This is not our API. This repository is an independent, third-party profile of a company's publicly available API surface, maintained by API Evangelist. API Evangelist does not operate, host, resell, or support this company's APIs, and is not affiliated with or endorsed by the company unless stated on the profile.
Where the information came from. Everything here is assembled from material a member of the public can reach with a browser and no credentials — the company's own website, developer portal and documentation, the specifications it publishes for public use (OpenAPI, AsyncAPI, JSON Schema,
apis.json,llms.txtand similar), its public repositories, and its public status, pricing and changelog pages. Nothing here is obtained by breaching a system, defeating an access control, or using credentials of any kind.The rating is an independent assessment. The Kin Score and Agent Readiness rating are independently calculated scores of a company's public API artifacts, produced by API Evangelist against a published rubric. They are not certifications, endorsements, security assessments, or audits, and they score published artifacts — not the quality, safety, or security of the software.
Corrections, re-scores, and removal are free. No partnership, contract, or purchase is required, and you do not need to justify the request.
- Something wrong? Open an issue on this repository, or email info@apievangelist.com.
- Published something new? Ask for a re-score and we will re-run the rating.
- Want the listing taken down? Say so and we will honor it. The profile is reduced to your company name, a factual description, and a link to your own site, and the company is recorded as unrated — never scored zero for having asked.
Response times. Acknowledgement within one business day; removal or restriction within two business days; corrections and re-scores within five business days.
On a security or compliance team? Email info@apievangelist.com with security in the subject line and you will get a person, not a form. We will tell you exactly which public URLs this profile was built from so your team can see the same surface we did, and we will take the listing down on request while you work through it.
Full detail: Where this data comes from
Centrica plc is the FTSE-listed British energy and services group behind British Gas, the United Kingdom's largest household energy supplier, along with Bord Gais Energy in Ireland, Centrica Business Solutions, Centrica Energy (its wholesale power, gas and LNG trading arm) and the Hive connected-home brand. It sits across the whole value chain — upstream gas and storage at Rough, generation and battery flexibility, wholesale trading and route-to-market, retail supply to roughly ten million UK homes, and a field-service engineering business — after exiting North America with the sale of Direct Energy to NRG in January 2021 to refocus on the UK and Ireland. Its API posture is honestly closed: Britain mandated the smart-metering INFRASTRUCTURE (the licensed Smart DCC monopoly and the SMETS2 rollout) rather than a consumer data right, so Centrica has no Consumer Data Right, no Green Button and no standards-conformant consumer usage endpoint. The DESNZ non-domestic smart meter data access requirement that does bind it is discharged by a written request answered within ten working days, not by an API. Household consumers reach their own data only through the British Gas app and account login; business customers through the Energy360 DataView portal. The single publicly reachable developer surface found is the Centrica FieldOps Azure API Management developer portal — a partner field-operations platform in its development environment — and Centrica publishes no open grid or market data of its own, leaving that to NESO, Elexon and the DNOs.
APIs.json: https://raw.githubusercontent.com/api-evangelist/centrica/refs/heads/main/apis.yml
- Energy
- United Kingdom
- Utilities
- Electricity
- Gas
- Smart Metering
- Energy Retail
- Energy Markets
- Ireland
- Field Service
- Created: 2026-07-27
- Modified: 2026-07-27
Token-issuing API on the Centrica FieldOps API Management platform, published on Centrica's Azure API Management developer portal. A single POST /oauth2/token operation exchanges an OAuth2 client_credentials grant (client_id + client_secret, form-encoded) for a bearer access token used against the FieldOps WorkOrder, Opportunity and Appointment Slots APIs. Harvested verbatim from the portal's development environment on 2026-07-27; the production hosts api.fieldops.centrica.com and api-developer.fieldops.centrica.com both answer 403 anonymously. Calls also carry an Azure APIM subscription key (Ocp-Apim-Subscription-Key header or subscription-key query parameter).
- Human URL: https://api-developer.dev.fieldops.centrica.com/api-details#api=identity-api
- Base URL:
https://api.dev.fieldops.centrica.com/api/v1/identity
- Identity
- OAuth2
- Field Service
- Partner
| Dimension | Finding |
|---|---|
| Home market | United Kingdom (plus Republic of Ireland via Bord Gais Energy) |
| Mandate regime | smart-meter-infrastructure — Smart DCC / SMETS2, a licensed infrastructure monopoly, not a consumer data right |
| Mandate status | designated-not-live — the DESNZ non-domestic data-access obligation is in force (1 Dec 2022 on request, 1 Oct 2024 default offer) but is discharged by a written request answered within ten working days, with no API |
| Data standard | No standard reference found — no Green Button/ESPI, no CDR Consumer Data Standards, no IEEE 2030.5, no OpenADR, no OCPP/OCPI, no IEC CIM |
| Consumer data API | No — British Gas app / account login for households, Energy360 DataView login for business |
| Open market data | No — Centrica publishes none; NESO, Elexon and the DNOs publish the open UK energy data |
| Access gate | partner-only — the FieldOps portal offers self-serve sign-up in its development environment, but production hosts answer 403 and the WorkOrder / Opportunity / Appointment Slots APIs are invisible anonymously |
| Auth model | OAuth2 client_credentials bearer tokens layered under Azure APIM subscription keys |
See review.yml for every URL probed, its HTTP status, and the full mandate-versus-implementation record.
Produced by the API Evangelist enrichment pipeline on 2026-07-27. Where a thing genuinely does not exist, the artifact records the absence with the probes that established it — that negative evidence is the point for a provider this closed.
| Artifact | File | Method | Finding |
|---|---|---|---|
| OpenAPI | openapi/ | searched | One operation, exported verbatim from Centrica's own Azure APIM instance |
| Overlay | overlays/ | generated | Our enhancements and the spec's gaps; the harvest is never mutated |
| Well-known | well-known/ | searched | 5 hosts probed, 3 documents found |
| security.txt | well-known/ | searched | On britishgas.co.uk; no Contact or Expires field, so RFC 9116 partial |
| OIDC discovery | well-known/ | searched | Real discovery doc on centrica.com — Umbraco CMS member auth, not a developer API |
| Authentication | authentication/ | derived | APIM subscription key in header and query |
| Conventions | conventions/ | derived | No idempotency, no pagination, no request-id, no error envelope |
| Conformance | conformance/ | derived | OpenAPI/OAuth2/OIDC/JWKS/PKCE yes; every energy data standard no |
| Lifecycle | lifecycle/ | searched | URI-path v1; no deprecation policy, no changelog, no status page |
| Plans | plans/ | searched | The two stock APIM products, unpriced |
| Rate limits | rate-limits/ | searched | 5 calls/min, 100 calls/week on Starter; unlimited on approval |
| Sandbox | sandbox/ | searched | No curated sandbox — an internal DEV environment left publicly reachable |
| Packages | packages/ | searched | Zero first-party SDKs across eight registries and both GitHub orgs |
| Data model | data-model/ | derived | One entity; WorkOrder, Opportunity and AppointmentSlot named but unpublished |
| MCP | mcp/ | derived | No server. Centrica's own APIM record reports isAgent: false, mcpProperties: null |
| Agent skill | skills/ | generated | One skill on the one real operationId |
| llms.txt | llms/ | generated | Centrica publishes none; /llms.txt is 404 on every host |
| Domain security | security/ | probed | TLS 1.3 + HSTS; DMARC p=reject on all four brand domains; no CAA, no DNSSEC |
| Vulnerability disclosure | security/ | searched | British Gas responsible-disclosure policy; no bug bounty |
Not emitted, because the underlying thing does not exist: AsyncAPI/Webhooks, ChangeLog, CLI, Components, ErrorCatalog, DeclineCodes, OAuthScopes, GraphQL, Protobuf, ToolCrosswalk, StatusPage, Deprecation, Compliance, TrustCenter, Postman.
- Kin Lane — kin@apievangelist.com