UGM Single Sign-On (CAS)
Central Authentication Service at sso.ugm.ac.id/cas, the login surface UGM systems redirect users to. A bare GET redirects to /cas/login and returns the login form (200, verified 2026-09-01). CAS defines a machine-readable /serviceValidate response, but UGM publishes no service-registration route, no protocol documentation and no developer-facing contract for it, so it is recorded as an authentication surface rather than as an API. It sits alongside, not behind, the OAuth server and the Shibboleth IdP — three institution-operated identity stacks.