UGM Shibboleth SAML 2.0 Identity Provider

UGM's own Shibboleth Identity Provider, entityID https://sso.ugm.ac.id/idp/shibboleth, publishing an unsigned SAML EntityDescriptor from the university's own host — retrieved live on 2026-09-01 (200, 6379 bytes, application/xml) and saved to this repo. Advertises SAML 2.0, SAML 1.1 and the native Shibboleth 1.0 authn profile over HTTP-Redirect, HTTP-POST and HTTP-POST-SimpleSign, with SOAP artifact resolution, three single-logout bindings, and a separate AttributeAuthority- Descriptor exposing SAML 1.0 and SAML 2.0 SOAP AttributeQuery. Institution-operated by definition. Two findings are recorded honestly: shibmd:Scope is declared as "ac.id" — the whole Indonesian academic namespace — rather than "ugm.ac.id", and the entity is NOT present in the eduGAIN aggregate (10,616 entities checked 2026-09-01), so the IdP is self-published rather than inter-federated. It is also not a developer API: no application can obtain an assertion without being registered as a service provider.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/shibboleth-idp"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

API entry from apis.yml

apis.yml Raw ↑
aid: gadjah-mada-university:shibboleth-idp
name: UGM Shibboleth SAML 2.0 Identity Provider
description: 'UGM''s own Shibboleth Identity Provider, entityID https://sso.ugm.ac.id/idp/shibboleth,
  publishing an unsigned SAML EntityDescriptor from the university''s own host — retrieved live on 2026-09-01
  (200, 6379 bytes, application/xml) and saved to this repo. Advertises SAML 2.0, SAML 1.1 and the native
  Shibboleth 1.0 authn profile over HTTP-Redirect, HTTP-POST and HTTP-POST-SimpleSign, with SOAP artifact
  resolution, three single-logout bindings, and a separate AttributeAuthority- Descriptor exposing SAML
  1.0 and SAML 2.0 SOAP AttributeQuery. Institution-operated by definition. Two findings are recorded
  honestly: shibmd:Scope is declared as "ac.id" — the whole Indonesian academic namespace — rather than
  "ugm.ac.id", and the entity is NOT present in the eduGAIN aggregate (10,616 entities checked 2026-09-01),
  so the IdP is self-published rather than inter-federated. It is also not a developer API: no application
  can obtain an assertion without being registered as a service provider.'
humanURL: https://sso.ugm.ac.id/
baseURL: https://sso.ugm.ac.id/idp/profile/Metadata/SAML
tags:
- Identity
- SSO
- SAML
- Shibboleth
- Federation
properties:
- type: IdentityFederation
  url: https://sso.ugm.ac.id/idp/profile/Metadata/SAML
- type: Authentication
  url: authentication/gadjah-mada-university-authentication.yml
- type: x-saml-metadata
  url: authentication/gadjah-mada-university-saml-idp-metadata.xml
- type: Conformance
  url: conformance/gadjah-mada-university-conformance.yml
x-operator: institution
x-operator-evidence: 'The EntityDescriptor is served from sso.ugm.ac.id, a host under the institution''s
  own registrable domain, and its entityID is https://sso.ugm.ac.id/idp/shibboleth. Deliberately classed
  `institution` rather than `federation`: the federation class describes metadata carried by a federation
  operator (mdq.incommon.org, mdq.ukfederation.org.uk, metadata.surfconext.nl), and this entity is absent
  from the eduGAIN aggregate and self-published from UGM''s own host. Calling it federated would assert
  an inter-federation membership that the probe disproved. The surface class is identity federation; the
  operator is the institution alone.'
x-entity-id: https://sso.ugm.ac.id/idp/shibboleth
x-sso-endpoint: https://sso.ugm.ac.id/idp/profile/SAML2/Redirect/SSO
x-scope: ac.id
x-probe:
  baseURL_status: 200
  baseURL_bytes: 6379
  entity_id_url_status: 200
  edugain_present: false
  edugain_checked: https://technical.edugain.org/api.php?action=list_entities&format=json — 10616 entities,
    no ugm.ac.id entity
  probed: '2026-09-01'