WashU Shibboleth Identity Provider (InCommon)
Washington University's own SAML 2.0 identity provider, entityID https://login.wustl.edu/idp/shibboleth, published as signed metadata through the InCommon per-entity metadata query service. The document carries an IDPSSODescriptor and an AttributeAuthorityDescriptor, HTTP-POST and HTTP-Redirect SingleSignOnService endpoints under login.wustl.edu, a shibmd:Scope of wustl.edu, and two opt-in assurance commitments the institution chose to make — the REFEDS Research & Scholarship entity category and SIRTFI incident-response certification. login.wustl.edu resolves to idm3-loginprod.g.wustl.edu, inside WashU's own network. A federation is shared by definition; the IdP behind this entry is not, and it is the strongest institution-operated machine-readable surface WashU has.