# Tsinghua University Identity Provider — SAML 2.0 Federation Metadata

**Canonical:** https://apis.io/apis/tsinghua/identity-federation/  
**Provider:** Tsinghua University — https://apis.io/providers/tsinghua/  
**Base URL:** https://idp.tsinghua.edu.cn  
**Documentation:** https://idp.tsinghua.edu.cn/idp/shibboleth

Tsinghua University Identity Provider — SAML 2.0 Federation Metadata is one of 4 APIs that [Tsinghua University](https://apis.io/providers/tsinghua/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. Tagged areas include Identity Federation, Shibboleth, SAML, Single Sign-On, and Metadata. The published artifact set on APIs.io includes an OpenAPI specification and authentication docs.

Tsinghua operates its own Shibboleth Identity Provider and publishes machine-readable SAML 2.0 metadata about it at a public, unauthenticated URL on its own domain. The document declares entityID https://idp.tsinghua.edu.cn/idp/shibboleth, a Shibboleth shibmd:Scope of tsinghua.edu.cn, an IDPSSODescriptor advertising SAML 2.0, SAML 1.1 and urn:mace:shibboleth:1.0, four SingleSignOnService and four SingleLogoutService bindings, two ArtifactResolutionService endpoints and an AttributeAuthorityDescriptor with SOAP attribute query on port 8443. This is the surface class a university operates by definition, and it is the one where Tsinghua is stronger than several of its better-ranked peers in this cohort: every SSO and SLO location resolves to a Tsinghua host, so the institution runs the SAML service itself rather than fronting it with OpenAthens or a federation operator. The corresponding human-facing login estate (id.tsinghua.edu.cn, with an OAuth-shaped /thu-oauth/callback) publishes no client registration, scope list or discovery document, so the federation metadata is the only part of the identity estate an outside party can read. Gaps recorded honestly: the metadata carries no validUntil, no cacheDuration and no XML signature, so relying parties have no published refresh interval and no tamper check.

## Machine-readable artifacts (6)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/tsinghua/refs/heads/main/openapi/tsinghua-identity-federation-api-openapi.yml
- **Metadata** — https://raw.githubusercontent.com/api-evangelist/tsinghua/refs/heads/main/examples/tsinghua-idp-saml-metadata.xml
- **Conformance** — https://raw.githubusercontent.com/api-evangelist/tsinghua/refs/heads/main/conformance/tsinghua-conformance.yml
- **Authentication** — https://raw.githubusercontent.com/api-evangelist/tsinghua/refs/heads/main/authentication/tsinghua-authentication.yml
- **Vocabulary** — https://raw.githubusercontent.com/api-evangelist/tsinghua/refs/heads/main/vocabulary/tsinghua-identity-federation-vocabulary.yml
- **Lifecycle** — https://raw.githubusercontent.com/api-evangelist/tsinghua/refs/heads/main/lifecycle/tsinghua-lifecycle.yml

## Other Tsinghua University APIs (3)

- [Tsinghua University TUNA Open Source Mirror](https://apis.io/apis/tsinghua/tsinghua-mirror-status-api/)
- [Tsinghua University DataCite DOI Registration and Resolution](https://apis.io/apis/tsinghua/datacite-doi/)
- [Tsinghua University GitLab](https://apis.io/apis/tsinghua/gitlab/)

## Tags

Identity Federation, Shibboleth, SAML, Single Sign-On, Metadata

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/tsinghua/identity-federation/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/tsinghua/.
