A hosted OCPP 1.6J and 2.0.1 server — the backend your chargers connect to. Any brand that speaks OCPP, under your own name, checked against the Open Charge Alliance’s new security guide. € 0 per charge point for its first 30 months, € 3 per month after.
OCPP is the open protocol between a charger and whatever manages it. The charger opens a WebSocket and reports in; the server decides everything that happens next. Six jobs, all of which MobiFLO does for every charger connected to it.
Each charger signs in with its own credential over TLS, and the server refuses anything unencrypted or unauthenticated before a single OCPP message is read.
Authorising cards, starting and stopping sessions, and turning meter values into records you can bill, per connector.
Start, stop, unlock, reset, reserve and reconfigure from the console — with who may send what decided by role on the server, not by which buttons are visible.
Charging profiles that share a site’s grid connection across every charger on it, so twenty points do not need twenty times the capacity.
Firmware rollouts and log retrieval, restricted to administrator roles — the commands that can change what a charger runs or send its logs elsewhere.
Sessions leave the OCPP layer as priced records for your invoices, and for OCPI 2.2.1 and Hubject roaming when your drivers charge elsewhere.
Most installed chargers speak 1.6J; most new ones ship 2.0.1. MobiFLO negotiates the version with each charger as it connects, so a mixed fleet runs on one platform without choosing.
| OCPP 1.6J | OCPP 2.0.1 | |
|---|---|---|
| Messages from the charger | 11 actions, each checked against a strict schema | 15 actions, each checked against a strict schema |
| Transactions | StartTransaction / StopTransaction | TransactionEvent, with richer state |
| Configuration | Key–value (ChangeConfiguration) | Device model (GetVariables / SetVariables) |
| Smart charging | Charging profiles | Charging profiles plus EV charging needs |
| Security | TLS with per-charger credentials; security extensions | Built into the protocol, including certificate signing |
Both are reasonable. The honest difference is who carries the operations — and what arrives with the server.
| SteVe | CitrineOS | MobiFLO | |
|---|---|---|---|
| OCPP versions | 1.6J (with security extensions) | 2.0.1, plus 1.6 since 1.6.0 | 1.6J and 2.0.1 |
| Licence | Open source | Open source (LF Energy) | Commercial, hosted |
| Hosting, patching, uptime | You | You | Us |
| Roaming, billing, driver app | Build or buy | Build or buy | Included |
| Cost | Your engineering time and hosting | Your engineering time and hosting | € 0 per charge point for 30 months, then € 3/month |
If you have engineers and want full control, the open-source servers are good software. If you would rather run chargers than run a server, that is what MobiFLO is for.
The Open Charge Alliance published version 2 of its Security Operations Guide in September 2026. MobiFLO was checked against it requirement by requirement: TLS 1.3 by default, a credential per charger (Security Profile 2), strict schema validation of every incoming message, and firmware, certificates and configuration restricted to administrators on the server.
Each charger is provisioned in the console with its own credential, then pointed at MobiFLO by changing its OCPP backend URL — which most vendor tools push to every unit at once. RFID cards come across as a CSV, and the chargers stay where they are.
Yes. SteVe is an open-source Java OCPP server that has implemented OCPP 1.6J, including the security extensions, since 2013, and CitrineOS is an LF Energy project built around OCPP 2.0.1 that added OCPP 1.6 in its 1.6.0 release. Both cost nothing to license; what you take on is hosting, security patching, upgrades, uptime and support, and neither ships roaming, settlement or a driver app. MobiFLO is not open source: it is € 0 per charge point for that charge point’s first 30 months and € 3 per charge point per month afterwards.
The server a charger connects to over OCPP — also called an OCPP server, central system or CSMS. The charger opens a WebSocket to it and reports in; the backend authorises cards, starts and stops sessions, reads meter values, sets charging limits and pushes configuration and firmware.
If they speak OCPP 1.6J or 2.0.1, yes — Alfen, Zaptec, Easee, Wallbox, ABB and most commercial hardware sold in Europe in the last decade. Moving them across means changing one setting on the charger: the OCPP backend URL.
Not to get started. OCPP 1.6J runs most of the installed base and handles authorisation, sessions, metering, smart charging and firmware well. OCPP 2.0.1 adds a richer device model, security built into the protocol and better transaction handling. MobiFLO runs both, per charger, so a mixed fleet needs no choosing.
OCPP software is the protocol server. A CPMS — charge point management system — is everything built on top of it: tariffs, billing, roaming, driver apps, reporting and load management across sites. MobiFLO is both; the OCPP server is the layer this page describes.