Perseus · Carbon Accounting Provider
Perseus readiness
Each step below is checked live against the Perseus sandbox for the FSP-initiated with one permission flow. Steps marked Your turn need you to act as the SME customer.
Setup
- ✓
We are listed in the Directory
DoneOur organisation is a member of the Perseus scheme with the Carbon Accounting Provider role.
3 of 3 checks passed
- ✓Directory returns our member recordhttps://directory.core.sandbox.trust.ib1.org/m/4tnapijm
- ✓Record has a legal nameCarbon Accounting Provider (sandbox)
- ✓Organisation holds the Carbon Accounting Provider rolehttps://registry.core.sandbox.trust.ib1.org/scheme/perseus/role/carbon-accounting-provider
- iMembership expiry is not in the public Directory APIIt is shown on the Directory web page and in the authenticated members API
- Legal name
- Carbon Accounting Provider (sandbox)
- ✓
- ✓
We have registered this application
DoneThis app is registered in the Directory under our organisation, claiming the CAP role.
3 of 3 checks passed
- ✓Directory returns our applicationhttps://directory.core.sandbox.trust.ib1.org/a/ciro1gll
- ✓Application is published by our organisationhttps://directory.core.sandbox.trust.ib1.org/m/4tnapijm
- ✓Application claims the Carbon Accounting Provider rolehttps://registry.core.sandbox.trust.ib1.org/scheme/perseus/role/carbon-accounting-provider
- Application ID
- https://directory.core.sandbox.trust.ib1.org/a/ciro1gll
- Title
- Perseus Readiness Demo
- ✓
- ✓
We hold Directory-issued certificates
DoneA client certificate for mTLS with other members, and a signing certificate for provenance records.
12 of 12 checks passed
- ✓Client certificate chains to the Trust Framework rootC=GB, O=Core Trust Framework, CN=Core (sandbox) Trust Framework client issuer
- ✓Client certificate is in date2026-09-21 to 2027-09-21
- ✓Client certificate matches our private key
- ✓Client certificate names this applicationhttps://directory.core.sandbox.trust.ib1.org/a/ciro1gll
- ✓Client certificate names our organisationhttps://directory.core.sandbox.trust.ib1.org/m/4tnapijm
- ✓Client certificate carries the CAP rolehttps://registry.core.sandbox.trust.ib1.org/scheme/perseus/role/carbon-accounting-provider
- ✓Signing certificate chains to the Trust Framework rootC=GB, O=Core Trust Framework, CN=Core (sandbox) Trust Framework signing issuer
- ✓Signing certificate is in date2026-09-21 to 2027-09-21
- ✓Signing certificate matches our private key
- ✓Signing certificate names this applicationhttps://directory.core.sandbox.trust.ib1.org/a/ciro1gll
- ✓Signing certificate names our organisationhttps://directory.core.sandbox.trust.ib1.org/m/4tnapijm
- ✓Signing certificate carries the CAP rolehttps://registry.core.sandbox.trust.ib1.org/scheme/perseus/role/carbon-accounting-provider
- Client certificate
- /tmp/perseus/certs/client/cert.pem
- Signing certificate
- /tmp/perseus/certs/signing/cert.pem
- ✓
- ✓
We can discover the Energy Data Provider
DoneThe EDP is found through the Directory catalogue, and its authorisation server supports the Perseus FAPI 2 profile.
7 of 7 checks passed
- ✓Directory catalogue lists an API conforming to the energy consumption data standardEDP Sandbox synthetic data
- ✓Our chosen EDP API is in the catalogue: EDP Sandbox synthetic dataconformsTo https://registry.core.sandbox.trust.ib1.org/scheme/perseus/standard/energy-consumption-data/2026-03-12
- ✓EDP is a Directory member with the Energy Data Provider role: Energy Data Provider (sandbox)https://directory.core.sandbox.trust.ib1.org/m/7a1qv915
- ✓Authorisation server requires Pushed Authorization Requests (RFC 9126)https://mtls.perseus-demo-authentication.ib1.org/api/v1/par
- ✓Clients authenticate with mTLS certificates (tls_client_auth)
- ✓PKCE with S256 is supported
- ✓Authorisation code flow is supported
- iMetadata issuer differs from the catalogue oauthIssuerMetadata says https://mtls.perseus-demo-authentication.ib1.org; we will expect that value in the authorisation response iss parameter
- iDirectory server allowlist is empty for Perseus, so it cannot be enforced yet
- Authorisation server metadata
- https://perseus-demo-authentication.ib1.org/.well-known/oauth-authorization-server
- ✓
User journey
- 5
User arrives from the FSP start link
Your turnThe FSP sends the SME to our landing page with its Directory ID; we keep it to preselect the FSP.
In production the FSP sends the SME a link to this page carrying the FSP’s Directory ID, e.g.
Follow a start link from Financial Service Provider 1 (sandbox)/?fsp=https://directory…/m/<id>. - 6
User signs in
Your turnThe SME creates an account or logs in. The FSP is saved to their account for future sessions.
- 7
User grants the Perseus permission
Not startedWe show the Registry permission text naming the EDP, us and the FSP, and log evidence of the consent.
- 8
User authorises us at the EDP
Not startedPushed Authorization Request over mTLS, then the SME confirms at the EDP and we exchange the code for tokens.
- 9
EDP confirms the permission
Not startedWe ask the EDP for its record of the permission, using our refresh token over mTLS.
- 10
We retrieve half-hourly consumption data
Not startedTwelve complete months of readings for each meter from the EDP, over mTLS with the access token.
- 11
We retrieve grid carbon intensity
Not startedHalf-hourly regional intensity from NESO for each electricity meter’s postcode outcode.
- 12
We calculate emissions
Not startedThe Perseus methods: half-hourly consumption × grid intensity (electricity) or × the Defra factor (gas), by whole month.
- 13
We verify and extend the provenance record
Not startedWe verify the EDP’s signed record, then add and sign our receipt, grid intensity origin, processing and transfer-to-FSP steps.
- 14
We produce the report for the FSP
Not startedAn emissions report for the FSP the SME chose, with its data in the Perseus emissions API format and its provenance.