Keio Okta Tenant — OpenID Connect
Keio runs an Okta tenant at keio.okta.com behind its campus applications; gslbs.keio.jp redirects an anonymous request into a SAML authentication request against it. The tenant's OpenID Connect discovery document is anonymously readable and advertises authorization, token, userinfo, JWKS and client-registration endpoints. The tenant, the users and the applications are Keio's; the identity service, its contract and its engineering are Okta's, and the discovery document is the one Okta publishes for every org — so Okta's contract is deliberately not saved under this institution. Readable, but not consumable: a client_id exists only if Keio IT creates one.