How the PJM Capacity Model is built: the engine, the fleet and its accreditation, the three reliability metrics, the auction record, the winter adjustments, the emergency-auction model, and the scope choices. Each tab's methodology card links to its section here.
The default engine is byte-identical to the author's shipped build and reproduces all 20 posted 2028/29 ELCC ratings within about 2 points: every number carries its chain of custody.
Contents
A public-data reconstruction of PJM's reliability machinery, run in the browser.
PJM is the grid operator for 13 states plus DC in the eastern US. Every year it runs a capacity auction: payments to power plants for promising to be available when the system is tight. The size of that procurement rests on a reliability model, and this dashboard is built on an independent reconstruction of that model from public data.
The tabs render precomputed numbers: our own offline runs of the shipped engine, exported to static data files. Each file traces to a named generator script. The dashboard works in full without the engine ever loading. The sidebar pill (or any live control) switches on a live copy of the same engine, compiled to WebAssembly. It downloads the 2028/29 data bundle (about 46 MB), runs in a background worker, and upgrades values in place. It never gates the page: off, loading, or failed, the precomputed values stay.
The engine is deterministic. It has no random number generator: weather and outage draws come from PJM's own published Monte Carlo tables. The same inputs give the same answer to the last digit, on any machine. A live run reproducing its precomputed value is therefore the expected case. Any live result more than 0.001 LOLE (expected shortfall days per year; the standard is 0.1, one day per decade) from its precomputed value flags on screen as a regression signal.
Costs, measured: one re-evaluation of changed inputs takes 0.34 to 0.8 seconds. Root-finding a full reliability requirement takes 7 to 33 seconds, machine-dependent (both ends measured). The full solve only runs behind an explicit button with a progress readout, on the Emergency Auction and Reserve Requirement Study tabs. Live controls today: on Metrics, the winter-credit runs and the class-rating rescan (a requirement solve plus 13 evaluations at the solved point). On the Emergency Auction tab, the winter dropdowns (a precomputed solve grid) plus the exact-values evaluation and full solve. On Reserve Requirement Study, the full workbench: fleet edits, evaluations, requirement and margin solves. Everything else stays precomputed by design. The per-vintage LOLE series would need three more data bundles, about 113 MB beyond the 2028/29 bundle the engine already holds; the Extreme Weather tab is a frozen snapshot.
The chain of custody, the golden harness, what reproduces, and the three disclosed limits.
Chain of custody first. Every engine artifact this dashboard runs is a copy of the shipped source engine: the WebAssembly solver, its JavaScript bindings, and every study data bundle. BUILD-MANIFEST.jsonrecords each one's source path, byte count, and SHA256 hash. The regression harness re-verifies the working tree against that manifest on every run. The engine behind these pages stays byte-identical to the audited engine, provably and continuously, not as a one-time claim.
The golden harness (tools/golden-check.mjs) has five layers, cheapest first. Layer 1 re-reads the pinned model numbers from the shipped files. Layer 2 sweeps every data fixture's SHA256. Layer 3 rebuilds the generated fixtures from their sources, byte-for-byte. Layer 4 checks the build manifest. Layer 5 re-executes the cheap engine evaluations live. Any change that moves a model number fails the harness loudly; an intended change has to be re-pinned in writing with a dated note.
What reproduces. Every input that carries weight is PJM's own published file, verified bit-for-bit: 14.1 million hourly load-scenario values and every Monte Carlo outage draw with a posted comparator match PJM's workbooks exactly, with zero unexplained discrepancies. The stochastic universe is PJM's, not the modeler's. The engine is deterministic and was independently re-executed from the compiled binary: nine of ten 2028/29 and six of six 2026/27 published figures reproduce, most to the last printed digit, on two independent solver implementations that agree to the milliwatt. And once five PJM-withheld quantities are calibrated against PJM's own published output, the model lands within 44 MW (0.03%) of PJM's 2028/29 solved reliability peak and within half a point on the winter risk shares. It then answers a question PJM publishes no number for: the loss-of-load expectation of the fleet the July 2026 auction actually bought.
Three limits, disclosed because they bound how far the claims above stretch. First, the 44 MW figure is a calibration residual, not an independent replication: the five withheld inputs were each fitted against the same published workbook the residual is scored on. Each is individually worth more than 44 MW at the hours that set the answer. Second, a live defect: the engine freezes its demand-response scaling denominator at PJM's solved load (162,063 MW), so any run above that load over-credits demand response. The over-credit is roughly +200 MW at the 165,953.5 MW forecast peak these fixtures run at, and roughly +930 MW at a 180 GW peak, uncapped; load-growth results from this engine need it subtracted or disclosed. Third, the original simulator's live ELCC scan and its printed benchmark table define the perfect-capacity reference two different ways (load-side versus supply-side), so scan results run about 1% relatively higher than the table. The benchmark below quotes the printed-table basis.
When the optional live engine is on, the Metrics and Emergency Auction tabs show an engine diagnostics strip. It lists worker and scenario-partition counts, the scenario and draw universe (weather scenarios times outage draws equals simulated years per evaluation), the measured bundle size, and the duration of the most recent run. Every value in the strip reads at runtime from the engine's health check, the measured download, or the last run's own timer. None is copied from static text. The Reserve Requirement Study tab carries a richer version of the same facts in its own Engine section.
How the fleet is counted, and why the model basis is not UCAP.
The fleet enters the model class by class: nuclear, coal, gas combined cycle, gas turbines, hydro, wind, solar, storage, demand response. Each class carries an accreditation ratio, the share of its nameplate that counts toward reliability. The accreditation module produces those rows, and both the portfolio chart and the shortfall waterfall read from it, the waterfall taking deltas so level bias cancels.
UCAP, unforced capacity, is PJM's official ledger of the same idea. The model's basis differs from UCAP enough that the dashboard states which one every chart is on, and the Portfolio tab explains the gap.
One connects the fleet to risk, two score the risk.
ELCC (effective load carrying capability) is the accreditation concept above: how much of a plant's nameplate actually carries load when it matters. LOLE (loss of load expectation) is the headline score: expected shortfall events per year, with 0.1 days per year as the standard, one bad day per decade. EUE (expected unserved energy) is the depth gauge: megawatt-hours of shortfall, so long deep failures weigh more than brief ones.
The simulation replays decades of weather against the accredited fleet, hour by hour, drawing plant failures from PJM's published outage tables. Days where available capacity falls below demand count toward LOLE; the missing energy counts toward EUE.
The packet stores no LOLE history. The "LOLE over time" series is produced by solving each vintage's input deck (2025/26, 2026/27, 2027/28, 2028/29 all ship in the packet) with the engine.
PJM sizes reliability for the whole system; the auction buys for only part of it.
Two different rulers run through every number on this site. PJM's Reserve Requirement Study models the whole system: all load, all machines, one requirement set at 0.1 loss-of-load days per year. The Base Residual Auction then buys for only part of that system, because utilities serving 7 to 8 percent of it self-supply (FRR, the option that lets a utility opt out of the capacity auction and file its own capacity plan): they opt out of the auction and file their own capacity plans, with an obligation set by their share of load. The auction's target is the whole-system requirement minus that obligation.
Year by year, 2025/26 through 2028/29, all PJM-published figures (verified): the whole-system requirement is 144,450.0 / 146,105 / 152,400.2 / 156,012.9 MW; the self-supply obligation is 10,886.4 / 11,585.5 / 11,299.0 / 10,863.8 MW; the auction target is 133,563.6 / 134,519.5 / 141,101.2 / 145,149.1 MW; the auction's share of the system is 92.5 / 92.1 / 92.6 / 93.0 percent.
The model treats self-supply the simple way: the engine's reliability solve never sees it. It re-solves the whole system with winter counted right, exactly the basis PJM itself models; who contracted which megawatt is an allocation applied afterwards, on the auction overlay. Self-supply plans are never re-cleared; their megawatts stand as filed in every counterfactual. When the corrected (smaller) requirement is pushed through the overlay, the auction's target falls by the auction's share of the correction (the delta times the year's share above), and the rest of the relief belongs to the self-supply utilities.
One year worked through, 2026/27. Requirement: 146,105 MW. Self-supply obligation: 11,585.5 MW. Auction target: 134,519.5 MW. The auction cleared 134,310.8 MW on PJM's print, 208.7 MW short of its target. The self-supply plans committed 11,932.9 MW, 347.4 MW more than their obligation. Net: the system ended 138.7 MW above the requirement, PJM's printed "139 MW above", but only because self-supply over-delivered by more than the auction missed.
This is the consequence for every dollar number on the site. The winter corrections credit weatherization at each auction's rate on the mandate's compliance timeline (50 / 60 / 70 / 80 percent by delivery year; cold-dense-air crediting in full every year; the winter-adjustments section below states the phase-in). At those rates they shrink the whole-system requirement by 2,878.8 / 3,396.1 / 4,513.3 / 3,823.9 MW across the four years (MODEL, reliability statements). The auction's demand curve moves by the translated amounts, 2,661.9 / 3,126.8 / 4,178.6 / 3,557.6 MW (derived: each year's fall times its published share). Savings are the full bill change of the re-cleared auction: what the auction actually paid minus what it would have paid. The untranslated correction remains meaningful as the physical winter gap on the backstop walk, a reliability statement, never a dollar basis.
The table of record for this ladder lives on the Reserve Requirement Study tab (System Requirement to Auction Outcome).
The verified four-auction record, its derived exhibits, and the auction axis they share.
The Base Residual Auctions tab carries the record of the four auctions for delivery years 2025/26 through 2028/29. Every cell in the four-auction table traces to a primary source: auction windows and results dates from PJM's posted RPM auction schedule workbooks, prices, cleared megawatts, auction values and new generation + uprates from the four PJM BRA results reports, and the 2026/27 no-cap counterfactual price from the market monitor's published re-solve. The two derived columns state their arithmetic on the exhibit: surplus-to-existing uses the tariff's own competitive-offer construction (default gross avoidable cost rate net of projected energy-and-ancillary revenue), and the real-terms history deflates the monitor's all-in RPM revenue series with CPI-U to constant-2026 dollars.
One exhibit unit carries the per-auction story: the pairing card, a same-axis waterfall beside the year's demand-and-supply geometry. Every pairing draws on the auction axis, the quantity scale of the auction as PJM ran it (RPM only, self-supplied load outside it). A published requirement stated on another scale is translated by the year's axis factor, the ratio of the auction-axis base to the published base; each card's footnotes quote its factor and both bases. The combined costs-and-savings ledger then consolidates the dollar record: what each auction paid (PJM's own column) beside what the winter corrections would have been worth in it, with lever-alone rows that never sum (the two levers share an overlap, counted once).
Consolidated in the August 2026 rebuild: the four traced supply-curve panels with stacked waste bars, the actual-vs-corrected price chart, the re-clearing table and the cap-suppression card all retired; the pairing exhibits and the ledger carry those stories on one axis, and the market monitor's no-cap re-solve price survives as the 2026/27 pairing's footnote.
The two winter corrections, their overlap, and the re-clearing counterfactual.
The model applies two winter adjustments. The cold-air credit recognizes that gas turbines make more power in cold, dense air; PJM applies the winter failure penalty but withholds the matching output. The winterization adjustment counts the freeze protection mandated after the December 2022 storm, which makes units fail less often in exactly the deep-cold hours that set the requirement. Because both fixes clear the same thin set of risk hours, their effects overlap; every exhibit counts the shared stretch once, and the Model Adjustments tab shows the overlap per delivery year.
Weatherization phases in on the mandate's own dates. The federal winterization standard (NERC reliability standard EOP-012) opened its compliance windows in sequence, and each auction is credited with the share of the fleet those windows support by its delivery year (verified against the published compliance dates; rates set 2026-08-14). For 2025/26, the existing-fleet rule (EOP-012 Requirement R3) was enforceable from October 1, 2025, one month before that winter, and a developed corrective plan was legal compliance: 50 percent. For 2026/27, the rule is a year old: 60 percent. For 2027/28, the existing-equipment fixes are past their inferred October 1, 2027 completion ceiling: 70 percent. For 2028/29, only the new-equipment window, open to about October 2029, remains: 80 percent. The September backstop buys resources in service by June 2032, past every window: 90 percent. The backstop's last step is narrative, not numeric: past 80 percent the requirement's response to weatherization is nearly flat, and moving from 80 to 90 changes the backstop residual by only 85 MW. Cold-dense-air crediting is unconditional physics and applies at 100 percent in every year.
The rates set the physics split. Roughly half of each year's correction is cold-air physics that needs no retrofit at all: 49.5 / 49.1 / 52.3 / 45.9 percent of the together shift across 2025/26 to 2028/29 at the years' rates, a 45.9 to 52.3 percent span (44.8 at the backstop's 90 percent; MODEL, engine decompositions at those rates). The rest assumes weatherization at the year's rate.
The modelling counterfactual re-clears each of the four auctions with the winter correction applied: the engine re-solves each vintage's whole-system reliability requirement with the two winter levers on, weatherization at the year's rate (the deltas are MODEL numbers), then each year's actual demand curve moves down by the auction's share of that delta (92 to 93 percent; the rest of the relief belongs to the self-supply utilities) and re-clears against the published facts about that year's supply. The two auctions that cleared short at the cap do not reprice; there the correction shrinks the auction's share of the shortfall that sizes the backstop instead, and the full correction remains stated separately as the physical winter gap: 2,003.3 MW for 2027/28 at its 70 percent rate and 3,007.4 MW for 2028/29 at 80 (2,915.6 MW at the backstop's 90 percent; MODEL, never a dollar basis).
The RBA shortfall bridge: anchors, lever steps, and pricing the close.
The Emergency Auction tab models the Reliability Backstop Auction (RBA) PJM plans for September 2026; its terms are proposed, not filed. The waterfall starts from the requirement implied by the target LOLE, places the committed fleet against it, then walks through the drivers: load additions and the policy levers (winterization, winter capability credit). Winterization defaults to the 2028/29 mandate-timeline rate of 80 percent, and the master card also states the backstop's own 90 percent reading (the winter-adjustments section above states the phase-in). What remains on the drawn bridge is the physical winter gap, a whole-system statement; the auction's own backstop buying nets only its share of the correction (about 93 percent), the procurement headline the master card carries.
All bridge numbers use PJM's current outage-scoring basis (the legacy day mapping); an alternative weather-aligned scoring basis exists in the engine and was not used.
The supply-blend chart answers the follow-on question: to add a given amount of firm capacity, how much nameplate of each class would it take? Working in ELCC terms makes the classes comparable; low-ELCC classes need far more nameplate for the same firm contribution.
Simulated replays of real storms against the modeled fleet.
The event pages take real historical weather, a December cold snap and a July heat wave, and replay them against the 2028/29 fleet. Cold events are the dangerous ones: failures that are independent in summer become correlated in winter, so the system's riskiest hour is not its busiest hour.
This tab is deliberately frozen. Its data is snapshotted, not live, so the showcased events stay stable while the interactive tabs move.
Where the model centers on 2028/29, what the vintage selector runs, and why.
The deep-dive tabs center on one delivery year, 2028/29, the year PJM's planned backstop auction covers, and one fleet: our reconstruction of the committed fleet the auction actually bought (the evidence-weighted central case; the underlying data file keeps its original most-likely-reconstruction.json name).
The Reserve Requirement Study runs wider: a vintage selector on that tab runs each auction's own input deck, 2025/26 through 2028/29, plus a backstop option, the 2028/29 study presented in backstop framing. The backstop walk nets at the backstop's 90 percent weatherization rate on the auction procurement basis; the winter-adjustments section above states the phase-in. Earlier builds carried free fleet-setup controls; those stay set aside so each tab answers one question well instead of many questions vaguely. Alternative fleets remain runnable in the underlying workspace.
Also consciously out: an assumed-clearing-price input. Auction terms are not public, and a price range would have implied precision the inputs do not have.
Every number says what it is: verified, model, or live-rechecked.
Every number on this dashboard carries a tag. VERIFIED: checked against a primary source (PJM published anchors, ELCC class-rating documents, IMM reports). MODEL: an output of our own runs of the shipped engine, directional and assumption-laden. When the optional live engine is on, a LIVE chip marks a value just re-evaluated in this browser; the evidence stays MODEL, the chip only says where it was computed. A live result more than 0.001 LOLE from its precomputed value shows a LIVE≠PRECOMPUTED warning chip instead: a regression signal, never a display choice.
Two further tags exist in the badge system but nothing on the tabs carries them today: FIXTURE (placeholder data, retired when the real series landed) and NOT INDEPENDENTLY RERUN (a source figure we have not reproduced ourselves).
The rule behind the tags: attribute what we inherit, own only what we verify or rerun ourselves.