DTU Identity Federation (SAML 2.0 / WS-Federation / OpenID Connect)
DTU operates its own security token service at sts.ait.dtu.dk (Microsoft AD FS) and publishes signed SAML 2.0 metadata and an OpenID Connect discovery document, both openly and without authentication. The IdP entityID http://sts.ait.dtu.dk/adfs/services/trust is registered in WAYF, the Danish national identity federation, and through WAYF in eduGAIN, with schacHomeOrganization dtu.dk and scopes dtu.dk and guest.dtu.dk. This is DTU's own engineering on DTU's own host — the clearest institution-operated machine-readable surface DTU publishes. Relying-party registration is not self-service and requires institutional affiliation.