Pitt Passport (Shibboleth SAML 2.0 Identity Provider)

The University of Pittsburgh's campus-wide single sign-on identity provider. Its SAML 2.0 metadata is publicly readable at the canonical Shibboleth /idp/shibboleth location, declares the shibmd namespace and asserts pitt.edu, with OrganizationName "University of Pittsburgh" and four contacts at pitt.edu. It is a registered InCommon — and thereby eduGAIN — entity, and InCommon's MDQ service returns a signed EntityDescriptor for it with a machine-readable validUntil. An authentication service for relying service providers, not a data API, and the surface that makes the shibboleth and saml conformance hits in this repository real. Discovered 2026-08-30 and absent from the June 2026 profile.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/pitt-passport-idp"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

API entry from apis.yml

apis.yml Raw ↑
aid: university-of-pittsburgh:pitt-passport-idp
name: Pitt Passport (Shibboleth SAML 2.0 Identity Provider)
description: The University of Pittsburgh's campus-wide single sign-on identity provider. Its SAML 2.0
  metadata is publicly readable at the canonical Shibboleth /idp/shibboleth location, declares the shibmd
  namespace and asserts <shibmd:Scope>pitt.edu</shibmd:Scope>, with OrganizationName "University of Pittsburgh"
  and four contacts at pitt.edu. It is a registered InCommon — and thereby eduGAIN — entity, and InCommon's
  MDQ service returns a signed EntityDescriptor for it with a machine-readable validUntil. An authentication
  service for relying service providers, not a data API, and the surface that makes the shibboleth and
  saml conformance hits in this repository real. Discovered 2026-08-30 and absent from the June 2026 profile.
humanURL: https://passport.pitt.edu
baseURL: https://passport.pitt.edu/idp/shibboleth
tags:
- Identity Federation
- Authentication
- SSO
- Shibboleth
- SAML
- InCommon
x-operator: institution
x-operator-evidence: entityID https://passport.pitt.edu/idp/shibboleth is under Pitt's own registrable
  domain; the metadata's OrganizationName and OrganizationDisplayName are "University of Pittsburgh";
  its four ContactPerson entries are helpdesk@pitt.edu, ric@pitt.edu and abj@pitt.edu; its asserted scope
  is pitt.edu; and it is registered in InCommon as Pitt's entity. Federation membership is an institution-operated
  fact by definition.
x-operator-caveat: 'Hosting may be outsourced even though the entity is not, and the cohort audit disagrees
  with the verdict recorded above. Run with --resolve, audit-university-contracts.py grades this surface
  `tenant`, because passport.pitt.edu CNAMEs to pitt.idaccessmanage.com (35.167.61.51, 44.233.206.84)
  — an institution-specific subdomain on a registrable domain that is not pitt.edu, which is the mechanical
  definition of a tenancy. Both verdicts are recorded here rather than one of them being suppressed. `institution`
  is kept because everything the surface says about itself is Pitt''s — entityID, OrganizationName, all
  four contacts, the asserted scope, the InCommon registration and the TLS certificate (CN=passport.pitt.edu,
  issued by Amazon) — and because idaccessmanage.com could not be shown to be a shared vendor platform:
  it is registered through Amazon Registrar, serves nothing at its apex, and of eleven likely institutional
  subdomains probed on 2026-08-30 only `pitt.` resolved, so the cohort-derived vendor test that governs
  this pipeline does not fire. A reader who weighs the CNAME above the metadata should read this surface
  as `tenant`; the evidence for both readings is above.'
properties:
- type: Metadata
  url: https://passport.pitt.edu/idp/shibboleth
- type: Metadata
  url: https://mdq.incommon.org/entities/https%3A%2F%2Fpassport.pitt.edu%2Fidp%2Fshibboleth
- type: Examples
  url: examples/university-of-pittsburgh-pitt-passport-saml-metadata.xml