McGill University Authentication Service — Shibboleth SAML 2.0 Identity Provider
McGill's SAML 2.0 identity provider and the only machine-readable surface in this profile that McGill itself operates. The federation metadata document at /idp/shibboleth is served unauthenticated (HTTP 200, application/xml, 8,995 bytes on 2026-08-30) and publishes signing and encryption keys, bilingual mdui:UIInfo display names, the mcgill.ca scope, and every SingleSignOnService and SingleLogoutService binding the IdP supports. This is an identity edge, not a data API — and it is exactly the surface class universities operate and catalogs routinely miss.