# Carnegie Mellon University

**Canonical:** https://apis.io/providers/carnegie-mellon-university/  
**Website:** https://www.cmu.edu/  
**APIs profiled:** 7

Carnegie Mellon University is a private research university in Pittsburgh, Pennsylvania, ranked 49th in the QS World University Rankings. It operates no central developer portal, no API gateway and no institution-wide developer program — api.cmu.edu and data.cmu.edu do not exist as developer surfaces — but unlike most of this cohort it does genuinely engineer public APIs, in three unrelated units that share no identifier, envelope or error model. The Delphi research group runs the Delphi Epidata API for real-time epidemiological surveillance; the CERT Coordination Center at the Software Engineering Institute runs the Vulnerability Notes API, the machine-readable record of coordinated vulnerability disclosure; and University Libraries self-hosts the Library Publishing Service, five open-access journals behind a REST API and a conformant OAI-PMH 2.0 provider on CMU's own hardware. None of the three publishes an OpenAPI, a changelog on the API host, a status page or a deprecation policy, and both research APIs return errors with HTTP 200. Everything else that carries CMU's name is a tenancy: KiltHub is figshare, Canvas is Instructure, and the eleven figshare-derived contracts this profile held until 2026-08-19 were a vendor's engineering credited to the university.

## Kin Score — 41.7 / 100 (developing)

Scored 2026-08-21 under rubric 0.12.0. Trend: flat (+0.4 from 41.3).

| Facet | Score |
|---|---|
| Discoverability | 74.1 |
| Contract Quality | 24.3 |
| Governance | 17.4 |
| Contract Governance | 17.4 |
| Operational Transparency | 26.3 |
| Developer Ergonomics | 35.7 |
| Commercial Clarity | 50.0 |
| Access Clarity | 50.0 |

Regulatory layer — **Education & Research**: 64.8 (matched via tags).

## Agent readiness — 38.5 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | no |
| MCP Server | no |
| Auth Clarity | yes |
| Idempotency | no |
| Error Semantics | documented |
| OpenAPI Examples | verified |
| Rate Limit Signal | documented |
| Event Surface Described | no |
| Agent Skills | no |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |

## Access

Free · No registration — onboarding: unknown, pricing: free, trial: no (confidence: high).

## APIs (7)

- **Delphi Epidata API** — Public, anonymously accessible HTTP/JSON API operated by the Delphi research group at Carnegie Mellon University, serving real-time and historical epidemiological surveillance d...
- **CERT/CC Vulnerability Notes API** — Public read API for the CERT Coordination Center's Vulnerability Notes database, operated by the CERT Division of the Software Engineering Institute — a federally funded researc...
- **CMU Library Publishing Service API + OAI-PMH** — REST API and conformant OAI-PMH 2.0 provider for the Carnegie Mellon University Library Publishing Service, the open-access publishing programme run by University Libraries. Exp...
- **CMU Web Login (Shibboleth SAML 2.0 Identity Provider)** — Carnegie Mellon's campus-wide single sign-on identity provider, running Shibboleth on CMU's own host and address space (login.cmu.edu, 128.2.42.22). Its SAML 2.0 metadata is pub...
- **KiltHub Institutional Repository (figshare) — tenant** — KiltHub is Carnegie Mellon's institutional repository for research data and scholarly output. The data, the collections and the DOIs are CMU's; the platform, the API and the OAI...
- **Canvas LTI 1.3 Advantage (Instructure) — tenant** — CMU's learning management system serves an LTI 1.3 / LTI Advantage JWKS at canvas.cmu.edu/api/lti/security/jwks, so the LTI standard is genuinely in play in CMU's teaching envir...
- **CMU Eats API (ScottyLabs) — student-operated** — A public JSON API for Carnegie Mellon dining locations, hours and menus, built and run by ScottyLabs, a CMU student organization, at api.cmueats.com. It exists because CMU's own...

## Agentic access (1)

- **Carnegie Mellon University Agentic Access** — 16 operations

## Security (2)

- **Carnegie Mellon University Authentication** — none/saml · 3 schemes
- **Carnegie Mellon University Domain Security** — TLSv1.2 · HSTS · DNSSEC · DMARC

## Plans (1)

- **Carnegie Mellon University Plans Pricing**

## Tags

University, Higher Education, Education, United States, Private Research University, Research, Epidemiology, Public Health, Cybersecurity, Vulnerability Disclosure, Scholarly Publishing, Institutional Repository, Identity Federation, Open Access, Open Data

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/carnegie-mellon-university/). Scores are computed from the provider's own public artifacts under a published rubric.
