# University of Otago Identity Provider (SAML 2.0 / Shibboleth) — Tuakiri Hosted Login

**Canonical:** https://apis.io/apis/university-of-otago/tuakiri-idp/  
**Provider:** University of Otago — https://apis.io/providers/university-of-otago/  
**Base URL:** https://directory.tuakiri.ac.nz/metadata/tuakiri-metadata-signed.xml  
**Documentation:** https://www.reannz.co.nz/products-and-services/tuakiri/technical-information

University of Otago Identity Provider (SAML 2.0 / Shibboleth) — Tuakiri Hosted Login is one of 5 APIs that [University of Otago](https://apis.io/providers/university-of-otago/) publishes on the [APIs.io](https://apis.io/) network. Tagged areas include Identity Federation, Shibboleth, SAML, Tuakiri, and REANNZ. The published artifact set on APIs.io includes API documentation and authentication docs.

Otago's SAML 2.0 identity is published as a complete IDPSSODescriptor in the SIGNED Tuakiri NZ Access Federation metadata aggregate, under entityID https://idp.otago.ac.nz/idp/shibboleth with DisplayName "The University of Otago". Confirmed live 2026-08-30: the aggregate returns 200 and 725,866 bytes covering 82 entities, of which two mention Otago. The operator finding is the useful one and it was not previously recorded: Otago owns the entityID, but all six advertised endpoint bindings — SAML2 Redirect/POST/POST-SimpleSign for both SSO and SLO — resolve to hosted-login.tuakiri.ac.nz/hosting/otago.ac.nz/idp/..., which is REANNZ's Tuakiri Hosted Login service (tuakiri-hostedidp-ha.reannz.co.nz). Otago holds the federation identity; REANNZ runs the software. Note also that idp.otago.ac.nz does not exist in DNS — a SAML entityID is a name, not an address, and must not be read as a callable Otago host. This is browser-mediated SSO, not a self-service API: a bare GET to the Redirect/SSO binding returns 500 because it carries no AuthnRequest, which is expected and is not a fault.

## Machine-readable artifacts (5)

- **Documentation** — https://docs.tuakiri.ac.nz/
- **BaseURL** — https://directory.tuakiri.ac.nz/metadata/tuakiri-metadata-signed.xml
- **Examples** — https://raw.githubusercontent.com/api-evangelist/university-of-otago/refs/heads/main/examples/university-of-otago-saml-idp-metadata.xml
- **Conformance** — https://raw.githubusercontent.com/api-evangelist/university-of-otago/refs/heads/main/conformance/university-of-otago-education-standards.yml
- **Authentication** — https://ask.otago.ac.nz/knowledgebase/article/KA-10002700/en-us

## Other University of Otago APIs (4)

- [Artificial Intelligence at Otago — WordPress REST API](https://apis.io/apis/university-of-otago/ai-site-wp-rest/)
- [OUR Archive OAI-PMH Metadata — Ex Libris Esploro tenancy](https://apis.io/apis/university-of-otago/our-archive-oai/)
- [Blackboard Learn — University of Otago tenancy](https://apis.io/apis/university-of-otago/blackboard-learn/)
- [Otago Scholarly Identifier Registrations (DataCite + Crossref)](https://apis.io/apis/university-of-otago/scholarly-identifiers/)

## Tags

Identity Federation, Shibboleth, SAML, Tuakiri, REANNZ, Single Sign-On, Tenant

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/university-of-otago/tuakiri-idp/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/university-of-otago/.
