Maastricht University Identity Provider (ADFS / SURFconext / eduGAIN)
Maastricht University runs its own identity provider on login.maastrichtuniversity.nl and publishes two machine-readable discovery documents without authentication: an OpenID Connect configuration (issuer https://login.maastrichtuniversity.nl/adfs, ten advertised scopes, JWKS, RS256) and signed SAML 2.0 federation metadata served as application/samlmetadata+xml. The same entityID appears in SURFconext's national IdP metadata with shibmd scopes maastrichtuniversity.nl and unimaas.nl, which places it in eduGAIN. This is the one surface class universities operate by definition and almost never appears in an API catalog. Client registration is not self-service; relying-party trusts are provisioned by UM ICT Services.