energy exists because Part IVD of the Competition and Consumer Act 2010 compelled it: Red Energy is a designated Consumer Data Right (CDR) energy data holder, listed on the CDR Register, implementing the Treasury Data Standards Body's Consumer Data Standards v1.36.0. GENERATED, not published by Red Energy. This file was generated by API Evangelist on 2026-07-27 from apis.yml and the artifacts in this repository. No /llms.txt exists on any Red Energy host — probes of www.redenergy.com.au (HTTP 403, Cloudflare), public.cdr.redenergy.com.au (404) and cdr.energymadeeasy.gov.au (404) all missed. ## The split that defines this provider There are exactly two access modes and nothing in between. - **Open and anonymous.** 1,705 Red Energy tariff plans, callable by anyone with no key, no signup and no accreditation — plus Red Energy's own CDR health and outage endpoints. - **Accredited only.** Every fact about an actual Red Energy customer — accounts, usage, billing, invoices, concessions, payment schedules, distributed energy resources — reachable only by an ACCC-accredited CDR data recipient, over mutual TLS with FAPI 1.0 Advanced OAuth2/OIDC, after that individual customer consents. ## APIs - [Red Energy CDR Energy Product Reference Data API](https://consumerdatastandardsaustralia.github.io/standards/#energy-apis): 1,705 electricity and gas plans. `GET https://cdr.energymadeeasy.gov.au/red-energy/cds-au/v1/energy/plans` with header `x-v: 1`. Served centrally by the Australian Energy Regulator's Energy Made Easy CDR host under the Red Energy brand path, not by Red Energy. Confirmed HTTP 200 on 2026-07-27. - [Red Energy CDR Discovery API](https://consumerdatastandardsaustralia.github.io/standards/#common-apis): `GET https://public.cdr.redenergy.com.au/cds-au/v1/discovery/status` and `/discovery/outages` with header `x-v: 1`. Red Energy's own registered CDR public base URI — the only API surface on a Red-Energy-controlled domain. Confirmed HTTP 200 on 2026-07-27. - [Red Energy CDR Energy Consumer Data API](https://consumerdatastandardsaustralia.github.io/standards/#energy-apis): the consumer-authorised half. Real and mandated; no public base URL, because the infosec base URI is published only through the authenticated portion of the CDR Register. ## Specs - [CDR Energy API 1.36.0](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/openapi/red-energy-cds-energy-openapi.yml): OpenAPI 3.0.3, 23 operations, 133 schemas. DSB standard, harvested verbatim. - [CDR Common API 1.36.0](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/openapi/red-energy-cds-common-openapi.yml): OpenAPI 3.0.3, 4 operations, 27 schemas. DSB standard, harvested verbatim. - [CDR Energy overlay](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/overlays/red-energy-cds-energy-overlay.yaml): OpenAPI Overlay 1.0.0 recording the real hosts, the anonymous/accredited split and the verified behaviour. - [CDR Common overlay](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/overlays/red-energy-cds-common-overlay.yaml) ## Getting started (no credential required) 1. `GET https://public.cdr.redenergy.com.au/cds-au/v1/discovery/status` with `x-v: 1` to check availability. 2. `GET https://cdr.energymadeeasy.gov.au/red-energy/cds-au/v1/energy/plans?page-size=25` with `x-v: 1` to list plans. 3. `GET https://cdr.energymadeeasy.gov.au/red-energy/cds-au/v1/energy/plans/{planId}` with `x-v: 3` for full tariff detail. The `x-v` header is mandatory on every endpoint. Omit it and you get HTTP 400 `urn:au-cds:error:cds-all:Header/Missing`. Ask for a version that is too high and you get HTTP 406 `urn:au-cds:error:cds-all:Header/UnsupportedVersion`. Different endpoints are on different version trains — plans is version 1, plan detail is version 3. ## Artifacts - [Authentication](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/authentication/red-energy-authentication.yml): none on the public half; FAPI 1.0 Advanced OAuth2/OIDC over mTLS with `private_key_jwt` and certificate-bound tokens on the consumer half. - [OAuth scopes](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/scopes/red-energy-scopes.yml): 11 CDR authorisation scopes with their consumer-facing data-language equivalents. - [Conventions](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/conventions/red-energy-conventions.yml): `x-v` version negotiation, offset pagination, `x-fapi-interaction-id` tracing, the CDS error envelope. No idempotency contract — the surface is read-only. - [Error catalogue](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/errors/red-energy-problem-types.yml): the full `urn:au-cds:error:...` registry; three codes observed live. - [Lifecycle](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/lifecycle/red-energy-lifecycle.yml): per-endpoint versioning, the Endpoint Version Schedule as deprecation policy, a 99.5% monthly availability obligation and per-tier latency thresholds. - [Rate limits](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/rate-limits/red-energy-rate-limits.yml): CDS traffic thresholds, including a 300 TPS public ceiling and 10-calls-per-24-hours velocity limits on NMI, usage and DER data. - [Conformance](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/conformance/red-energy-conformance.yml): what is behaviourally verified versus statutorily asserted. - [Changelog](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/changelog/red-energy-changelog.yml): the DSB standards changelog that governs this contract. - [Data model](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/data-model/red-energy-data-model.yml): the entity graph derived from the specs. - [Agentic access](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/agentic-access/red-energy-agentic-access.yml): all 27 operations classified connected/read — nothing on this API mutates anything. - [Examples](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/examples/): seven request/response pairs captured live on 2026-07-27, including the 400, 404 and 406 error shapes. - [Agent skills](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/skills/_index.yml): three packaged skills grounded in verified operationIds. - [Domain security](https://raw.githubusercontent.com/api-evangelist/red-energy/refs/heads/main/security/red-energy-domain-security.yml): TLS, HSTS, DNSSEC, SPF and DMARC probe results. ## Standards - [Consumer Data Standards (Australia) v1.36.0](https://consumerdatastandardsaustralia.github.io/standards/) - [CDS Security Profile](https://consumerdatastandardsaustralia.github.io/standards/#security-profile) - [CDS Authorisation Scopes](https://consumerdatastandardsaustralia.github.io/standards/#authorisation-scopes) - [CDS Error Codes](https://consumerdatastandardsaustralia.github.io/standards/#error-codes) - [CDS Non-functional Requirements](https://consumerdatastandardsaustralia.github.io/standards/#non-functional-requirements) - [CDR Register — energy data holder brands](https://api.cdr.gov.au/cdr-register/v1/energy/data-holders/brands/summary) ## Not available - No developer portal. `developer.`, `developers.`, `api.`, `docs.` and `data.` subdomains of redenergy.com.au do not resolve in DNS. - No `/llms.txt`, no `/openapi.json`, no `/.well-known/` document on any host. - No first-party SDK in any package registry, no CLI, no embedded components, no Postman collection. - No webhooks, no event stream, no AsyncAPI. The CDR data holder surface is request/response only. - No sandbox published by Red Energy. Testing tooling exists at the ecosystem level from the Data Standards Body and the ACCC. - No MCP server. A candidate tool list derived from the specs is at `mcp/red-energy-mcp.yml`. - `www.redenergy.com.au` returns HTTP 403 with a Cloudflare bot challenge to every programmatic client, including its own CDR policy PDF.