UCSF Identity Provider (Shibboleth / InCommon)

UCSF's Shibboleth SAML 2.0 identity provider, registered in the InCommon Federation and re-exported to eduGAIN. Signed, versioned, publicly retrievable federation metadata describing SingleSignOnService and SingleLogoutService endpoints at dp.ucsf.edu across HTTP-Redirect, HTTP-POST, HTTP-POST-SimpleSign and the Shibboleth 1.0 AuthnRequest binding, with shibmd:Scope ucsf.edu declarations, an AttributeAuthorityDescriptor and an SPSSODescriptor. UCSF serves the metadata itself at https://dp.ucsf.edu/idp/shibboleth and InCommon redistributes a signed copy. This is the most standards-conformant machine-readable artifact UCSF publishes, and it is the education regime's `saml` and `shibboleth` domain standards in one document. UCSF separately fronts interactive login with Okta at login.ucsf.edu; the federated entity remains dp.ucsf.edu. Verified live 2026-08-19.

API entry from apis.yml

apis.yml Raw ↑
aid: ucsf:incommon-idp
name: UCSF Identity Provider (Shibboleth / InCommon)
x-operator: institution
x-operator-evidence: A SAML identity provider is institution-operated by definition — the entity asserts
  UCSF's own users. UCSF self-publishes the metadata on its own host, https://dp.ucsf.edu/idp/shibboleth
  (an EntitiesDescriptor named https://ucsf-federation.edu/metadata/myaccess-ucsf.xml, carrying entityIDs
  urn:mace:incommon:ucsf.edu and https://dp.ucsf.edu/idp/shibboleth, with shibmd:Scope ucsf.edu). The
  InCommon MDQ service redistributes a signed copy; the running IdP is UCSF's.
description: UCSF's Shibboleth SAML 2.0 identity provider, registered in the InCommon Federation and re-exported
  to eduGAIN. Signed, versioned, publicly retrievable federation metadata describing SingleSignOnService
  and SingleLogoutService endpoints at dp.ucsf.edu across HTTP-Redirect, HTTP-POST, HTTP-POST-SimpleSign
  and the Shibboleth 1.0 AuthnRequest binding, with shibmd:Scope ucsf.edu declarations, an AttributeAuthorityDescriptor
  and an SPSSODescriptor. UCSF serves the metadata itself at https://dp.ucsf.edu/idp/shibboleth and InCommon
  redistributes a signed copy. This is the most standards-conformant machine-readable artifact UCSF publishes,
  and it is the education regime's `saml` and `shibboleth` domain standards in one document. UCSF separately
  fronts interactive login with Okta at login.ucsf.edu; the federated entity remains dp.ucsf.edu. Verified
  live 2026-08-19.
humanURL: https://it.ucsf.edu/
baseURL: https://dp.ucsf.edu/idp/shibboleth
tags:
- Identity Federation
- SAML
- Shibboleth
- InCommon
- eduGAIN
- Authentication
properties:
- type: Authentication
  url: authentication/ucsf-authentication.yml
- type: Metadata
  url: authentication/ucsf-idp-self-published-metadata.xml
- type: Metadata
  url: authentication/ucsf-incommon-saml-metadata.xml
- type: IdentityFederation
  url: https://mdq.incommon.org/entities/urn%3Amace%3Aincommon%3Aucsf.edu
- type: Conformance
  url: conformance/ucsf-education-standards-conformance.yml