# CWRU Shibboleth Identity Provider (SAML 2.0 metadata)

**Canonical:** https://apis.io/apis/case-western-reserve-university/shibboleth-idp/  
**Provider:** Case Western Reserve University — https://apis.io/providers/case-western-reserve-university/  
**Base URL:** https://mdq.incommon.org/entities/urn%3Amace%3Aincommon%3Acase.edu  
**Documentation:** https://case.edu/utech/departments/information-security

CWRU Shibboleth Identity Provider (SAML 2.0 metadata) is one of 9 APIs that [Case Western Reserve University](https://apis.io/providers/case-western-reserve-university/) publishes on the [APIs.io](https://apis.io/) network. Tagged areas include Identity Federation, Shibboleth, SAML, InCommon, and eduGAIN. The published artifact set on APIs.io includes authentication docs.

CWRU's own Shibboleth Identity Provider, entityID urn:mace:incommon:case.edu. Every SingleSignOnService binding in the production descriptor is on CWRU's own registrable domain — https://login.case.edu/idp/profile/SAML2/Redirect/SSO, .../POST/SSO and .../POST-SimpleSign/SSO — and the descriptor asserts nine shibmd:Scope values, all case.edu subdomains (case.edu, artsci, dental, engineering, law, management, med, nursing, sass). The metadata is distributed unauthenticated through the InCommon per-entity metadata service (MDQ), registrationAuthority https://incommon.org, validUntil 2026-09-15. canvas.case.edu was observed redirecting into this IdP. This is the strongest institution-operated, machine-readable contract CWRU publishes. Caveat worth knowing: CWRU's own metadata URL https://login.case.edu/idp/shibboleth answers 200 but serves a stale DEV descriptor (entityID https://login-dev.case.edu/idp, "Still using old keypairs - fine for dev for now"), so the MDQ copy is the authoritative one.

## Machine-readable artifacts (4)

- **Authentication** — https://raw.githubusercontent.com/api-evangelist/case-western-reserve-university/refs/heads/main/authentication/case-western-reserve-university-authentication.yml
- **Conformance** — https://raw.githubusercontent.com/api-evangelist/case-western-reserve-university/refs/heads/main/conformance/case-western-reserve-university-domain-standards.yml
- **Website** — https://login.case.edu/
- **APIsJSON** — https://raw.githubusercontent.com/api-evangelist/case-western-reserve-university/refs/heads/main/apis.yml

## Other Case Western Reserve University APIs (8)

- [CWRU Apereo CAS single sign-on (login.case.edu)](https://apis.io/apis/case-western-reserve-university/apereo-cas/)
- [Scholarly Commons @ CWRU — OAI-PMH 2.0 provider](https://apis.io/apis/case-western-reserve-university/scholarly-commons-oai-pmh/)
- [CWRU Microsoft Entra ID tenant (OIDC + SAML metadata)](https://apis.io/apis/case-western-reserve-university/entra-id-tenant/)
- [Crossref member registration — Case Western Reserve University (member 7530)](https://apis.io/apis/case-western-reserve-university/crossref-member/)
- [ROR organization record — Case Western Reserve University (051fd9666)](https://apis.io/apis/case-western-reserve-university/ror-record/)
- [CWRU Tableau Server deployment (data.case.edu)](https://apis.io/apis/case-western-reserve-university/tableau-server/)
- [CWRU library discovery — Ex Libris Primo view 01OHIOLINK_CWRU:CWRUC](https://apis.io/apis/case-western-reserve-university/primo-discovery-view/)
- [CWRU General Bulletin — Leepfrog CourseLeaf catalog (bulletin.case.edu)](https://apis.io/apis/case-western-reserve-university/courseleaf-bulletin/)

## Tags

Identity Federation, Shibboleth, SAML, InCommon, eduGAIN

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/case-western-reserve-university/shibboleth-idp/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/case-western-reserve-university/.
