PennKey Identity Provider — SAML 2.0 / Shibboleth Metadata
Penn's Shibboleth identity provider publishes a signed SAML 2.0 EntityDescriptor at a well-known location (HTTP 200, application/xml, entityID https://idp.pennkey.upenn.edu/idp/shibboleth), carrying the Shibboleth metadata extension namespace and an embedded X.509 signing certificate. The same entity resolves live through InCommon MDQ as application/samlmetadata+xml, which makes federation membership verifiable rather than self-asserted. This is machine-readable infrastructure the institution itself operates, and it is the strongest institution-owned surface in this profile.
Other Resources
x-saml-metadata
https://idp.pennkey.upenn.edu/idp/shibboleth
x-federation-entry
https://mdq.incommon.org/entities/https%3A%2F%2Fidp.pennkey.upenn.edu%2Fidp%2Fshibboleth
x-conformance
https://raw.githubusercontent.com/api-evangelist/university-of-pennsylvania/refs/heads/main/conformance/university-of-pennsylvania-conformance.yml
x-authentication
https://raw.githubusercontent.com/api-evangelist/university-of-pennsylvania/refs/heads/main/authentication/university-of-pennsylvania-authentication.yml
x-lifecycle
https://raw.githubusercontent.com/api-evangelist/university-of-pennsylvania/refs/heads/main/lifecycle/university-of-pennsylvania-lifecycle.yml