HY Login Service — Shibboleth IdP + OpenID Connect
The University's identity provider at login.helsinki.fi, machine-readable twice over. SAML: GET /idp/shibboleth returns an EntityDescriptor with entityID https://login.helsinki.fi/shibboleth, an IDPSSODescriptor and shibmd:Scope helsinki.fi; the federation-signed copy sits in the Haka aggregate alongside fifteen helsinki.fi service providers, interfederated through eduGAIN. OIDC: /.well-known/openid-configuration returns a full discovery document — issuer https://login.helsinki.fi, endpoints under /idp/profile/oidc/, scopes openid, profile, email, groups, offline_access — releasing eduPerson, SCHAC and funetEduPerson claims alongside local hy* claims. Identity federation is the surface class universities operate by definition and almost never catalogue.