Bootstrap an IEEE 2030.5 (SEP2/CSIP) client: establish mutual TLS with a device certificate and discover the server's DeviceCapability and EndDeviceList resources.

domain: sunspec.org · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Provision a device certificate (manufacturer-issued or, per CSIP allowances, self-signed); the certificate's SHA-256 hash yields the device's LFDI (first 20 bytes) and SFDI (a truncated, checksummed form of the LFDI) identifiers.
  2. Determine the server's host, HTTPS port, and DeviceCapability resource path via out-of-band provisioning or DNS-SD; implementations commonly expose this at a path like '/dcap', but the exact path is server-defined, not a mandated well-known URI in the base standard.
  3. Perform a TLS 1.2 handshake presenting the device certificate for mutual authentication, using one of the cipher suites required by the CSIP/2030.5 profile; plain HTTP is not permitted.
  4. GET the DeviceCapability resource to enumerate function-set links, then follow its EndDeviceListLink to GET the EndDeviceList resource.
  5. Complete registration: for out-of-band registration the utility pre-populates the EndDevice entry; for in-band registration the client POSTs a new EndDevice instance and verifies a PIN in the linked Registration resource.
  6. Poll EndDeviceList and related resources per the server's declared pollRate, or use the SubscriptionListLink if the server supports push notifications.

Known gotchas

Related routes

Implement an IEEE 2030.5 (SEP2) client for DER communications under CSIP
sunspec.org · 6 steps · unrated
Implement a CSIP-Aus dynamic operating envelope (DOE) client that receives per-interval export/import limits from an Australian DNSP IEEE 2030.5 server
limepoint.com · 6 steps · unrated
Implement X.509 Just-in-Time Provisioning (JITP) in AWS IoT Core with a CA-signed device certificate
aws-iot · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans