Enterprise Single Sign-On (WSO2 Identity Server)

The university self-hosts a WSO2 Identity Server at auth-eis.vuw.ac.nz — no CNAME, resolving directly to 130.195.13.55 inside the institution's own address space — and it is the SAML issuer that fronts the student records system. Discovered on 2026-08-30 by following the sign-on redirect from studentrecords.vuw.ac.nz, which arrives at /samlsso with a signed SAMLRequest and RelayState /c/auth/SSB, and returns a login page carrying WSO2's Apache-2.0 copyright header. This is the university's third distinct identity surface and its second institution-operated one, separate from the Shibboleth IdP used for research federation and from the Microsoft Entra ID tenant used for student-facing browser sign-on. Every machine-readable endpoint WSO2 normally exposes — OIDC discovery, SAML2 metadata, SCIM 2.0 ServiceProviderConfig, the SOAP admin services — returns HTTP 403 from a web application firewall that echoes a signature ID and the caller's IP. THAT IS A FINDING, NOT AN ABSENCE: the host is live and the endpoints are protected, so no conformance is claimed for any of them.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/enterprise-sso-wso2"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.

API entry from apis.yml

apis.yml Raw ↑
aid: victoria-university-of-wellington:enterprise-sso-wso2
name: Enterprise Single Sign-On (WSO2 Identity Server)
x-operator: institution
description: 'The university self-hosts a WSO2 Identity Server at auth-eis.vuw.ac.nz — no CNAME, resolving
  directly to 130.195.13.55 inside the institution''s own address space — and it is the SAML issuer that
  fronts the student records system. Discovered on 2026-08-30 by following the sign-on redirect from studentrecords.vuw.ac.nz,
  which arrives at /samlsso with a signed SAMLRequest and RelayState /c/auth/SSB, and returns a login
  page carrying WSO2''s Apache-2.0 copyright header. This is the university''s third distinct identity
  surface and its second institution-operated one, separate from the Shibboleth IdP used for research
  federation and from the Microsoft Entra ID tenant used for student-facing browser sign-on. Every machine-readable
  endpoint WSO2 normally exposes — OIDC discovery, SAML2 metadata, SCIM 2.0 ServiceProviderConfig, the
  SOAP admin services — returns HTTP 403 from a web application firewall that echoes a signature ID and
  the caller''s IP. THAT IS A FINDING, NOT AN ABSENCE: the host is live and the endpoints are protected,
  so no conformance is claimed for any of them.'
humanURL: https://www.wgtn.ac.nz/students/tools-and-help
baseURL: https://auth-eis.vuw.ac.nz/
tags:
- Identity
- Single Sign-On
- SAML
- WSO2
- Self-Hosted
- Institution-Operated
tags_raw:
- Identity
- Single Sign-On
- SAML
- WSO2
- Self Hosted
- Institution Operated
properties:
- type: x-authentication
  url: authentication/victoria-university-of-wellington-authentication.yml
- type: Website
  url: https://studentrecords.vuw.ac.nz/