Carnegie Mellon University website screenshot

Carnegie Mellon University

Carnegie Mellon University is a private research university in Pittsburgh, Pennsylvania, ranked 49th in the QS World University Rankings. It operates no central developer portal, no API gateway and no institution-wide developer program — api.cmu.edu and data.cmu.edu do not exist as developer surfaces — but unlike most of this cohort it does genuinely engineer public APIs, in three unrelated units that share no identifier, envelope or error model. The Delphi research group runs the Delphi Epidata API for real-time epidemiological surveillance; the CERT Coordination Center at the Software Engineering Institute runs the Vulnerability Notes API, the machine-readable record of coordinated vulnerability disclosure; and University Libraries self-hosts the Library Publishing Service, five open-access journals behind a REST API and a conformant OAI-PMH 2.0 provider on CMU's own hardware. None of the three publishes an OpenAPI, a changelog on the API host, a status page or a deprecation policy, and both research APIs return errors with HTTP 200. Everything else that carries CMU's name is a tenancy: KiltHub is figshare, Canvas is Instructure, and the eleven figshare-derived contracts this profile held until 2026-08-19 were a vendor's engineering credited to the university.

Carnegie Mellon University publishes 12 APIs on the APIs.io network, including Articles API, Covidcast API, Feeds API, and 9 more. Tagged areas include University, Higher Education, Education, United States, and Private Research University.

The Carnegie Mellon University catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Carnegie Mellon University’s developer surface includes documentation, API reference, authentication, support, engineering blog, code examples, and 35 more developer resources.

42.4/100 developing ▬ flat Agent 32/100 agent ready Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
AccessFree⚡ Free to try
6 APIs
UniversityHigher EducationEducationUnited StatesPrivate Research UniversityResearchEpidemiologyPublic HealthCybersecurityVulnerability DisclosureScholarly PublishingInstitutional RepositoryIdentity FederationOpen AccessOpen Data

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Regulatory Posture applies to this provider. Its tags matched the Education & Research regime, so Regulatory Posture carries 15 points of the composite. If this regime is wrong for your business, say so on your provider repo — the applicability map is public and we will correct it.
Create-or-Update Ergonomics does not apply to this provider. The published contracts declare no write operations, and a read-only API cannot create-or-update. The facet is excluded from this provider's denominator entirely — not scored zero. A reference or data API is not deficient for being unable to upsert.
The six quality facets above are damped to 85 points between them, because the conditional facet above carries the other 15. That is why each facet's contribution is shown against a damped maximum: raising a quality facet moves the composite by 85% of its nominal weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/carnegie-mellon-university: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 16

Individual APIs this provider publishes, each with its own machine-readable definition.

CMU Web Login (Shibboleth SAML 2.0 Identity Provider)

Carnegie Mellon's campus-wide single sign-on identity provider, running Shibboleth on CMU's own host and address space (login.cmu.edu, 128.2.42.22). Its SAML 2.0 metadata is pub...

KiltHub Institutional Repository (figshare) — tenant

KiltHub is Carnegie Mellon's institutional repository for research data and scholarly output. The data, the collections and the DOIs are CMU's; the platform, the API and the OAI...

Canvas LTI 1.3 Advantage (Instructure) — tenant

CMU's learning management system serves an LTI 1.3 / LTI Advantage JWKS at canvas.cmu.edu/api/lti/security/jwks, so the LTI standard is genuinely in play in CMU's teaching envir...

CMU Eats API (ScottyLabs) — student-operated

A public JSON API for Carnegie Mellon dining locations, hours and menus, built and run by ScottyLabs, a CMU student organization, at api.cmueats.com. It exists because CMU's own...

Carnegie Mellon University Covidcast API

COVIDcast real-time indicator signals across geographies.

Carnegie Mellon University Fluview API

US ILINet influenza-like-illness surveillance (CDC FluView).

Carnegie Mellon University Forecasts API

Delphi's own nowcasts and forecasts.

Carnegie Mellon University Issues API

Issues within a journal.

Carnegie Mellon University Journals API

The journals CMU Libraries publishes.

Carnegie Mellon University Meta API

Service metadata and version.

Carnegie Mellon University Oai Pmh API

OAI-PMH 2.0 metadata harvesting provider.

Carnegie Mellon University Preprints API

Preprint repository objects.

Carnegie Mellon University Vendors API

Per-vendor coordination status.

Scroll for all 16

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

FinOps 1

Cost, billing, and metering signals for API financial operations.

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Carnegie Mellon University Context

28 classes · 7 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Carnegie Mellon University API Rules

6 rules · 4 errors 1 warnings 1 info

SPECTRAL

Carnegie Mellon University API Rules

11 rules · 6 errors 3 warnings 2 info

SPECTRAL

JSON Schema 2

Standalone JSON Schema definitions for this provider's data models.

CERT/CC Vulnerability Note

30 properties

JSON SCHEMA

Delphi Epidata response envelope

3 properties

JSON SCHEMA

Examples 6

Example request and response payloads for these APIs.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Carnegie Mellon University Authentication

none/saml · 3 schemes

SECURITY

Carnegie Mellon University Domain Security

TLSv1.2 · HSTS · DNSSEC · DMARC

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Carnegie Mellon University Scopes

OAuth 2.0 · no documented scopes

0 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Carnegie Mellon University Agentic Access

16 operations

16 operations · 0 acting

AGENTIC

Resources

Documentation 3

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 7

Pagination, idempotency, versioning, errors, and events

Scroll for all 7

Build 7

SDKs, sample code, and the tooling you integrate with

Scroll for all 7

Access & Security 4

Authentication, authorization, and security posture

Learn 1

Tutorials, courses, talks, and written guidance

Operate 2

Status, limits, changes, and where to get help

Commercial 5

Pricing, plans, and the legal terms of use

Company 4

The organization behind the API

Other 7

Properties that don't map to a standard resource type

Scroll for all 7

Source (apis.yml)

apis.yml Raw ↑
aid: carnegie-mellon-university
name: Carnegie Mellon University
description: 'Carnegie Mellon University is a private research university in Pittsburgh, Pennsylvania, ranked 49th in the
  QS World University Rankings. It operates no central developer portal, no API gateway and no institution-wide developer
  program — api.cmu.edu and data.cmu.edu do not exist as developer surfaces — but unlike most of this cohort it does genuinely
  engineer public APIs, in three unrelated units that share no identifier, envelope or error model. The Delphi research group
  runs the Delphi Epidata API for real-time epidemiological surveillance; the CERT Coordination Center at the Software Engineering
  Institute runs the Vulnerability Notes API, the machine-readable record of coordinated vulnerability disclosure; and University
  Libraries self-hosts the Library Publishing Service, five open-access journals behind a REST API and a conformant OAI-PMH
  2.0 provider on CMU''s own hardware. None of the three publishes an OpenAPI, a changelog on the API host, a status page
  or a deprecation policy, and both research APIs return errors with HTTP 200. Everything else that carries CMU''s name is
  a tenancy: KiltHub is figshare, Canvas is Instructure, and the eleven figshare-derived contracts this profile held until
  2026-08-19 were a vendor''s engineering credited to the university.'
type: Index
deliveryModel:
  model: unknown
  open_source: unknown
  commercial: true
  callable_host: true
  label: Delivery model not determined — needs a product licence on record
  confidence: low
  source:
  - openapi
  - pricing
  - repository-unlicensed
  generated: '2026-08-28'
  method: derived
accessModel:
  pricing: free
  onboarding: none
  trial: false
  try_now: true
  public: true
  label: Free · No registration
  confidence: high
  source:
  - authentication
  - openapi
  generated: '2026-08-19'
  method: probed
position: Producing
access: Public
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/carnegie-mellon-university.png
url: https://raw.githubusercontent.com/api-evangelist/carnegie-mellon-university/refs/heads/main/apis.yml
tags:
- University
- Higher Education
- Education
- United States
- Private Research University
- Research
- Epidemiology
- Public Health
- Cybersecurity
- Vulnerability Disclosure
- Scholarly Publishing
- Institutional Repository
- Identity Federation
- Open Access
- Open Data
created: '2026-06-03'
modified: '2026-08-19'
specificationVersion: '0.23'
x-type: university
x-category: Private Research University
apis:
- aid: carnegie-mellon-university:web-login-sso
  name: CMU Web Login (Shibboleth SAML 2.0 Identity Provider)
  description: Carnegie Mellon's campus-wide single sign-on identity provider, running Shibboleth on CMU's own host and address
    space (login.cmu.edu, 128.2.42.22). Its SAML 2.0 metadata is publicly readable at the canonical /idp/shibboleth location,
    and it is a registered InCommon — and thereby eduGAIN — entity carrying the Research & Scholarship entity category, which
    is a machine-readable commitment to release a defined attribute bundle to R&S service providers. An authentication service
    for relying service providers, not a data API, and the single most unambiguously institution-operated machine-readable
    surface CMU publishes.
  humanURL: https://www.cmu.edu/computing/services/security/identity-access/authentication/sso-provider.html
  baseURL: https://login.cmu.edu/idp/shibboleth
  tags:
  - Identity Federation
  - Authentication
  - SSO
  - Shibboleth
  - SAML
  - InCommon
  x-operator: institution
  properties:
  - type: Documentation
    url: https://www.cmu.edu/computing/services/security/identity-access/authentication/sso-provider.html
  - type: Metadata
    url: https://mdq.incommon.org/entities/https%3A%2F%2Flogin.cmu.edu%2Fidp%2Fshibboleth
- aid: carnegie-mellon-university:kilthub-figshare-tenant
  name: KiltHub Institutional Repository (figshare) — tenant
  description: KiltHub is Carnegie Mellon's institutional repository for research data and scholarly output. The data, the
    collections and the DOIs are CMU's; the platform, the API and the OAI-PMH endpoint are figshare's. kilthub.cmu.edu is
    a CNAME to FIGSHARE.COM and answers HTTP 202 with an empty body to non-browser clients; its records are harvestable only
    from figshare's own shared host at https://api.figshare.com/v2/oai using set=portal_231, whose Identify response names
    the repository as "figshare". Recorded as a tenant relationship, which is what it is. The eleven figshare-derived contracts
    this repo carried until 2026-08-19 — altmetric/articles/authors/collections/institutions/oauth/other/profiles/projects/symplectic
    — were the same vendor document split by tag and credited to CMU eleven times over. They have been removed; the relationship
    has not.
  humanURL: https://kilthub.cmu.edu/
  baseURL: https://api.figshare.com/v2
  tags:
  - Institutional Repository
  - Research Data
  - Open Access
  - Tenant
  x-operator: tenant
  x-vendor: figshare
  x-vendor-evidence: kilthub.cmu.edu CNAME FIGSHARE.COM (dig, 2026-08-19). OAI-PMH Identify at https://api.figshare.com/v2/oai
    returns repositoryName "figshare"; CMU's content is addressed as set=portal_231.
  properties:
  - type: Documentation
    url: https://kilthub.cmu.edu/
- aid: carnegie-mellon-university:canvas-lti-tenant
  name: Canvas LTI 1.3 Advantage (Instructure) — tenant
  description: CMU's learning management system serves an LTI 1.3 / LTI Advantage JWKS at canvas.cmu.edu/api/lti/security/jwks,
    so the LTI standard is genuinely in play in CMU's teaching environment. It is recorded as a tenancy rather than a CMU
    surface because canvas.cmu.edu is a CNAME to CMU-VANITY.INSTRUCTURE.COM — the LTI implementation, key rotation and contract
    are Instructure's, running under a CMU vanity hostname. The courses and tool deployments behind it are CMU's; the engineering
    is not. Included because the tenancy is a real institutional fact and because it is the only `lti` conformance point on
    a CMU name.
  humanURL: https://canvas.cmu.edu/
  baseURL: https://canvas.cmu.edu/api/lti
  tags:
  - Learning Management
  - LTI
  - Tenant
  x-operator: tenant
  x-vendor: Instructure
  x-vendor-evidence: canvas.cmu.edu CNAME CMU-VANITY.INSTRUCTURE.COM (dig, 2026-08-19).
  properties:
  - type: Documentation
    url: https://canvas.cmu.edu/
- aid: carnegie-mellon-university:cmu-eats-scottylabs
  name: CMU Eats API (ScottyLabs) — student-operated
  description: 'A public JSON API for Carnegie Mellon dining locations, hours and menus, built and run by ScottyLabs, a CMU
    student organization, at api.cmueats.com. It exists because CMU''s own dining surface does not: apps.studentaffairs.cmu.edu/dining/conceptinfo
    is a Blazor Server app whose catch-all route returns the SPA shell with HTTP 200 for every path, including deliberate
    nonsense, so there is no institutional JSON endpoint to call. Recorded as `tenant` rather than `institution` because the
    domain is not CMU''s and no cmu.edu endorsement of the service was found; the data it serves is CMU''s, the software is
    not. The older ScottyLabs host dining.apis.scottylabs.org still answers but its payload now instructs callers to migrate.'
  humanURL: https://cmueats.com/
  baseURL: https://api.cmueats.com/v2
  tags:
  - Campus Life
  - Dining
  - Student Built
  - Tenant
  x-operator: tenant
  x-endorsement: unverified
  properties:
  - type: SourceCode
    url: https://github.com/ScottyLabs
- aid: carnegie-mellon-university:carnegie-mellon-university-articles-api
  name: Carnegie Mellon University Articles API
  description: Published articles.
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - Articles
  tags_raw:
  - articles
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-articles-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
- aid: carnegie-mellon-university:carnegie-mellon-university-covidcast-api
  name: Carnegie Mellon University Covidcast API
  description: COVIDcast real-time indicator signals across geographies.
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - covidcast
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-covidcast-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
- aid: carnegie-mellon-university:carnegie-mellon-university-feeds-api
  name: Carnegie Mellon University Feeds API
  description: Syndication.
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - Feeds
  tags_raw:
  - feeds
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-feeds-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
- aid: carnegie-mellon-university:carnegie-mellon-university-fluview-api
  name: Carnegie Mellon University Fluview API
  description: US ILINet influenza-like-illness surveillance (CDC FluView).
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - fluview
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-fluview-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
- aid: carnegie-mellon-university:carnegie-mellon-university-forecasts-api
  name: Carnegie Mellon University Forecasts API
  description: Delphi's own nowcasts and forecasts.
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - Forecast
  tags_raw:
  - forecasts
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-forecasts-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
- aid: carnegie-mellon-university:carnegie-mellon-university-issues-api
  name: Carnegie Mellon University Issues API
  description: Issues within a journal.
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - Issues
  tags_raw:
  - issues
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-issues-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
- aid: carnegie-mellon-university:carnegie-mellon-university-journals-api
  name: Carnegie Mellon University Journals API
  description: The journals CMU Libraries publishes.
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - Journals
  tags_raw:
  - journals
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-journals-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
- aid: carnegie-mellon-university:carnegie-mellon-university-meta-api
  name: Carnegie Mellon University Meta API
  description: Service metadata and version.
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - Meta
  tags_raw:
  - meta
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-meta-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
- aid: carnegie-mellon-university:carnegie-mellon-university-notes-api
  name: Carnegie Mellon University Notes API
  description: Vulnerability Notes.
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - Notes
  tags_raw:
  - notes
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-notes-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
- aid: carnegie-mellon-university:carnegie-mellon-university-oai-pmh-api
  name: Carnegie Mellon University Oai Pmh API
  description: OAI-PMH 2.0 metadata harvesting provider.
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - OAI-PMH
  tags_raw:
  - oai-pmh
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-oai-pmh-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
- aid: carnegie-mellon-university:carnegie-mellon-university-preprints-api
  name: Carnegie Mellon University Preprints API
  description: Preprint repository objects.
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - Preprints
  tags_raw:
  - preprints
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-preprints-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
- aid: carnegie-mellon-university:carnegie-mellon-university-vendors-api
  name: Carnegie Mellon University Vendors API
  description: Per-vendor coordination status.
  humanURL: https://cmu-delphi.github.io/delphi-epidata/
  baseURL: https://api.delphi.cmu.edu/epidata
  tags:
  - Vendors
  tags_raw:
  - vendors
  properties:
  - type: OpenAPI
    url: openapi/carnegie-mellon-university-vendors-api-openapi.yml
  - type: Documentation
    url: https://cmu-delphi.github.io/delphi-epidata/
  - type: APIReference
    url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
  - type: SourceCode
    url: https://github.com/cmu-delphi/delphi-epidata
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-delphi-epidata-envelope.json
  - type: Documentation
    url: https://certcc.github.io/
  - type: APIReference
    url: https://www.kb.cert.org/vuls/
  - type: SourceCode
    url: https://github.com/CERTCC
  - type: JSONSchema
    url: json-schema/carnegie-mellon-university-cert-vulnerability-note.json
  - type: Documentation
    url: https://lps.library.cmu.edu/
common:
- type: License
  name: MIT
  url: https://github.com/cmu-delphi/delphi-epidata/blob/dev/LICENSE
- type: Website
  url: https://www.cmu.edu/
- type: Documentation
  url: https://cmu-delphi.github.io/delphi-epidata/
- type: Documentation
  url: https://www.kb.cert.org/vuls/
- type: APIReference
  url: https://cmu-delphi.github.io/delphi-epidata/api/README.html
- type: GitHubOrganization
  url: https://github.com/cmu-delphi
- type: GitHubOrganization
  url: https://github.com/CERTCC
- type: SourceCode
  url: https://github.com/cmu-sei
- type: SourceCode
  url: https://github.com/cmu-lib
- type: IdentityFederation
  url: https://login.cmu.edu/idp/shibboleth
- type: IdentityFederation
  url: https://mdq.incommon.org/entities/https%3A%2F%2Flogin.cmu.edu%2Fidp%2Fshibboleth
- type: ResearchRepository
  url: https://lps.library.cmu.edu/
- type: ResearchRepository
  url: https://kilthub.cmu.edu/
- type: LibraryCatalog
  url: https://www.library.cmu.edu/
- type: CourseCatalog
  url: https://enr-apps.as.cmu.edu/open/SOC/SOCServlet
- type: ResearchComputing
  url: https://www.cmu.edu/computing/services/research/
- type: AIPolicy
  url: https://www.cmu.edu/teaching/technology/aitools/
- type: Authentication
  url: https://www.cmu.edu/computing/services/security/identity-access/authentication/sso-provider.html
- type: PrivacyPolicy
  url: https://www.cmu.edu/legal/privacy-notice
- type: TermsOfService
  url: https://www.cmu.edu/legal/
- type: Support
  url: https://www.cmu.edu/computing/support/
- type: Blog
  url: https://www.cmu.edu/news/
- type: Blog
  url: https://insights.sei.cmu.edu/
- type: LinkedIn
  url: https://www.linkedin.com/school/carnegie-mellon-university/
- type: Conformance
  url: conformance/carnegie-mellon-university-education-standards-conformance.yml
- type: Authentication
  url: authentication/carnegie-mellon-university-authentication.yml
- type: OAuthScopes
  url: scopes/carnegie-mellon-university-scopes.yml
- type: ErrorCatalog
  url: errors/carnegie-mellon-university-errors.yml
- type: Lifecycle
  url: lifecycle/carnegie-mellon-university-lifecycle.yml
- type: Vocabulary
  url: vocabulary/carnegie-mellon-university-vocabulary.yml
- type: DataModel
  url: json-ld/carnegie-mellon-university-context.jsonld
- type: Examples
  url: examples/carnegie-mellon-university-delphi-fluview-example.json
- type: Examples
  url: examples/carnegie-mellon-university-cert-vulnerability-note-example.json
- type: Rules
  url: rules/carnegie-mellon-university-rules.yml
- type: Rules
  url: rules/carnegie-mellon-university-jsonschema-spectral-rules.yml
- type: AgenticAccess
  url: agentic-access/carnegie-mellon-university-agentic-access.yml
- type: DomainSecurity
  url: security/carnegie-mellon-university-domain-security.yml
- type: Plans
  url: plans/carnegie-mellon-university-plans-pricing.yml
- type: RateLimits
  url: rate-limits/carnegie-mellon-university-rate-limits.yml
- type: FinOps
  url: finops/carnegie-mellon-university-finops.yml
- type: Review
  url: review.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
x-coverage:
  state: covered
  reason: institution_operated_surfaces_verified
  generated: '2026-08-19'
  method: probed
  detail: 'Seven surfaces were settled by live probe on 2026-08-19 before anything was saved: four institution-operated and
    three tenancies. The operator axis is the whole finding. CMU''s previous profile scored 41.1 with agent readiness 38.9
    — the figshare fingerprint shared by the eight top-scoring universities in the catalog — on eleven tag-split copies of
    one vendor contract for KiltHub. Those were removed, along with twenty derived Postman/OpenCollection files whose every
    request URL was api.figshare.com. What replaced them is smaller and real: the Delphi Epidata API, the CERT/CC Vulnerability
    Notes API at the Software Engineering Institute, and the Library Publishing Service''s REST API and OAI-PMH provider self-hosted
    at 128.2.24.32 inside CMU''s own /16. The CERT/CC surface is a first-time find for this cohort and the cohort audit could
    not have seen it, because it lives on cert.org rather than cmu.edu. Real absences confirmed rather than assumed: api.cmu.edu
    does not resolve; data.cmu.edu redirects to a marketing page; www.cmu.edu/llms.txt and /.well-known/security.txt both
    404; status.cmu.edu does not resolve; no OpenAPI exists for any CMU surface (/epidata/openapi.json, .yaml, /openapi and
    /swagger.json all 404, and no spec file exists in cmu-delphi/delphi-epidata); no deprecation policy exists, demonstrated
    by api.heinz.cmu.edu/courses_api which retired into an HTML page with no notice; and CMU''s own dining application is
    a soft-200 Blazor catch-all that returns the SPA shell for a deliberate nonsense path, which is why the only dining API
    is a student organization''s. Every OpenAPI, schema, ruleset and context in this repo is marked `derived` and attributed
    to API Evangelist, not to Carnegie Mellon University.'
  evidence:
  - url: https://api.delphi.cmu.edu/epidata/version
    status: 200
  - url: https://api.delphi.cmu.edu/epidata/fluview/?regions=nat&epiweeks=202001
    status: 200
  - url: https://kb.cert.org/vuls/api/421644/
    status: 200
  - url: https://kb.cert.org/vuls/api/421644/vendors/
    status: 200
  - url: https://kb.cert.org/vuls/atomfeed/
    status: 200
  - url: https://lps.library.cmu.edu/api/journals/
    status: 200
  - url: https://ncmr.lps.library.cmu.edu/api/oai/?verb=Identify
    status: 200
  - url: https://login.cmu.edu/idp/shibboleth
    status: 200
  - url: https://mdq.incommon.org/entities/https%3A%2F%2Flogin.cmu.edu%2Fidp%2Fshibboleth
    status: 200
  - url: https://api.datacite.org/repositories/cmu.lps
    status: 200
  - url: https://kilthub.cmu.edu/
    status: 202
    note: figshare tenancy; bot challenge, graded live.
  - url: https://canvas.cmu.edu/api/lti/security/jwks
    status: 200
    note: Instructure tenancy.
  - url: https://apps.studentaffairs.cmu.edu/dining/conceptinfo/zzz-nonsense-xyz
    status: 200
    note: Soft-200 negative probe — SPA shell returned for a nonsense path. No API here.
  - url: https://api.cmu.edu/
    status: 0
    note: NXDOMAIN.
  - url: https://www.cmu.edu/llms.txt
    status: 404
  - url: https://api.crossref.org/members?query=carnegie+mellon
    status: 200
    note: total-results 0 — CMU is not a Crossref member.
  removed: 10
  removed_detail: Ten figshare-derived OpenAPIs plus their _original, and twenty derived collection files, all attributed
    to a vendor host.

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/carnegie-mellon-university"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/carnegie-mellon-university/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/carnegie-mellon-university/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.