# Xylem > Xylem Inc. (NYSE: XYL) is a global water technology company that moves, treats, > analyzes, monitors and returns water to the environment. Its brands include Sensus > (smart water, gas and electric metering and AMI networks), Xylem Vue (utility > operations software, built with Idrica's GoAigua platform), YSI (water quality > instrumentation), HYPACK (hydrographic survey software), Flygt, Godwin, WEDECO and > Aanderaa. This file was generated by API Evangelist from an independent third-party > profile of Xylem's PUBLIC surface; Xylem does not publish an llms.txt of its own > (https://www.xylem.com/llms.txt returns HTTP 404). ## What an agent can and cannot do with Xylem today Xylem operates real, live, first-party API hosts. It publishes no API contract for any of them. As of 2026-09-04 there is no OpenAPI, Swagger, GraphQL SDL, AsyncAPI, gRPC proto, WSDL, MCP server or A2A agent card served anywhere on a Xylem host, and no developer portal, API reference, quickstart, SDK, CLI or Postman collection exists. Every API host that answers does so with an authentication challenge. An agent cannot call Xylem without a customer relationship, and cannot learn the shape of the call at all. - [Xylem](https://www.xylem.com/en-us/): company site and product catalogue. - [Software products](https://www.xylem.com/en-us/products--services/software/): the named software surface — quote-only, no prices, no developer access. ## The one machine-readable document Xylem publishes - [Xylem Cloud OpenID Connect discovery](https://cloud.xylem.com/xcloud/auth/realms/xcloud/.well-known/openid-configuration): HTTP 200, application/json. A Keycloak realm ("xcloud") on Xylem's own domain. It advertises the authorization code, client credentials, device code, JWT bearer, token exchange, UMA ticket and CIBA grants; PKCE (S256), PAR, JARM, DPoP and mutual-TLS certificate-bound access tokens; and 14 scopes including two Xylem-defined ones, `service_account` and `api:customer`. This is the only Xylem document from which a machine can learn anything precise about how to authenticate. ## Live Xylem API hosts (all authentication-gated, none documented) - `https://cloud.xylem.com/xcloud/v1/` — Xylem Cloud platform API. HTTP 401, `{"errorCode":"UNAUTHORIZED_ERROR", ... "message":"Missing authentication header"}`. The sign-in page names `https://cloud.xylem.com/xcloud/v1/users/` as a real endpoint. - `https://selector-beta-api.xylem.com/` — Xylem product selector API behind a gateway. HTTP 401, `{"message":"No client found attached to request","code":"invalid_req_client"}`. - `https://ae-api-view.xylem.com/`, `https://data-api-view.xylem.com/`, `https://gis-api-view.xylem.com/`, `https://ums-api.view.xylem.com/` — Xylem Vue microservices (Explorer, vStream Get Data, GIS, user management). Each returns a bare "…is running (welcome page)" banner and 404s every spec path probed. - `https://.sensus-analytics.com/` — Sensus Analytics, deployed per utility tenant. Portal login only; no API is documented. ## Security and trust (Xylem's strongest published surface) - [Cybersecurity](https://www.xylem.com/en-us/about/cybersecurity/): programme overview; NIST CSF, ISO 27001 and SOC 2 Type II are named as guiding frameworks. - [Incident response and coordinated vulnerability disclosure](https://www.xylem.com/en-us/about/cybersecurity/incident-response/): a real CVD policy run by a Xylem PSIRT, aligned to the EU Cyber Resilience Act. Xylem is an approved CVE Numbering Authority for its own products. - [Report a vulnerability](https://www.xylem.com/en-us/about/cybersecurity/contact/): security@xylem.com or product.security@xylem.com; PGP key published. - [Security advisories](https://www.xylem.com/en-us/about/cybersecurity/security-advisories/): 17 numbered advisories, XPSA-2019-001 through XPSA-2024-015. No RSS, Atom, CSAF or VEX feed. - [Trust center](https://trust.xylem.com/): SafeBase portal; ISO 27001 certified. ## Company and legal - [Terms and conditions](https://www.xylem.com/en-us/support/terms-and-conditions/) - [Privacy statement](https://www.xylem.com/en-us/resources/policies/privacy/) - [Contact us](https://www.xylem.com/en-us/contact-us/) - [Making Waves blog](https://www.xylem.com/en-us/resources/blogs/making-waves/) - [Newsroom](https://www.xylem.com/en-us/about-xylem/newsroom/) - [Investors](https://www.xylem.com/en-us/investors/) - [Xylem NOC status](https://status.xylem.com/) — exists, but login-gated. ## Optional - Probed and absent on 2026-09-04, recorded so an agent does not retry them: `/openapi.json`, `/swagger.json`, `/swagger/v1/swagger.json`, `/v3/api-docs`, `/v2/api-docs`, `/api-docs`, `/docs`, `/redoc` on cloud.xylem.com, apis.xylem.com, ae-api-view.xylem.com, data-api-view.xylem.com, gis-api-view.xylem.com and selector-beta-api.xylem.com — all 401 or 404. `/.well-known/agent-card.json`, `/.well-known/agent.json`, `/.well-known/api-catalog`, `/.well-known/ai-plugin.json`, `/.well-known/security.txt` and `/llms.txt` on xylem.com, www.xylem.com, cloud.xylem.com and apis.xylem.com — all 403 or 404. The one security.txt reachable under a Xylem hostname (status.xylem.com) is Atlassian's, not Xylem's. - `https://apis.xylem.com/` resolves and returns HTTP 200, but it is an internal ASP.NET application titled "Apis Manager" — not an API catalogue and not a developer portal. - `https://github.com/Xylem` is an unrelated private individual's account, not Xylem Inc. `https://github.com/xyleminc` exists but publishes no repositories. Generated: 2026-09-04. Method: generated, from probes and searches recorded in this repository (well-known/, authentication/, scopes/, conformance/, errors/, security/, lifecycle/, packages/, plans/, rate-limits/, conventions/).