I've recently switched from OVO to Octopus Intelligent Go for several reasons.
OVO , in conjunction with their partner Kaluza runs a system of overnight cheap rate charging called Battery Boost where you hand over control to them (I believe it's similar to the Axel system)
Octopus successfully took over my supply over a week ago however when I try to enter Timed Charging data into the AIO (via App or portal) something called battery.boost.agent (delegate) will overwrite the timed charge settings with 5 minutes. This shows in the logs
I have removed all permissions in the portal however battery.boost.agent (delegate) persists.
Spent an hour on the phone with Givenergy and their only solution is to ask OVO/Kaluza to relinquish control. As I'm no longer a customer it's not high on their priority list.
Any thoughts? I have a screenshot of the logs but not sure how to post.
OVO Battery Boost won't relinquish control over my AIzo

In the portal, have you looked at Account Settings and then Manage Account Security and Manage API Tokens? That should enable you to revoke any API token that OVO (presumably) have. Or remove Delegate Access if that exists...
ChrisLav All revoked. All fields are clear.
Givenergy confirmed.
Still won't retain a Timed Charge slot.
Another day dealing with OVO Solar!

That can't be right? Unless OVO have some sort of irrevocable back door into Givenergy (which would be a massive worry) they surely must be able to revoke their access?
There are two types of API access - one is via API keys and the other is through OAuth, but both options present a way to revoke keys (albeit in different parts of the online portal) - have you looked through all sections of the 'my account' pages on the portal. I forget what it is named but I think it's under security settings or something along those lines.
hoggy
This problem has been persisting for over a week and I think I've looked everywhere, but I'll have another look.
Also spent an hour on the phone with Givenergy who can see everything I can see and they are mystified.
I also find it strange that Givenergy do not have an administrator mode that would allow remote clearing of setting and privileges. They claim they don't and it's down to OVO/Kaluza to revoke their own access.
Tried several times this morning and still having my timed access settings overwritten by battery.boost.agent (delegate).
Thanks for your advice and I'll keep on digging.

mikes01666 I also find it strange that Givenergy do not have an administrator mode that would allow remote clearing of setting and privileges. They claim they don't and it's down to OVO/Kaluza to revoke their own access.
In which case I'd do several things -
1) Raise a formal complaint with Ovo;
2) Initiate a Subject Access Request with Ovo & Kaluza;
3) Raise a formal complaint with GE;
4) Initiate a Subject Access Request with GE - and make sure they give you ALL the data from the portal, including that which is hidden from you by default;
5) Raise a formal complaint with the Information commissioner regarding both companies usage of your data and their refusal to correct errors in that data.
Take the complaint all the way to the electricity ombudsman as that's the only way you're going to get Ovo's attention.
mikes01666 Can we assume that "(delegate)" indicates that it's using a delegate account for access. For me, that's the second-last section in the security page at https://givenergy.cloud/account-settings/security
(I don't have any set up, so I can't tell you how you would go about revoking such a thing.)
Vestas
Many thanks for the responses.
I've already raised a complaint with OVO.
The others are like letting everyone having both barrels at once!
I never thought about the information requests and will keep that in reserve.
I think OVO should be allowed a couple of days to correct the situation.
I'll keep the forum posted in case anyone else encounters this problem.
Restarted the Inverter. Still timed charge us being overwritten.
Screenshot of API and Delegate access fields from portal.

mikes01666 You'll need to do the SARs as part of the complaint to the ICO anyway.
Basically a company (companies) is misusing and storing incorrect data about you and (so far) refusing to correct that data. That misuse is having a detrimental effect on you/your finances. Its a classic case for the ICO who WILL fine all those involved as its so egregious.
Its a good heads-up for everyone else - NEVER "Delegate Access" under any circumstances!
Can you do a factory reset of the Inverter and change the user ID and API keys?
You could also block the IP range for the OVO provider at your router firewall.
kram You could also block the IP range for the OVO provider at your router firewall.
It's probably coming via the GE servers. Home routers usually block all inbound connections by default.
I suggested a factory reset to GE but they said it would make no difference.
GE also rejected a new account.
GE technical are now looking at it.
OVO/Kaluza are quiet.
Someone (GE or Kaluza) is playing with the battery settings.
Unusual settings are being written by battery.boost.agent (delegate).
I always set to 100%charge between 23.00 and 05.00.
Someone is setting it to charge between 08.30 and 09.00 to 79%
There is also an unusual User called 'Server'.
Screenshot of logs attached.
Let this be a warning to those who hand over access to third parties.

mikes01666 GE have a lot to answer in all this whoever the source is. From the info posted there should be no ability for external control, so GE are (albeit accidentally) complicit in facilitating this.
Was there ever an entry for you to delete in the Delegate Access section though - it might be that some sort of bug is present where that delegation was approved to make things work, but never showed properly at all in that section, and so is not visible to be deleted by you as a user.
Firewall tweaks etc shouldn't have any effect, all of this kind of stuff needs a 3rd party (usually GE in this case, or their proxies / authorized 3rd party infrastructure) to be able work at all behind any kind of home-grade broadband router.
Is installer access granted, could something be 'leaking' in that way. Did they help you set anything up with OVO?

It would appear that the OVO way is very much a bespoke 3rd party integration rather than the more expected (https://givenergy.co.uk/software/commercial/commercial-integrations/)
That being said THE very basic idea that the control may need to be disabled at some point by either party (or the equipments owner) appears to have been completely missed. How on earth that’s possible & why Givenergy alone can’t even kick someone out of their own backend does raise some intriguing points in the “well if this hasn’t been thought about what other things are missing / security holes are present”
hoggy I'm pretty sure the finger should be pointing at Kaluza here, although the GE incompetence isn't unexpected as there's clearly no meaningful QA on the portal s/w.
Its my understanding that Kaluza are not unknown to the ICO 😉
Mouton If you have some means of local control then the simplest thing to do is to block the inverter from connecting to anything outside the local network. Even crappy routers have that option.
If you block all outgoing traffic from the inverter then there's no way for the portal/server/anything else outside the LAN to connect to it.
Unfortunately the OP said he'd moved to OIG so that would block Octopus too. Might have to be done though.
mikes01666 Another option would be the press, if things go nowhere.
Somewhere like The Register (www.theregister.com) would report it and a lot of the UK MSM journos read that site.
It'd make a good story 🙂
Mouton
It currently shows an API access for Octopus.
Nothing else in any of those access sections in the portal.
There was legacy access for the installer but that was revoked about 10 days ago.
Vestas Sorry, yes I omitted the nuclear option of stopping it talking to anyone. Kind of assumed portal, firmware updates, etc were essential part of normal ops. But indeed it would stop the mess in the meantime as long as the inverter can be set to timed charge via local control.
Mouton Was there ever an entry for you to delete in the Delegate Access section though - it might be that some sort of bug is present where that delegation was approved to make things work, but never showed properly at all in that section, and so is not visible to be deleted by you as a user.
I'm beginning to think this might be the case.
Although all access sections in the portal appear clear, there is some kind of legacy access lurking behind unseen.
I can't believe that GE are not capable of locating and clearing via Admin rights to the software.
mikes01666 Worth disabling Octopus to eliminate and prove to GE you've removed everything you can?
I see Octopus in the same section in my account too, but they have no control of my AIO (I'm on IOG too). I assumed this entry is to allow the GE app read access to my tariff.
The only control of my GE stuff (apart from my GE login and the GE app) comes from Home Assistant which links to signals from IOG and my car charging. I've never (knowingly) granted Octopus access to my AIO/battery and never added it to their systems, so maybe this section is about connections in the 'other direction'?
Vestas
This was my worry when GE were considering creating another login (which they rejected).
Changing the AIO may affect the connection to the inverter, Gateway, and panels; the warranty information embedded in the AIO; and the connection to Octopus.
I think all these might be solvable but I didn't want to solve one problem and create several others as other than the ability to set a Timed Charge, all other aspects of the system are working as expected.
Mouton (In fact I am more sure about that last sentence, since not looking for ages I can now see calculated import and export values in the GE App based on my real tariff).
mikes01666 Did Ovo install the system or were they just your energy supplier?
You haven't mentioned them installing the system but their website says that in order to be eligible for "Battery Boost" Ovo must have installed the system?
Yes, OVO installed it. I don't think Battery Boost is conditional rather an optional 'add on'.
mikes01666 When did you revoke the installer access?
I have a theory that the delegation was done via OVO's master installer account and when you revoked that access that made it impossible for them to remove the delegation automatically.
"Battery Boost" is only available to customers who had PV/battery installed by OVO from what their site says so I'm assuming they're utilising an installer account to run the service.
Vestas When did you revoke the installer access?
When this problem first arose when I moved to Octopus about 2 weeks ago.
When I first contacted GE they asked me to revoke all remote accesses indicated on the portal. This included installer setup access.
However the Battery Boost add on was only added to my OVO account several weeks after the system had been commissioned.
Additionally OVO subcontracted the installation to a GE accredited installer.
Vestas That starts to make sense why it might be hidden from remval by end user too as it's all done centrally and tied up with OVO tariff. Stops you getting one that way and then messing / overriding with HA etc, they have to have absolute control if you stay.
Mouton It would also maybe make sense as to why -
1) GE can't revoke access - its a major installer's account;
2) Changing user account wouldn't help - installer remains the same.
mikes01666 When this problem first arose when I moved to Octopus about 2 weeks ago.
At this point had you contacted OVO or not?
mikes01666 However the Battery Boost add on was only added to my OVO account several weeks after the system had been commissioned.
Also I assume you didn't make any changes in the portal or generate an API for them - like you did for Octopus?
Vestas
I've raised a complaint. However as they no longer supply me they appear not hugely interested. Maybe the complaint will hurry them up.
As I said earlier something is happening. When I check if the slot I've programmed is intact, there's a completely different one there. So either OVO or GE are tinkering.

mikes01666 I don't know if this might work, but a temporary fix might be to change the inverter date/time setting so the time slots the delegate agent sets match the slots you want? Assuming of course that the delegate agent doesn't immediately change the time settings back again...
Just while GE/OVO are (hopefully) fixing the problem
A screenshot of your API tokens would be useful.
https://givenergy.cloud/account-settings/api-tokens

If they've really done this at "Superuser" level, that does make sense as to why, but that does beg the question of how the access tiering works in the portal even with installer level access removed? I understand the need for (hopefully a very limited) number of Givenergy accounts with God Level access but I wasn't expecting Installer access being revoked still letting anyone but Givenergy access anything at all (given you have no idea if say the entire support floor of OVO know the password to their master account...)
Does that mean wholesalers like Segen/Midsummer can see/control every inverter they've ever sold?
Rubikcube posted above a couple of days ago (can’t link to the post for some reason)
hoggy but that does beg the question of how the access tiering works in the portal even with installer level access removed?
It clearly doesn't work. That's what bugger all QA and working on live production systems does though so we shouldn't be even slightly surprised.
Some screenshots from the App showing that the Timed Charge slots are randomly changing in terms of time and charge level.
These are happening with no input from me.




Completely mystified as to what's going on!
Vestas
No. Battery Boost was added automatically by OVO. It just started working a few days after I applied for it.
Mouton posted above a couple of days ago
No it wasn't.
The nearest thing posted was account security
https://givenergy.cloud/account-settings/security
We need to see the API tokens
https://givenergy.cloud/account-settings/api-tokens
mikes01666 Completely mystified as to what's going on!
Maybe you could check/post your API tokens. Just click this link.
Rubikcube Interesting subtlety. So I understand completely, are you saying that even if there were any, there would not be a list in this section in account security, but only after clicking through to the full API tokens page. Ta

mikes01666 Done via an installer account then.
Mouton
Nothing there.

Vestas
It would seem so - OVO/Kaluza.
However Installer permissions have been revoked at GEs request about 2 weeks ago
Yet another random slot generated with no input from me.

This isn't Octopus Flux programming cheap slots?
mikes01666 Are you on Flux or Go? In the first post you said OIG?
These slots aren't random and you don't really need to keep posting them.
Clearly revoking installer access doesn't revoke the method Ovo/Kaluza have used to run their "Battery Boost" product.
This leads to the suspicion that others could do the same, regardless of the owner's wishes. Wouldn't be the first glaring security hole in the portal, and affects us all.
Were I you I'd be looking at some local control and blocking the inverter from the internet until GE/OVO/Kaluza sort it out.
Vestas Are you on Flux or Go? In the first post you said OIG?
I'm on Go but maybe Octopus have made a mistake? Unlikely, but I'm grasping at straws here.
The screenshots demonstrate that someone is remotely controlling the battery. The nature of this remote control has changed. Initially my slots were overwritten and deleted. Now 30 minute random slots at varying charge levels are being remotely added.
It shows that OVO/Kaluza or GE are intervening.
Vestas Were I you I'd be looking at some local control and blocking the inverter from the internet until GE/OVO/Kaluza sort it out.
What would you suggest? Removing the ethernet cable?
There's not much sun around today and the remotely set timed charge slots are filling the battery at peak rate! I've manually switched off the latest slot but having to continually monitor is a pain.
mikes01666 Okay, no API token, so I'm out of ideas.
I have a firewall that would stop this on my system, but unless you are competent with either iptables or netfilter, it's an advanced project!
https://community.givenergy.cloud/d/1403-restricting-remote-control/7
mikes01666 Could you set the timed slots, quick refresh check they are set correctly, and then immediately remove ethernet (or wifi) connection. That should leave the AIO with no means of being changed (or monitored, or updated mind) until GE can respond or take some action. Following the rules set out in the settings you leave eg ECO mode, with timed charges. You may get a bit of clock time drift with no internet updates, but should be minimal over a few weeks.
Alternatively you may be able to block the IP assigned to your AIO from contacting the internet (outbound) by adding (outbound) firewall rules in your router (very much dependent on the router's abilities and your tech knowledge). This option might leave your app still able to connect locally for monitoring etc (others may be able to confirm). You need to also bear in mind that a reboot of router may change the AIO's local IP address and that might need to be avoided by a static assignment at the router end to avoid this (ability also router dependent).
Rubikcube
Bog standard Sky router so it may be beyond its capabilities - certainly beyond mine!
I'm reluctant to change the system settings as before this problem it was working fine. It may solve one problem but introduce several others.
Mouton
Removing Internet access will stop OVO/Kaluza or GE remotely fixing the problem.
mikes01666 You might be able to do it with a Sky router actually by the looks of this - https://www.techfinitive.com/explainers/how-can-i-stop-devices-using-sky-wi-fi/
The source LAN IPv4 address would be the IP currently assigned to the AIO. I don't believe they use IPv6 yet so ignore. You can probably create static assignments from the attached devices table somehow.
However unless you are techncally confident, or have a friend who is, tread carefully..
Go for the unplug option above first unless anyone here can think of why not.
I would just leave it for a few days and bear the cost, whilst hassling GE and OVO for a solution. If it's not fixed after a few days, turn off the AIO (or remove the network connection). With the AIO off any commands will time out. To see them in the remote control history, you would need to turn off "Filter Errors".
Did you add your inverter to the devices list in the octopus app?
They would cause octopus to control it, like octopus intelligent flux control.
I've heard of others adding the inverter to the app without realising what that would mean.
TX200 The "battery.boost.service" which OVO setup (without any user action) is still active and logged as such.
Nothing to do with Octopus.
This one seems to be a tossup between OVO/Kaluza and GE (or their parent anyway).
Definitely one for the ICO, regardless of who is to blame as its a poster case of incorrect data being misused to the customer's detriment. Fines all round are deserved IMHO.
Vestas Totally agree, I'd go down the ICO route, the pain of SARs etc is great way to get attention.
I wonder if OVO have a master API token for GE's API that allows them to make calls containing any valid serial number (although you'd hope restricted to those serial numbers in their scheme). This would mean -
- It's not visible in an individuals account, as it's not theirs to revoke
- lower levels of GE helpdesk won't understand or see often, if at all
- GE can't unilaterally revoke because it would break all linked OVO devices
- Re-issue at that level wouldn't solve because if OVO keep sending authenticated API calls with a valid serial number the AIO / inverter will concerned will just get changed again using the new auth token
Now living in fear of my AIO serial number being typo'd into an OVO system...
Mouton Sounds entirely plausible.
I'd suggest people get some means of local control implemented - could be anything from Home Assistant/GivTCP to @Rubikcube 's app.
I dunno, the idea that you can't control a major electrical appliance installed in your house without an internet connection has always been a no-no to me. Others obviously differ.
mikes01666 Removing Internet access will stop OVO/Kaluza or GE remotely fixing the problem.
Probably incorrect. If not they can ask you to reconnect it when they finally wake up, in what could be weeks or months.
I see two options now, and if that's your final view above then only option 1 is valid, although let me try and persuade you of option 2.
1) If that's your stance then you have no way of stopping the continued changes yourself at all so just wait for GE OVO etc to get back to you (maybe follow the advice about SARs etc above as they are painful and will get people's attention), bear the cost of the peak charges, or keep on staying awake to cancel them.
2) Here's why, in my humble opinion, I think your statement might be incorrect.
I'll be advised otherwise by others more knowledgeable, but part of your problem is at GE 'head office' (allowing themselves to be a conduit for the requests). Your AIO / inverter itself likely does nothing but report back to GE servers to be run / managed / updated / monitored / set by GE, you, your app, the commercial API etc. Granting others access (eg API) access gives authorized entities access to GE 'head office's published (in this case) commercial API interface, which if the requestor can authenticate properly, will then make GE servers in turn request changes to your AIO settings. This is achieved by GE servers receiving the instructions, checking authorization etc (as documented in their API spec), and then GE passing on the settings changes to your AIO (in a simlar manner as changing on the portal, app etc would do) and also with a note of who/what requested the change, hence the entries in your logs.
The authorization of the access (and your problem) is at GE, not your inverter. I don't think there will be a valid route for instructions for 3rd parties coming direct to your inverter. (There are lots of techy reasons for me assuming this, and although I am not a programmer, I have worked in IT for 35 years). Revokation of the authority can very likely be done with your AIO offline.
OVO etc would have to use the internet accessible commercial API. There is no access to your LAN from the internet to access any local controls / interfaces, these are not exposed to the internet without firewall changes in your Sky router.
References and light reading
GE commercial API https://givenergy.co.uk/software/commercial/commercial-integrations/
GE free API https://givenergy.cloud/docs/api/v1#authenticating-requests
URL of GE API where requests are sent - https://api.givenergy.cloud/v1/ This is not your personal inverter, it's GE servers
An example explanation of using the public / commercial API and explains why some of us are suggesting some of these things to you - https://www.speaktothegeek.co.uk/2023/10/givenergy-ev-charger-and-home-assistant-using-the-cloud-api/
Also posted in reply to @Vestas post (more detail over there) - While typing this and thinking for you it has occurred to me - Possibly OVO have some sort of master API token that allows them to make changes to any inverter if the call includes a correct serial number. This would make it difficult for GE to revoke without co-ordination as it would break every other OVO linked system temporarily, and most worryingly mean GE cannot stop the requests to your inverter without stopping everything OVO linked. In which case your focus needs to be beating up OVO with GE's help? As long as OVO have a valid token (old or new) and keep making API calls with your serial number you're going to have a problem.
I wonder if it's appropriate to summon @TheDragon (GivEnergy) if they have time. Sorry if not proper etiquette, but there are possibly some architectural design / security questions here that might go beyond an individual case.
mikes01666 one of the settings on my hybrid is the AC charge power %, which only seems to affect charging from grid. If aio has the same, and if you are prepared to disable all grid charging, setting that to 0 might be useful in the short term.
Well .. it won't disable grid charging, since during a charging slot you'll still disable battery discharge to home, but at least it won't be actively charging battery.
And that's assuming the hostile agent doesn't adjust it back.
DD
This outside interference doesn't seem to affect the Timed Discharge setting. As I test I've set a slot and it's remained unchanged for a few days.
Thanks
mikes01666 Using the portal remote control you could set up a Pause Charge window to prevent charging outside the hours you want. Unless you have some automation to keep charging running within the window you do want this is likely to just leave you with a flat battery though

This is already in hand by the portal team.
I've no idea what OVO/Kaluza or GE are doing in the background (if anything!).
I've turned off Timed Charge and Timed Discharge from the App. Let's see what happens.
I'm due to call both of them later this morning.
Well that was short lived!
Phantom Timed Charge slot programmed for 11-11.30 to 42% charge. I've turned off.
[unknown] Did you use an OVO app when you were with them? If so it may be worth checking the settings in the app and seeing if there is anything there that is linked to your system. Just a long shot, but you never know.
As quickly as this problem arose, it appears to have been resolved. I believe Kaluza have released access to the AIO.
My advice to anyone leaving OVO with Battery Boost enabled is to cancel the add on (and receive confirmation from OVO) well in advance of switching.