MSU Identity Provider (Shibboleth / SAML 2.0)
MSU's federated single sign-on. The Shibboleth Identity Provider publishes SAML 2.0 metadata unauthenticated at idp.idm.msu.edu/idp/shibboleth — verified live on 2026-08-30, returning an md:EntityDescriptor with entityID urn:mace:incommon:msu.edu and an IDPSSODescriptor supporting urn:oasis:names:tc:SAML:2.0:protocol. This is institution-operated by definition and is a genuinely machine-readable surface, but it is not an onboardable API: obtaining assertions requires a registered service provider in InCommon plus an MSU NetID, i.e. institutional affiliation rather than a developer credential.