# Enterprise Single Sign-On (WSO2 Identity Server)

**Canonical:** https://apis.io/apis/victoria-university-of-wellington/enterprise-sso-wso2/  
**Provider:** Victoria University of Wellington — https://apis.io/providers/victoria-university-of-wellington/  
**Base URL:** https://auth-eis.vuw.ac.nz/  
**Documentation:** https://www.wgtn.ac.nz/students/tools-and-help

Enterprise Single Sign-On (WSO2 Identity Server) is one of 10 APIs that [Victoria University of Wellington](https://apis.io/providers/victoria-university-of-wellington/) publishes on the [APIs.io](https://apis.io/) network. Tagged areas include Identity, Single Sign-On, SAML, WSO2, and Self-Hosted.

The university self-hosts a WSO2 Identity Server at auth-eis.vuw.ac.nz — no CNAME, resolving directly to 130.195.13.55 inside the institution's own address space — and it is the SAML issuer that fronts the student records system. Discovered on 2026-08-30 by following the sign-on redirect from studentrecords.vuw.ac.nz, which arrives at /samlsso with a signed SAMLRequest and RelayState /c/auth/SSB, and returns a login page carrying WSO2's Apache-2.0 copyright header. This is the university's third distinct identity surface and its second institution-operated one, separate from the Shibboleth IdP used for research federation and from the Microsoft Entra ID tenant used for student-facing browser sign-on. Every machine-readable endpoint WSO2 normally exposes — OIDC discovery, SAML2 metadata, SCIM 2.0 ServiceProviderConfig, the SOAP admin services — returns HTTP 403 from a web application firewall that echoes a signature ID and the caller's IP. THAT IS A FINDING, NOT AN ABSENCE: the host is live and the endpoints are protected, so no conformance is claimed for any of them.

## Machine-readable artifacts (2)

- **x-authentication** — https://raw.githubusercontent.com/api-evangelist/victoria-university-of-wellington/refs/heads/main/authentication/victoria-university-of-wellington-authentication.yml
- **Website** — https://studentrecords.vuw.ac.nz/

## Other Victoria University of Wellington APIs (9)

- [Website Global Object](https://apis.io/apis/victoria-university-of-wellington/website-global-object/)
- [Shibboleth Identity Provider (Tuakiri / eduGAIN)](https://apis.io/apis/victoria-university-of-wellington/identity-federation/)
- [Institutional Repository (self-hosted DSpace)](https://apis.io/apis/victoria-university-of-wellington/institutional-repository/)
- [Open Access Repository (Figshare tenancy)](https://apis.io/apis/victoria-university-of-wellington/open-access-repository-figshare/)
- [Te Waharoa Library Discovery (Ex Libris Primo / Alma tenancy)](https://apis.io/apis/victoria-university-of-wellington/te-waharoa-discovery/)
- [Nuku Learning Management (Instructure Canvas tenancy)](https://apis.io/apis/victoria-university-of-wellington/nuku-canvas-lms/)
- [Research Information System (Symplectic Elements tenancy)](https://apis.io/apis/victoria-university-of-wellington/symplectic-elements/)
- [Student Records (Ellucian Banner Self-Service tenancy)](https://apis.io/apis/victoria-university-of-wellington/student-records-banner/)
- [Microsoft Entra ID Tenant (production browser sign-on)](https://apis.io/apis/victoria-university-of-wellington/entra-id-federation/)

## Tags

Identity, Single Sign-On, SAML, WSO2, Self-Hosted, Institution-Operated

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/victoria-university-of-wellington/enterprise-sso-wso2/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/victoria-university-of-wellington/.
