Queen's University Shibboleth Identity Provider (SAML 2.0 Metadata)
Queen's runs its own Shibboleth Identity Provider and publishes SAML 2.0 IdP metadata as application/xml at a stable, unauthenticated URL on its own registrable domain. The EntityDescriptor carries entityID https://login.queensu.ca/idp/shibboleth and a shibmd:Scope of queensu.ca. This is the single most substantive machine-readable surface Queen's operates itself: it is the credential authority every federated Queen's service resolves to, including its repository tenants, whose REST APIs advertise `shibboleth realm="DSpace REST API"` and redirect to this IdP. Consumed by relying parties and federation operators, not by general developers — there is no self-service registration.