UAB Single Sign-On — SAML 2.0 Identity Provider
UAB self-publishes a complete SAML 2.0 IdP EntityDescriptor at https://sso.uab.cat/cas/idp/metadata (HTTP 200, text/xml), entityID https://sso.uab.cat/cas/idp, shibmd:Scope sso.uab.cat. It declares separate signing and encryption key descriptors and four SSO bindings — HTTP-POST, HTTP-POST-SimpleSign, HTTP-Redirect and SOAP (ECP) — plus HTTP-POST and HTTP-Redirect single logout. This is the single most complete machine-readable contract in this profile and, unlike the equivalent surface at most institutions in this cohort, it is served from the institution's own infrastructure rather than a managed identity vendor's.