RWTH Single Sign-On (OAuth2 / OpenID Connect / Shibboleth)
The RWTH IT Center operates the central Single Sign-On at sso.rwth-aachen.de, offering OAuth2 and OpenID Connect for web and mobile application authorization (Device, Implicit, and Refresh grants) as well as Shibboleth/SAML2 federated authentication via the DFN-AAI federation. Application registration is handled through the OAuth2 Management Interface. Verified 2026-08-30: the IdP serves an XML-DSig signed SAML 2.0 EntitiesDescriptor (entityID https://login.rz.rwth-aachen.de/shibboleth) and an OpenID Connect discovery document (issuer https://sso.rwth-aachen.de). The previously recorded pointer https://oauth.campus.rwth-aachen.de/ was REMOVED: the host resolves to 134.130.66.33 but resets the TLS connection from outside the campus network, so it graded dead.