Move along, nothing...
 
Notifications
Clear all

Move along, nothing to see here....

18 Posts
9 Users
10 Reactions
2,427 Views
Majordennisbloodnok
(@majordennisbloodnok)
Noble Member Moderator
7259 kWhs
Joined: 3 years ago
Posts: 745
 

Posted by: @derek-m

Posted by: @mjr

Posted by: @majordennisbloodnok
The API already provides the functionality to set up new account

Only for partner organisations, who Octopus should be tracking more closely and have tighter contracts with.

At the moment, risk is low, but it may not always be so (it seems likely DD adjustments and credit balance refund requests could be added in future), so sharing API keys is a bad idea.

To the uninitiated, please explain API keys.

 

By all means.

In order to make data available to third parties, a company may well provide what is known as an API (Application Programming Interface). It's a rather specialised kind of web site where the person doing the querying uses an address ( https://something.com) that relates to the kind of data he or she is trying to access. As such, https://api.octopus.energy/v1/electricity-meter-points/ will give you electricity meter point information whereas https://api.octopus.energy/v1/products/ will give you data about Octopus' products or tariffs. What the query actually answers pack with is in a predefined format meaning the developer's application knows how to separate it all out into different bits of data that can be put into a database or otherwise used.

All this is really useful for exchanging data between systems without human intervention, but is generally important enough to lock down with some security. In the case of Octopus this is done less with a username and password and more with a key; a string of text only you and they know and which identifies you to them. As a result, if I wanted to examine my meter's consumption then I would need my mpan and Octopus account number to get the right data, but I'd also need to tell the API my key so it knows I'm authorised and allowed to query the data for that meter. If I tried to query my neighbour's meter, Octopus would tell me to go travel because my key doesn't allow me to query someone else's meter consumption and quite rightly so.

 

105 m2 bungalow in South East England
Mitsubishi Ecodan 8.5 kW air source heat pump
18 x 360W solar panels
1 x 6 kW GroWatt battery and SPH5000 inverter
1 x Myenergi Zappi
1 x VW ID3
Raised beds for home-grown veg and chickens for eggs

"Semper in excretia; suus solum profundum variat"


   
👍
1
ReplyQuote
(@marvinator80)
Honorable Member Member
1415 kWhs
Joined: 2 years ago
Posts: 197
 

@mjr my Scottish government grant didn’t require a heat metre or room temp monitors and we get £9k rather than £5k. We do have monitors in the downstairs rooms in the form of the underfloor heating control panels. Upstairs now we just have the Hive control in the main hall. 

My 9 year old son just complained about the heating saying it’s now “too hot”. 😆

just because I’ve  been blasting the radiators to get the glycol through them and make sure they are all working I think. It’s 21 degrees upstairs just now and I do much prefer 19-20 but my wife prefers it hotter. Do heat pumps have a solution for that?!? 😆

think I’ll try 20.5!


   
ReplyQuote
(@scrchngwsl)
Reputable Member Member
1519 kWhs
Joined: 2 years ago
Posts: 91
 

Posted by: @majordennisbloodnok

Posted by: @keefsloan

I feel like I've finally been given official permission to now tell my friends about my tracking spreadsheets, constant tweaking of the WC curve, MELcloud, multiple room thermometers and the Octopus Compare app.

Sorry to be something of a curmudgeon but I've just looked at the Octopus Compare app and it worries me. In order to use it, you are asked for your Octopus API key and your account number, both of which are privileged information; Octopus even go so far as to state multiple times on various parts of their web site that you should never share your API key.

If someone offered a great financial app and asked you to "just" provide your bank account details and online banking username/password in order for the app to do its stuff, I like to hope your answer to them would be a "no" with an "off" in it. Nonetheless, that's exactly what the Octopus Compare app is asking for in relation to your Octopus account. I'm happy to admit the damage someone could do right now with that API access is markedly less than if they had access to your bank account but that may not always be so. The API already provides the functionality to set up new accounts, and Octopus won't let you know in advance if and when they add the functionality to query account details. Do you trust the developers of Octopus Compare with (potentially) visibility of your personal account details? Even now, are you happy they could query your meter's consumption history and build up a picture of when you're likely at home or away?

Realistically, the chances you're running a significant risk by using Octopus Compare are probably low. However, that is only a "probably" and even if it's correct then there's no guarantee it will stay a low risk. I would urge you to stop using the app, go to your Octopus account page and regenerate your API key.

 

Agreed - absolutely no way I'd give some random company the API key for my energy provider. Very suspicious!

 

ASHP: Mitsubishi Ecodan 8.5kW
PV: 5.2kWp
Battery: 8.2kWh


   
ReplyQuote



(@derek-m)
Illustrious Member Member
15283 kWhs
Veteran Expert
Joined: 4 years ago
Posts: 4429
 

Posted by: @marvinator80

@mjr my Scottish government grant didn’t require a heat metre or room temp monitors and we get £9k rather than £5k. We do have monitors in the downstairs rooms in the form of the underfloor heating control panels. Upstairs now we just have the Hive control in the main hall. 

My 9 year old son just complained about the heating saying it’s now “too hot”. 😆

just because I’ve  been blasting the radiators to get the glycol through them and make sure they are all working I think. It’s 21 degrees upstairs just now and I do much prefer 19-20 but my wife prefers it hotter. Do heat pumps have a solution for that?!? 😆

think I’ll try 20.5!

You will need to play the 'Son' card, just tell your wife that her 'beloved' is too hot and she won't complain and soon get used to the lower temperature. 😀 

Unfortunately all our 'beloveds' have flown the nest, so now I have to convince my wife the her 'beloved' cat is complaining that it is too hot. 😋 

 


   
ReplyQuote
(@marvinator80)
Honorable Member Member
1415 kWhs
Joined: 2 years ago
Posts: 197
 

@derek-m yes, great idea. Her little Prince has been complaining, will try that one!


   
ReplyQuote
Majordennisbloodnok
(@majordennisbloodnok)
Noble Member Moderator
7259 kWhs
Joined: 3 years ago
Posts: 745
 

Posted by: @mjr

Posted by: @majordennisbloodnok
The API already provides the functionality to set up new account

Only for partner organisations, who Octopus should be tracking more closely and have tighter contracts with.

Agreed. My point is that the interface already interacts with account data, and Octopus won’t inform all customers of every slight change in functionality. I don’t say any API access is total access, but the extent it could be exploited if put in the wrong hands is not immediately apparent.

Posted by: @mjr

At the moment, risk is low, but it may not always be so (it seems likely DD adjustments and credit balance refund requests could be added in future), so sharing API keys is a bad idea.

Thank you. I wasn’t aware of those plans but as you say that rather ups the ante if one’s personal key was made public.

 

105 m2 bungalow in South East England
Mitsubishi Ecodan 8.5 kW air source heat pump
18 x 360W solar panels
1 x 6 kW GroWatt battery and SPH5000 inverter
1 x Myenergi Zappi
1 x VW ID3
Raised beds for home-grown veg and chickens for eggs

"Semper in excretia; suus solum profundum variat"


   
ReplyQuote
Page 2 / 2
Share:

Join Us!

Heat Pump Dramas?

Thinking about installing a heat pump but unsure where to start? Already have one but it’s not performing as expected? Or are you locked in a frustrating dispute with an installer or manufacturer? We’re here to help.

Pre-Installation Planning
Post-Installation Troubleshooting
Performance Optimisation
✅ Complaint Support (Manufacturer & Installer)

👉 Book a one-to-one consultation now.

Latest Posts

x  Powerful Protection for WordPress, from Shield Security
This Site Is Protected By
Shield Security