# Shibboleth Identity Provider (SAML 2.0 metadata)

**Canonical:** https://apis.io/apis/university-of-sydney/identity-federation/  
**Provider:** University of Sydney — https://apis.io/providers/university-of-sydney/  
**Base URL:** https://federation.sydney.edu.au/idp/  
**Documentation:** https://federation.sydney.edu.au/idp/shibboleth

Shibboleth Identity Provider (SAML 2.0 metadata) is one of 7 APIs that [University of Sydney](https://apis.io/providers/university-of-sydney/) publishes on the [APIs.io](https://apis.io/) network. Tagged areas include Identity Federation, SAML, Shibboleth, eduGAIN, and AAF. The published artifact set on APIs.io includes authentication docs.

The University of Sydney's federation entity serves signed SAML 2.0 metadata from federation.sydney.edu.au: entityID https://federation.sydney.edu.au/idp/shibboleth, an IDPSSODescriptor advertising urn:oasis:names:tc:SAML:2.0:protocol, the Shibboleth metadata extension shibmd:Scope=sydney.edu.au, an idp-signing.crt key the institution issued itself in 2018, and Redirect, POST and POST-SimpleSign SingleSignOnService bindings. The entity appears in the Australian Access Federation aggregate as "The University of Sydney" and in the eduGAIN interfederation aggregate. Operator is TENANT, not institution, and the DNS says so: federation.sydney.edu.au CNAMEs to d007b274d34f1a4319cafeaf6941cfa7.idp-cname.aaf.edu.au and answers from CloudFront + an AWS ALB running Jetty 12.1.0 under an Amazon-issued certificate — the AAF Rapid IdP hosted identity service, not university-run infrastructure. The federation membership, the entityID, the scope and the signing key are the university's; the running software is AAF's. This is still the only openly machine-readable artifact served under a University of Sydney hostname, and it is not consumable by third-party developers — relying parties must be registered service providers in AAF or eduGAIN.

## Machine-readable artifacts (3)

- **Authentication** — https://raw.githubusercontent.com/api-evangelist/university-of-sydney/refs/heads/main/authentication/university-of-sydney-authentication.yml
- **Conformance** — https://raw.githubusercontent.com/api-evangelist/university-of-sydney/refs/heads/main/conformance/university-of-sydney-education-standards.yml
- **APIsJSON** — https://raw.githubusercontent.com/api-evangelist/university-of-sydney/refs/heads/main/apis.yml

## Other University of Sydney APIs (6)

- [Sydney eScholarship Repository (institutional repository, OAI-PMH)](https://apis.io/apis/university-of-sydney/escholarship-repository/)
- [CUSP — Course & Unit of Study Portal](https://apis.io/apis/university-of-sydney/cusp-course-catalog/)
- [myUni Student Portal (session-gated internal APIs)](https://apis.io/apis/university-of-sydney/myuni/)
- [api.sydney.edu.au — MuleSoft Anypoint gateway (not publicly reachable)](https://apis.io/apis/university-of-sydney/anypoint-gateway/)
- [Library Discovery — Ex Libris Primo VE / Alma (tenant)](https://apis.io/apis/university-of-sydney/primo-alma/)
- [Canvas LMS (tenant)](https://apis.io/apis/university-of-sydney/canvas-lms/)

## Tags

Identity Federation, SAML, Shibboleth, eduGAIN, AAF, Rapid IdP, Tenant, Authentication

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/university-of-sydney/identity-federation/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/university-of-sydney/.
