Columbia Identity — Shibboleth IdP and CAS

Columbia University Information Technology operates the university's own identity infrastructure: a production Shibboleth Identity Provider publishing signed SAML 2.0 metadata anonymously under the InCommon entityID urn:mace:incommon:columbia.edu, and a CAS server handling browser single sign-on with UNI credentials and MFA. The metadata is the most substantial machine-readable artifact Columbia publishes about itself — two X.509 key descriptors, four SSO endpoints, three SAML bindings, a declared scope of columbia.edu and a logout handoff to CAS. It is readable by anyone and actionable by nobody outside the university: relying parties are registered by CUIT and there is no public or dynamic registration. No OpenID Connect discovery document is published.

API entry from apis.yml

apis.yml Raw ↑
aid: columbia:identity
name: Columbia Identity — Shibboleth IdP and CAS
description: 'Columbia University Information Technology operates the university''s own identity infrastructure:
  a production Shibboleth Identity Provider publishing signed SAML 2.0 metadata anonymously under the
  InCommon entityID urn:mace:incommon:columbia.edu, and a CAS server handling browser single sign-on with
  UNI credentials and MFA. The metadata is the most substantial machine-readable artifact Columbia publishes
  about itself — two X.509 key descriptors, four SSO endpoints, three SAML bindings, a declared scope
  of columbia.edu and a logout handoff to CAS. It is readable by anyone and actionable by nobody outside
  the university: relying parties are registered by CUIT and there is no public or dynamic registration.
  No OpenID Connect discovery document is published.'
humanURL: https://www.cuit.columbia.edu/web-authentication-federation
baseURL: https://shibboleth.columbia.edu/idp
tags:
- Identity
- Identity Federation
- Authentication
- SAML
- Shibboleth
- CAS
- InCommon
- SSO
properties:
- type: IdentityFederation
  url: identity-federation/columbia-identity-federation.yml
- type: Authentication
  url: authentication/columbia-authentication.yml
- type: Conformance
  url: conformance/columbia-conformance.yml
- type: Documentation
  url: https://www.cuit.columbia.edu/shibboleth
- type: Documentation
  url: https://www.cuit.columbia.edu/cas-authentication
- type: Signup
  url: https://www.cuit.columbia.edu/cas-authentication/registration
x-operator: institution
x-operator-evidence: shibboleth.columbia.edu -> 128.59.105.181 and cas.columbia.edu -> 128.59.105.39,
  both in Columbia University address space, under a TLS certificate subject O=Columbia University, CN=*.columbia.edu
  issued by InCommon RSA OV SSL CA 3. The metadata document self-describes as "Columbia Shibboleth idp
  production instance metadata".
x-access: public
x-status: 200 application/xml, probed 2026-08-19