UCL

UCL Identity Provider — UK Access Management Federation

UCL is a registered Identity Provider in the UK Access Management Federation (Jisc), and by extension in eduGAIN. Its SAML metadata is published in the federation's machine-readable aggregate under entityID https://shib-idp.ucl.ac.uk/shibboleth, carrying OrganizationDisplayName 'UCL (University College London)', a Shibboleth shibmd:Scope of ucl.ac.uk, and a registrationInstant of 2009-12-04. This is the surface class a university is supposed to operate by definition, and UCL is the case that complicates the rule: the SingleSignOnService locations in UCL's own federation metadata do not point at any UCL host, they point at login.openathens.net/saml/2/sso/ucl.ac.uk/c/ukfed. The entityID, the scope and the federation membership are UCL's; the SAML service is operated by OpenAthens on an institution-specific path, so the operator is recorded as tenant rather than institution.

API entry from apis.yml

apis.yml Raw ↑
aid: ucl:identity-federation
name: UCL Identity Provider — UK Access Management Federation
description: 'UCL is a registered Identity Provider in the UK Access Management Federation (Jisc), and
  by extension in eduGAIN. Its SAML metadata is published in the federation''s machine-readable aggregate
  under entityID https://shib-idp.ucl.ac.uk/shibboleth, carrying OrganizationDisplayName ''UCL (University
  College London)'', a Shibboleth shibmd:Scope of ucl.ac.uk, and a registrationInstant of 2009-12-04.
  This is the surface class a university is supposed to operate by definition, and UCL is the case that
  complicates the rule: the SingleSignOnService locations in UCL''s own federation metadata do not point
  at any UCL host, they point at login.openathens.net/saml/2/sso/ucl.ac.uk/c/ukfed. The entityID, the
  scope and the federation membership are UCL''s; the SAML service is operated by OpenAthens on an institution-specific
  path, so the operator is recorded as tenant rather than institution.'
humanURL: https://www.ukfederation.org.uk/
baseURL: http://metadata.ukfederation.org.uk/ukfederation-metadata.xml
tags:
- Identity Federation
- Shibboleth
- SAML
- eduGAIN
- Single Sign-On
properties:
- type: Documentation
  url: https://www.ukfederation.org.uk/
- type: Conformance
  url: conformance/ucl-education-standards-conformance.yml
x-operator: tenant
x-operator-evidence: entityID is under ucl.ac.uk and the federation registration is UCL's own, but IDPSSODescriptor/SingleSignOnService
  resolves to login.openathens.net, not to a UCL host. shib-idp.ucl.ac.uk does not resolve to a reachable
  service (it is an identifier, not an endpoint).
x-vendor: OpenAthens (Jisc / EBSCO)
x-probe:
  url: http://metadata.ukfederation.org.uk/ukfederation-metadata.xml
  status: 200
  note: 11,113 entities scanned; exactly one UCL IdP entity found
  checked: '2026-08-19'