USC Shibboleth Identity Provider (SAML 2.0 Metadata)
USC's production single sign-on identity provider, operated by USC Information Technology Services on USC's own host, publishing its SAML 2.0 metadata unauthenticated. GET https://shibboleth.usc.edu/idp/shibboleth returns 200 application/xml, 17,096 bytes, titled "USC Metadata" with Name="usc-idp-metadata" and validUntil 2028-04-06. The EntitiesDescriptor carries an IDPSSODescriptor for entityID https://shibboleth.usc.edu/shibboleth-idp supporting SAML 2.0, SAML 1.1 and Shibboleth 1.0, with shibmd:Scope usc.edu and an X509 certificate issued to O=University of Southern California, OU=Information Technology Services. USC's federation registration resolves independently through InCommon's metadata query service as entityID urn:mace:incommon:usc.edu (200, 13,035 bytes of signed metadata), binding SSO to /idp/profile/SAML2/POST/SSO, /POST-SimpleSign/SSO and /Redirect/SSO on shibboleth.usc.edu and artifact resolution to shibboleth.usc.edu:8444. https://my.usc.edu/ redirects into this IdP, confirming it is the live login path and not a stale entry. This is machine-readable, institution-operated and unambiguously USC's own — it is the strongest programmable surface USC publishes.