IKEN Moodle LMS — web services and LTI 1.3 platform
IISc's own learning management system, a self-hosted Moodle branded "IKEN" at courses.iisc.ac.in, exposing two machine surfaces verified live 2026-09-01. The LTI 1.3 Advantage platform endpoints are public — GET /mod/lti/certs.php returns 200 application/json with a real JWKS (RSA, RS256, kid ffa71c7514f167fc08f4) and /mod/lti/auth.php returns 200 — which makes this a genuine, evidenced IMS LTI conformance surface on the institution's own domain. The Moodle web-services REST endpoint at /webservice/rest/server.php is live and token-gated, returning 200 application/json {"exception":"moodle_exception","errorcode":"invalidtoken"} to a keyless call, and /lib/ajax/service.php returns a structured Moodle JSON error. No token is issued to the public, so no payload could be read and no contract has been generated to stand in for one: the Moodle web-services contract is Moodle's product contract, shared by every deployment, and belongs in Moodle's own repo rather than here. The deployment, the host and the courses are IISc's.