TU Dresden Identity Provider (Shibboleth SAML 2.0 + OpenID Connect)

The university's own Shibboleth identity provider, operated by ZIH, and the surface class this pipeline exists to surface: institution-operated by definition, fully machine-readable, and almost never catalogued. The SAML 2.0 metadata document at /idp/shibboleth carries an IDPSSODescriptor with four SingleSignOnService bindings — HTTP-POST, HTTP-POST-SimpleSign, HTTP-Redirect and SOAP ECP on port 8443 — plus four signing and encryption KeyDescriptors. REFEDS MET confirms the entity is exported from DFN-AAI into eduGAIN and republished by the InCommon, SWAMID and UK Access Management federations, and that it holds both the REFEDS Research and Scholarship entity category and SIRTFI. The same IdP now also speaks OpenID Connect, correcting the June 2026 profile which recorded OIDC as planned but unavailable: /.well-known/openid-configuration returns issuer https://idp.tu-dresden.de, response_types [code], grant_types [authorization_code], scopes [openid], four token-endpoint auth methods including private_key_jwt, and claims_supported carrying the eduPerson set — eduPersonPrincipalName, eduPersonScopedAffiliation, eduPersonAssurance and eduPersonEntitlement. /idp/profile/oidc/keyset serves a three-key JWKS.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/sso-shibboleth"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

API entry from apis.yml

apis.yml Raw ↑
aid: tu-dresden:sso-shibboleth
name: TU Dresden Identity Provider (Shibboleth SAML 2.0 + OpenID Connect)
x-operator: institution
x-operator-evidence: Every endpoint in the published metadata is on idp.tu-dresden.de — the four SAML
  SSO bindings, the OIDC authorization, token and userinfo endpoints, and the JWKS. The entity is registered
  by DFN-AAI (registrationAuthority https://www.aai.dfn.de, registrationInstant 2021-04-21), declares
  shibmd:Scope tu-dresden.de, and carries mdui display names and an OrganizationURL of http://www.tu-dresden.de
  with contacts informationssicherheit@tu-dresden.de and servicedesk@tu-dresden.de. Unlike the hosted
  federation proxies common in this cohort, TU Dresden runs the software.
description: 'The university''s own Shibboleth identity provider, operated by ZIH, and the surface class
  this pipeline exists to surface: institution-operated by definition, fully machine-readable, and almost
  never catalogued. The SAML 2.0 metadata document at /idp/shibboleth carries an IDPSSODescriptor with
  four SingleSignOnService bindings — HTTP-POST, HTTP-POST-SimpleSign, HTTP-Redirect and SOAP ECP on port
  8443 — plus four signing and encryption KeyDescriptors. REFEDS MET confirms the entity is exported from
  DFN-AAI into eduGAIN and republished by the InCommon, SWAMID and UK Access Management federations, and
  that it holds both the REFEDS Research and Scholarship entity category and SIRTFI. The same IdP now
  also speaks OpenID Connect, correcting the June 2026 profile which recorded OIDC as planned but unavailable:
  /.well-known/openid-configuration returns issuer https://idp.tu-dresden.de, response_types [code], grant_types
  [authorization_code], scopes [openid], four token-endpoint auth methods including private_key_jwt, and
  claims_supported carrying the eduPerson set — eduPersonPrincipalName, eduPersonScopedAffiliation, eduPersonAssurance
  and eduPersonEntitlement. /idp/profile/oidc/keyset serves a three-key JWKS.'
humanURL: https://idp.tu-dresden.de/docu/
baseURL: https://idp.tu-dresden.de/idp/shibboleth
tags:
- Identity Federation
- Authentication
- SSO
- SAML
- Shibboleth
- OpenID Connect
- eduGAIN
properties:
- type: Documentation
  url: https://idp.tu-dresden.de/docu/
- type: Authentication
  url: authentication/tu-dresden-authentication.yml
- type: OpenIDConnectDiscovery
  url: https://idp.tu-dresden.de/.well-known/openid-configuration
- type: PrivacyPolicy
  url: https://idp.tu-dresden.de/dataprivacy
- type: Conformance
  url: conformance/tu-dresden-education-standards.yml