EnergyFiby Arkreen
Join the sandbox waitlist
140 GWh verified on-chain · 300,000+ nodes reporting

Energy cash flows your code can call.

EnergyFi is the coordination layer that turns verified electricity into assets contracts can read, risk engines can consume, and capital can settle against — globally, in stablecoins, in real time.

Join the sandbox waitlist →Read the architecture
Evidence stream · sample
⛁ 3.42 kWh signed · dev_3pW8▣ epoch 71,204 anchored · 0x8f…3e21↳ 0.40 USDC routed · 3,000 unit holders◈ data_assurance L3 · audit variance 0.31%⚡ 0.6 kWh settled · Accra · eCandle⟳ evidence_ref evd_6Rk9wT · four clusters matched⛏ 3.1 kW surplus → 214 TH/s · AU
⛁ 3.42 kWh signed · dev_3pW8▣ epoch 71,204 anchored · 0x8f…3e21↳ 0.40 USDC routed · 3,000 unit holders◈ data_assurance L3 · audit variance 0.31%⚡ 0.6 kWh settled · Accra · eCandle⟳ evidence_ref evd_6Rk9wT · four clusters matched⛏ 3.1 kW surplus → 214 TH/s · AU
00 — The Gap

On-chain finance never lacked capital. It lacked a way to check.

Energy is among the most straightforward real-world assets there is: enormous in scale, structurally resilient in demand, backed by cash flows that run for decades.

It is also one of the hardest for on-chain finance to hold. Not because the value isn't there — but because it has been locked inside a legacy trust structure: centralized intermediaries, after-the-fact reporting, periodic audits.

Blockchains are good at verifying, programming, and composing. Energy finance has always depended on someone in the middle vouching for what happened. That mismatch is why most "energy on-chain" attempts stop at packaging. What the chain receives is a credible description — not a verifiable chain of facts.

One question sits underneath all of it:

Can the chain continuously verify that an energy cash flow was actually produced by verifiable energy behavior?

EnergyFi exists to answer yes.

01 — The Loop
LIVE

Four steps. One continuous chain of evidence.

This does not remove the operator, the offtaker, the custodian, or the auditor. Distributed energy finance needs all of them, and pretending otherwise would be the same mistake as pretending a report is a fact. What changes is that what each of them did becomes checkable instead of asserted.

01

Sense

Distributed devices record what physically happened — generation, delivery, consumption, payment — as they happen.

02

Verify

Events become signed, continuity-checked, anomaly-screened facts, anchored on-chain. A fact chain programs can reference, not a report filed later.

03

Assetize

Verified energy and the cash it produces are organized into standardized, composable on-chain assets.

04

Settle

Revenue routes to owners through smart contracts — peer-to-peer, across borders, on schedule.

device telemetry → signature & continuity check → anomaly screening → audit sampling → on-chain attestation → standardized risk output

The output is not a PDF. It's a continuous stream of evidence, consumable by risk engines.

LIVE — the four steps have run end to end on AREC since 2023 and on TH-PY-01 since 2025.

02 — Architecture

Keep the truth layer honest. Put the cleverness somewhere else.

Most RWA designs fail in the same place: to make an asset easier to sell, they smooth it — and the smoothing quietly detaches the token from the thing. EnergyFi separates the three jobs so that never has to happen.

LAYER 03

Financial Interface Layer

EARLY ACCESSERC-20 wrapper · oracle feed · standardized risk output

Standardized, composable interfaces for on-chain finance — without compromising the honesty of what sits underneath. None of these are deployed yet.

LAYER 02

Structured Composition Layer

EARLY ACCESSERC-4626 · index · tranche

Will organize fragmented assets into usable structures, reducing fragmentation friction and single-point volatility. Every construction will declare the assurance floor it accepts.

Specified. No contract deployed.

LAYER 01 · FOUNDATION

Asset Atomic Layer

LIVEERC-1155 · PowerYield Unit · AttestationAnchor

Preserves truth. Isolates risk. Anchors to verifiable cash flows.

One project, one token id — a bad plant cannot contaminate a good one.

Nothing here is averaged, smoothed, or wrapped. What the meters said is what the asset says.

Running today on AREC and on TH-PY-01. The published interface is still being frozen.

Keep the asset layer disciplined. Unlock capability in the structure layer. Stay compatible at the interface layer.

03 — Assurance
EARLY ACCESS

Not every kilowatt-hour deserves the same trust. So we grade them — three ways, separately.

EARLY ACCESS — this model is specified, and we open it to partners one at a time. Everything below describes how the three dimensions work and how each one is established.

An open network has to answer a question most platforms dodge: if anyone can connect, why should anyone believe the data?

Our answer is to separate two things that are usually fused — how hard it is to connect, and what your data is allowed to become. Connecting will be nearly free. Issuing a cash-flow asset will not.

But one ladder cannot carry that weight. A signature proves a reading came from a registered device. It says nothing about who owns the plant, whether the SPV can transfer the revenue, whether the offtaker actually pays, or who is allowed to hold the resulting unit. Those are different questions. Answering them with a single letter grade is how tokenized assets have gone wrong before.

So there are three grades. They are independent, they are read separately, and an asset can only be issued when all three are true at once.

data_assuranceHow much you can trust the reading
L0 · L1 · L2 · L3
asset_readinessWhether the asset is legally ready
draft · technical_verified · legal_verified · investment_ready
compliance_statusWho is allowed to hold it
SGHKAEaccreditedlockup 180d
declared per offering

data_assurance — how much you can trust the reading.

LevelWhere the data comes fromWhat it provesWhat it does not prove
L0Self-reported
Posted through the API by an operator.That someone submitted a number.Everything else.
L1Attested cloud
Pulled from a manufacturer's cloud under OAuth, carrying provenance.That the data came from a named vendor account.Whether the device was tampered with.
L2Device-signed
Signed inside the device by a key that cannot be exported.That a registered device produced it, unaltered in transit.Whether that device measures accurately, or whether the plant is yours.
L3Dual-sourced & audited
L2, plus independent settlement-side evidence and periodic sampling.All of the above, and that it reconciles against an independent money-side record.Legal title. Compliance eligibility.

data_assurance grades the data. It does not grade the asset. L3 on a plant with a defaulting offtaker is still L3 — an honest record of a bad situation.

asset_readiness — whether the asset is legally ready.

StateWhat it meansWho establishes it
draftProject created, not submitted.The asset owner.
technical_verifiedBaseline complete, devices trusted, generation data holds up.Automatic.
legal_verifiedTitle, offtake contract, SPV structure, insurance and permits checked.A licensed service partner, countersigned by Arkreen review.
investment_readyAll of the above, plus a settlement rail and a custody arrangement in place.Review.

This gate is not new. Every project onboarded so far has passed through it by hand — someone read the title deed, someone read the PPA. What changes is that it stops being a private conversation and becomes a field you can read, with a named party's signature behind it.

A signing chip in an inverter will never be enough to issue a cash flow. It was never supposed to be.

compliance_status — who is allowed to hold it.

Declared per offering, not per project. The same rooftop can be financed twice under two different sets of rules, and each offering will carry its own eligible investor types, its own eligible and excluded jurisdictions, and its own transfer restrictions — enforced at the contract level before a transfer clears.

This is the dimension that has nothing to do with the plant and everything to do with you.

To issuedata_assuranceasset_readinessAREC / ART environmental attributes≥ L1≥ technical_verifiedPowerYield cash-flow assets≥ L2= investment_readyStructured products · collateral= L3= investment_ready

compliance_status declared on every offering, always

Two conditions, not one. Neither substitutes for the other.

It moves both ways.

Break continuity, fail an audit, trip the anomaly detector — the level will drop on its own. New issuance freezes. Structured-layer weighting goes to zero. Existing holdings and existing distributions are untouched, always.

That first drop will be provisional. Meters get swapped. Firmware gets updated. Links go down and clocks drift. The partner will have fourteen days to submit evidence of what actually happened, after which the level is either restored or the downgrade is confirmed.

It's public.

All three fields will be first-class on every project, device and offering — readable through the API and anchored on-chain alongside the facts they grade.

It's a floor, not a filter.

Structured products declare the minimum they accept. An index that says "L3, investment_ready only" means it, and you can check.

Downgrade state machineanomaly detected→ provisional_downgrade automatic · immediate→ new issuance frozen automatic→ structured weighting → zero automatic→ existing holdings and distributions untouched→ remediation evidence submitted 14-day window→ automatic re-check, or human review→ level restored or confirmed_downgrade

Protection is automatic. Correction is not the same thing as approval.

The downgrade fires without anyone deciding to let it. What follows — submitting evidence that a meter was swapped rather than tampered with, and having the level restored — is a process, and it should be. A system that cannot tell a firmware update from an attack, and has no way to be told, is not rigorous. It is just brittle.

What we will not grade.

There is no fourth dimension for economic risk, and there will not be one.

We publish the inputs. We do not publish a grade. Arkreen is not a rating agency and will not become one — being both the issuance venue and the rating authority is a conflict the rest of finance already learned to separate.

Generation history, curtailment, counterparty concentration, collection ratio, jurisdiction: the inputs will all be readable through one endpoint. What they add up to is for rating agencies, lending protocols and index builders to decide, each with their own model and their own liability. We would rather the standard be adopted than owned.

This is what lets the network be open and the asset layer be strict at the same time.

04 — Proof
NOW

This isn't a roadmap. Some of it has been running for three years.

140 GWhRECs issued, consumed, and monetized on-chain
300,000+distributed nodes reporting generation
1,700,000+on-chain climate actions executed
160,000+Bitcoin blocks greened

AREC Protocol

LIVE · 4 chains

The full loop, proven first on environmental attributes — issuance, exchange, retirement. Deployed on Polygon, Celo, BNB Chain, and Solana.

PowerYield · TH-PY-01

LIVE · Thailand

A 300 kW commercial rooftop, split into 100W units, metered on-chain, distributing stablecoins on a monthly epoch. The first cash-flow asset on the stack.

eCandle · Awka

PRIVATE BETA · Nigeria

1 kWh nodes with machine wallets. Scan, pay in stablecoin, receive energy. Capital, local operator, and community user coordinated by one device. Invited partners only.

dVPP

PRIVATE BETA · Australia

Surplus kilowatt-hours dispatched into compute instead of curtailed. Electricity becomes hash; hash becomes value. Invited partners only.

Every one of these was built on the same four steps. EnergyFi is what happens when you stop rebuilding them and open them up.

NowNext

Everything above this line is running today. Everything below it is specified and in early access, opening to partners one at a time. We label which is which on every card, because a spec written in the present tense is just a promise wearing a lab coat. If something below is on your path, write to [email protected].

05 — Integrate
NEXT · EARLY ACCESS

Five ways in. Four will start with a key. One starts with a licence.

EARLY ACCESS — the open API and its sandbox are specified, and we open them per partner rather than by self-serve signup. Every call below is the interface. Write to [email protected] and we will set up your keys.

You own energy assets

EARLY ACCESS

Bring a plant, a battery bank, or a microgrid online and turn its output into units the world can own. You will connect through your existing inverter cloud in an afternoon, or take an edge gateway and sign at the device.

First call:POST /v1/projectsThen:authorize your inverter cloud — target: data flowing in ~30 minutesTo an open offering:target of about three weeks, most of it your baseline window
Join the waitlist →

You deploy capital

EARLY ACCESS

Find assets, run your own diligence against live evidence, subscribe in stablecoins, and reconcile distributions automatically. Operational diligence will no longer start and end with a PDF. Live evidence will sit alongside the legal documents behind the asset — you will still read the PPA, and you will no longer have to take the generation figures in it on faith.

First call:GET /v1/offerings?data_assurance=L3&asset_readiness=investment_readyThen:GET /v1/evidence/projects/{id}/stream — feed it to your own modelSettlement:self-custody or a licensed custodian. We never hold your assets.
Join the waitlist →

You make devices

EARLY ACCESS

Ship hardware that is born verifiable. Provision Arkreen keys at the factory and your customers will arrive at L2 on day one — which makes you a distribution channel, not just a supplier.

First call:POST /v1/devices:attestAlso:publish a connector to the marketplace and cover your installed baseSDKs:C · Rust · Python · device simulator, no hardware needed to start
Join the waitlist →

You build

EARLY ACCESS

Compose with verified energy facts and cash-flow primitives. Read access will be free, will require no KYB, and always will be — the sandbox will ship with a full simulated plant and its history.

First call:GET /v1/evidence/projects/{id}/streamOn-chain:a Chainlink-compatible feed exposing verified_wh, collection_ratio, data_assurance
Read the docs →

You are licensed, or you are the one who checks

EARLY ACCESS

Issue and distribute under your own licence, administer an SPV, hold units in custody, audit a project, or move money across the boundary between a bank and a chain.

These roles are not adjacent to the loop. Several of its links cannot close without them. asset_readiness will not reach legal_verified unless someone with a licence signs that it did, and settlement evidence is only independent if an independent party produced it. Most platforms will call you a vendor. Here your signature is a fact in the chain, carried in the evidence under your own name.

First call:POST /v1/service-partnersThen:POST /v1/attestations/legal — sign what you verifiedEndpoints:Asset · Evidence · ComplianceAccess:T3, licence on file. This is the door that starts with a conversation.
Talk to the team →
NEXT · EARLY ACCESS

Ten minutes to your first verified fact.

EARLY ACCESS — this is the interface we have specified, and sandbox keys are issued per partner. Once yours are set up, these three lines are what you run first.

# 1 · sandbox key, self-serve, no approval
curl -X POST https://sandbox.api.arkreen.com/v1/auth/token \
  -d 'grant_type=client_credentials' \
  -d "client_id=$ARK_ID" -d "client_secret=$ARK_SECRET"

# 2 · read a live plant
curl https://sandbox.api.arkreen.com/v1/projects/prj_8fK2mQ \
  -H "Authorization: Bearer $TOKEN"

# 3 · pull the evidence behind last month's distribution
curl https://sandbox.api.arkreen.com/v1/evidence/evd_6Rk9wT \
  -H "Authorization: Bearer $TOKEN"
< 10 minto your first successful API calltarget
< 1 dayto your first verified telemetry readingtarget
< 21 daysto your first live offeringtarget

These are the targets we are building toward, not measurements we can show you yet. On the day the sandbox opens, they become published commitments wired to the status page and measured continuously. Hold us to them then — and hold us to the distinction now.

06 — Under the hood
NEXT · EARLY ACCESS

One reference connects the loop.

EARLY ACCESS — the evidence object is specified, and the endpoints below open with your sandbox keys.

Every distribution will carry an evidence_ref. Follow it and you get what sits behind the money, in four parts: whether the electricity was produced, whether the revenue is legally yours, whether the money actually arrived, and how it was split.

A signature on a meter reading proves electricity moved. It does not prove anyone paid for it. Those are separate claims and they need separate evidence — which is why this is four clusters and not one chain.

Not a summary of what happened. The record of what happened, in the order it happened.

energy_evidence

Was the electricity actually produced?

If missing: nothing can be issued.

legal_evidence

Who owns the revenue from it?

If missing: asset_readiness cannot advance.

settlement_evidence

Did the money actually arrive?

If missing: no distribution can execute.

distribution_evidence

How was it split?

If missing: the payout cannot be audited.

A distribution will not execute until settlement_evidence is matched.

Paying out against an invoice that has not been collected means paying interest out of the reserve — with someone else's money. The chain of evidence is structured so that this is not a policy we promise to follow. It is a state the contract cannot reach.

// GET /v1/distributions/dst_4mB7xQ
{
  "epoch": 71204,
  "verified_generation_wh": 39840000,
  "tariff_minor_per_mwh": 4120,
  "gross_minor": 164140,
  "currency": "USD",
  "waterfall_result": {
    "opex_reserve":  31590,
    "operator":       9421,
    "protocol_fee":   3129,
    "unit_holders": 120000
  },
  "per_unit_minor": 40,
  "tx_hash": "0x8f3a…c21e",
  "evidence_ref": "evd_6Rk9wT"   // ← follow this
}
// GET /v1/evidence/evd_6Rk9wT
{
  "evidence_id": "evd_6Rk9wT",
  "epoch": 71204,
  "data_assurance": "L3",
  "asset_readiness": "investment_ready",

  "energy_evidence": {
    "records": 8928, "signature_valid": 8928, "continuity_gaps": 0,
    "audit": { "sampled": 45, "variance_pct": 0.31 },
    "anchor": { "chain": "polygon", "block": 78412093, "merkle_root": "0x4a…91" }
  },
  "legal_evidence": {
    "offtake_agreement": "doc_5nT2", "title": "doc_8vJ4", "insurance": "doc_1cZ6",
    "attested_by": "adt_9qH4", "valid_through": "2031-01-14"
  },
  "settlement_evidence": {
    "invoiced_minor": 164140, "offtaker_confirmed": true,
    "funds_received": true, "reconciled": true, "currency": "USD"
  },
  "distribution_evidence": {
    "gross_minor": 164140, "rounding_residue_minor": 2045,
    "waterfall": "executed", "tx_hash": "0x8f3a…c21e"
  }
}

Without this reference, a tokenized plant is a promise with a wrapper. With it, it's a cash flow you can follow from a signed meter reading to a bank confirmation to the transaction that paid you.

07 — What gets built
NEXT

We'd rather be a dependency than a destination.

Verified energy facts and the cash flows they produce are inputs. What gets built on top of them isn't ours to decide — and the design is better if it isn't.

None of the six below exist yet. They are what the primitives are for, listed here so you can tell us which one we got wrong.

Non-correlated collateral

Solar cash flows as a new class of on-chain collateral.

EARLY ACCESS

Indices over plants

Diversified exposure with a declared assurance floor.

EARLY ACCESS

Underwriting without paperwork

Risk engines pulling live evidence alongside the documents, instead of waiting on a quarterly PDF.

EARLY ACCESS

Energy-denominated stables

A unit of stable value anchored to 1 kWh. Direction only — no design frozen, no date.

RESEARCH

Compute markets

Surplus power routed to flexible load, settled on-chain.

PRIVATE BETA · running as dVPP in Australia

Agent-side settlement

Machines paying for their own electricity, per epoch.

PRIVATE BETA · running as eCandle in Awka

Questions that actually block a decision.

Which parts of this are running today?

+

What happens when a plant underperforms?

+

Do you hold my funds?

+

How do you handle jurisdictions?

+

Can I verify a distribution independently?

+

What if the data connection breaks?

+

Do you rate the assets?

+

Which chain does it settle on?

+

The interface layer is open.

Whether you have kilowatt-hours, capital, hardware, a licence, or an idea about what energy could become once it's programmable — the specification is public and the queue is open.

Join the sandbox waitlistRead the docsTalk to the team