Columbia Identity — Shibboleth IdP and CAS

Columbia University Information Technology operates the university's own identity infrastructure: a production Shibboleth Identity Provider publishing signed SAML 2.0 metadata anonymously under the InCommon entityID urn:mace:incommon:columbia.edu, and a CAS server handling browser single sign-on with UNI credentials and MFA. The metadata is the most substantial machine-readable artifact Columbia publishes about itself — two X.509 key descriptors, four SSO endpoints, three SAML bindings, a declared scope of columbia.edu and a logout handoff to CAS. It is readable by anyone and actionable by nobody outside the university: relying parties are registered by CUIT and there is no public or dynamic registration. No OpenID Connect discovery document is published.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/identity"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

API entry from apis.yml

apis.yml Raw ↑
aid: columbia:identity
name: Columbia Identity — Shibboleth IdP and CAS
description: 'Columbia University Information Technology operates the university''s own identity infrastructure:
  a production Shibboleth Identity Provider publishing signed SAML 2.0 metadata anonymously under the
  InCommon entityID urn:mace:incommon:columbia.edu, and a CAS server handling browser single sign-on with
  UNI credentials and MFA. The metadata is the most substantial machine-readable artifact Columbia publishes
  about itself — two X.509 key descriptors, four SSO endpoints, three SAML bindings, a declared scope
  of columbia.edu and a logout handoff to CAS. It is readable by anyone and actionable by nobody outside
  the university: relying parties are registered by CUIT and there is no public or dynamic registration.
  No OpenID Connect discovery document is published.'
humanURL: https://www.cuit.columbia.edu/web-authentication-federation
baseURL: https://shibboleth.columbia.edu/idp
tags:
- Identity
- Identity Federation
- Authentication
- SAML
- Shibboleth
- CAS
- InCommon
- SSO
properties:
- type: IdentityFederation
  url: identity-federation/columbia-identity-federation.yml
- type: Authentication
  url: authentication/columbia-authentication.yml
- type: Conformance
  url: conformance/columbia-conformance.yml
- type: Documentation
  url: https://www.cuit.columbia.edu/shibboleth
- type: Documentation
  url: https://www.cuit.columbia.edu/cas-authentication
- type: Signup
  url: https://www.cuit.columbia.edu/cas-authentication/registration
x-operator: institution
x-operator-evidence: shibboleth.columbia.edu -> 128.59.105.181 and cas.columbia.edu -> 128.59.105.39,
  both in Columbia University address space, under a TLS certificate subject O=Columbia University, CN=*.columbia.edu
  issued by InCommon RSA OV SSL CA 3. The metadata document self-describes as "Columbia Shibboleth idp
  production instance metadata".
x-access: public
x-status: 200 application/xml, probed 2026-08-19