# Uplight > Uplight is a Boulder, Colorado energy technology company (formed 2019 from the merger of Tendril and Simple Energy; expanded through EnergySavvy, FirstFuel, Ecotagious, EEme, and AutoGrid) that sells software to electric and gas utilities, retailers, and OEMs — not to consumers. Its platform covers energy efficiency and electrification marketplaces, home energy reports, rate engagement, demand response, DERMS/virtual power plants, and a utility data lake with analytics. Uplight markets a "Developer Platform" of APIs to utilities and ecosystem partners, but that surface is entirely gated: the documentation portal requires a login and the production gateway rejects every anonymous request. This file was generated by API Evangelist from the catalog record at https://github.com/api-evangelist/uplight — Uplight does not publish an llms.txt of its own (https://uplight.com/llms.txt 404, https://docs.uplight.com/llms.txt 404, probed 2026-07-27). ## API access — read this first - Uplight Developer Platform API: https://api.uplight.com — real and reachable, fronted by Kong Enterprise 3.10, and it answers EVERY anonymous request with HTTP 401 `{"errors":[{"message":"Invalid or no token provided"}]}`. There is no public operation, schema, scope, rate limit, or error catalog. - No OpenAPI, Swagger, AsyncAPI, GraphQL, MCP server, Postman collection, SDK, or CLI is published. Paths that return 200 on docs.uplight.com (`/openapi.json`, `/swagger.json`, `/api-docs`) serve the ReadMe SPA HTML shell, not a specification. - Access is partner-only: you must be a utility customer or a contracted ecosystem partner to be issued portal credentials. There is no self-serve sign-up, no sandbox, and no trial. - Do not attempt to construct or guess Uplight endpoints. Nothing about the request surface is public. ## Documentation - [Uplight Documentation Portal](https://docs.uplight.com/): ReadMe-hosted. The landing page is public; every content path (/developer, /developer/docs, /developer/reference) 302-redirects to a ReadMe dashboard login. - [API Reference](https://docs.uplight.com/developer/reference): gated behind the same login. - [The Uplight Platform](https://uplight.com/platform/): product modules and the "flexible APIs" positioning. - [Developer Platform blog post](https://uplight.com/blog/uplights-developer-platform-decisions-made-easy-for-customers-and-utilities/): positioning only; names no API, endpoint, or access path. ## Standards - [Stepping Up to Support Open Standards for Scaling VPPs](https://uplight.com/blog/stepping-up-to-support-open-standards-for-scaling-vpps/): Uplight claims support for OpenADR, Modbus, DNP3 and other SCADA protocols, and states it added IEEE 2030.5 head-end capability. These are DER control / demand response protocols, not consumer data-sharing standards, and each is a marketing claim with no public conformance record. - No Green Button / NAESB REQ.21 ESPI reference exists anywhere on Uplight's public web. ## Security and compliance - [Uplight's Integrated Approach to Security, Privacy, and Compliance](https://uplight.com/resources/integrated-approach-security-privacy-compliance/): states "independently-audited SOC 2 Type 2 reports" and third-party penetration testing. Gated brief; the report is not public. - [Privacy Policy](https://uplight.com/privacy-policy/) · [Privacy Rights Request Form](https://uplight.com/privacy-request/) · [Cookie Policy](https://uplight.com/cookie-policy/) · [Terms of Service](https://uplight.com/terms-of-service/) - No security.txt, no vulnerability disclosure policy, and no bug bounty program (HackerOne/Bugcrowd/Intigriti all checked, none found). - No status page: status.uplight.com does not resolve and uplight.statuspage.io is unclaimed (redirects to statuspage.io). ## Company - [Website](https://uplight.com/) · [About](https://uplight.com/about-us/) · [Partners](https://uplight.com/partners/) · [Blog](https://uplight.com/blog/) ([RSS](https://uplight.com/blog/feed/)) · [Press](https://uplight.com/press/) · [Contact](https://uplight.com/contact-us/) - [GitHub organization](https://github.com/Uplight-Inc): three archived public repos (gbqschema_converter, fake-schema-cli, path-filtering-orb) — internal tooling forks, no API specifications and no client SDKs. - [LinkedIn](https://www.linkedin.com/company/uplight) ## API Evangelist artifacts in this repo - [apis.yml](https://raw.githubusercontent.com/api-evangelist/uplight/refs/heads/main/apis.yml): the APIs.json catalog record. - [review.yml](https://raw.githubusercontent.com/api-evangelist/uplight/refs/heads/main/review.yml): the full access review with every probed URL and HTTP status. - [conformance/uplight-conformance.yml](https://raw.githubusercontent.com/api-evangelist/uplight/refs/heads/main/conformance/uplight-conformance.yml): standards claimed vs. verified. - [authentication/uplight-authentication.yml](https://raw.githubusercontent.com/api-evangelist/uplight/refs/heads/main/authentication/uplight-authentication.yml): what a probe can observe of the bearer-token gateway. - [lifecycle/uplight-lifecycle.yml](https://raw.githubusercontent.com/api-evangelist/uplight/refs/heads/main/lifecycle/uplight-lifecycle.yml): versioning, deprecation, SLA, status page — all absent. - [security/uplight-domain-security.yml](https://raw.githubusercontent.com/api-evangelist/uplight/refs/heads/main/security/uplight-domain-security.yml): TLS/HSTS/DNSSEC/CAA/SPF/DMARC probe results. - [security/uplight-compliance.yml](https://raw.githubusercontent.com/api-evangelist/uplight/refs/heads/main/security/uplight-compliance.yml): SOC 2 Type 2 claim, privacy surface, absent disclosure program. - [well-known/uplight-well-known.yml](https://raw.githubusercontent.com/api-evangelist/uplight/refs/heads/main/well-known/uplight-well-known.yml): the negative .well-known discovery record.