Brown University Identity Provider (Shibboleth / SAML 2.0)
Brown's Shibboleth identity provider, and the strongest machine-readable contract in this profile. Brown self-publishes signed per-entity SAML metadata at the entityID itself — uncommon; most institutions leave that to the federation aggregate — and the same entity appears in InCommon's signed MDQ service, flowing on into eduGAIN. Declares HTTP-POST, HTTP-Redirect, POST-SimpleSign and Shibboleth AuthnRequest SSO bindings, a SOAP attribute authority, a shibmd:Scope of brown.edu, and four entity categories including InCommon and REFEDS Research & Scholarship and REFEDS Sirtfi, backed by a dedicated security contact. It is browser SSO: it grants no API credentials, and there is no OAuth server, token endpoint or OIDC discovery document anywhere on Brown's surface.