Columbia University website screenshot

Columbia University

Columbia University is a private Ivy League research university in New York City, ranked seventeenth in the QS World University Rankings. Its programmable footprint is small, real, and almost entirely invisible from the outside. Columbia operates exactly one publicly consumable, unauthenticated API of its own: the Columbia University Libraries Hours API at hours.library.columbia.edu, two read operations returning JSON with CORS enabled, built on Columbia's own openly published Rails codebase and documented by nobody. Alongside it the university runs a production Shibboleth Identity Provider that publishes signed SAML 2.0 metadata under the InCommon entityID urn:mace:incommon:columbia.edu, mints DOIs under its own DataCite prefix 10.7916 across 1.1 million registered identifiers, deposits into Crossref as member 6984, and releases the entire CLIO library catalogue as CC0 MARCXML bulk extracts. That is the whole of it. The Open Data Service that Columbia describes as its developer-facing service is gated behind a UNI login, and the IRI/LDEO Climate Data Library now redirects its data paths to a login form. Columbia publishes no OpenAPI, no developer portal reachable without affiliation, no changelog, no llms.txt and no API terms, and it reserves the hostname api.library.columbia.edu while serving nothing but a placeholder there. Most consequentially for machine access, Columbia defends its estate with two different anti-bot products: a Cloudflare managed challenge across the central web estate, and an Anubis proof-of-work challenge in front of the Libraries' entire discovery layer — the CLIO catalogue, Academic Commons and GeoData — which returns HTTP 200 with a bot-check body and made the institution's OAI-PMH endpoint unverifiable. Learning management runs on Instructure's Canvas and the research data platform on Redivis; both are tenant relationships, recorded as such and scored against their vendors.

Columbia University publishes 1 API on the APIs.io network: Libraries Hours API. Tagged areas include University, Higher Education, Education, Ivy League, and Private Research University.

The Columbia University catalog on APIs.io includes 1 JSON-LD context and 1 Spectral governance ruleset.

Columbia University’s developer surface includes authentication, code examples, and 26 more developer resources.

40.9/100 developing ▲ 17.5 Agent 48/100 agent ready Full breakdown ↓
scored 2026-08-20 · rubric v0.12.0
AccessFree⚡ Free to try
10 APIs
UniversityHigher EducationEducationIvy LeaguePrivate Research UniversityUnited StatesNew YorkIdentity FederationLibraryOpen DataResearch RepositoryResearch DataCourse CatalogCampus Life

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-20 · rubric v0.12.0
Composite quality — 40.9/100 · developing
Contract Quality 14.6 / 21
Developer Ergonomics 3.6 / 17
Access Clarity 4.9 / 17
Operational Transparency 2.9 / 11
Contract Governance 0.4 / 10
Discoverability 5.5 / 9
Regulatory Posture 7.5 / 15
Agent readiness — 48/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
Documented Reversibility 0 / 6
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Regulatory Posture applies to this provider. Its tags matched the Education & Research regime, so Regulatory Posture carries 15 points of the composite. If this regime is wrong for your business, say so on your provider repo — the applicability map is public and we will correct it.
The six quality facets above are damped to 85 points between them, because the conditional facet above carries the other 15. That is why each facet's contribution is shown against a damped maximum: raising a quality facet moves the composite by 85% of its nominal weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/columbia: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 10

Individual APIs this provider publishes, each with its own machine-readable definition.

Columbia University Libraries Hours API

The only institution-operated, publicly consumable, unauthenticated API found anywhere in Columbia University's estate. Two read operations: which library locations are open rig...

Columbia Identity — Shibboleth IdP and CAS

Columbia University Information Technology operates the university's own identity infrastructure: a production Shibboleth Identity Provider publishing signed SAML 2.0 metadata a...

CLIO Library Catalog Open Data

Columbia University Libraries publishes its full catalogue — bibliographic and holdings records from the integrated library system behind CLIO — as gzipped MARCXML bulk extracts...

Columbia Open Data Service

The central university service publishing data feeds to software developers in programming-friendly formats such as JSON and XML — the course directory, the CLIO library catalog...

CU Directory of Classes

The public web directory of Columbia University class offerings, browsable by subject, department, semester, instruction method, weekday and start time. Live and fully readable,...

Columbia Academic Commons

Columbia University's institutional research repository, holding the scholarly output, theses and research data of the university. Unusually for this cohort it is NOT a vendor t...

Digital Library Collections and the 10.7916 DOI namespace

Columbia University Libraries' digital collections platform and the resolution target for Columbia's own DOI namespace. Columbia is a registered DataCite repository client (CUL....

IRI/LDEO Climate Data Library

The Climate Data Library run by the International Research Institute for Climate and Society and the Lamont-Doherty Earth Observatory, both Columbia University units. A long-run...

CourseWorks (Instructure Canvas)

Columbia's learning management system. The REST API is live and returns a well-structured JSON 401 to unauthenticated callers, and the LTI 1.3 tool-platform JWKS is publicly rea...

Columbia University Data Platform (Redivis)

Columbia's research data platform runs on Redivis as an institution-specific tenancy, and the university has registered two distinct DataCite repository clients against it — CUL...

Scroll for all 10

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Columbia Rate Limits

1 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Columbia Context

8 classes · 3 properties

JSON-LD

Spectral Rules 1

Spectral governance rulesets for linting and validating these APIs.

Columbia University API Rules

0 rules ·

SPECTRAL

JSON Schema 1

Standalone JSON Schema definitions for this provider's data models.

Examples 7

Example request and response payloads for these APIs.

Scroll for all 7

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Columbia Authentication

6 schemes

SECURITY

Columbia Domain Security

TLSv1.3 · DMARC

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

Columbia Scopes

OAuth 2.0 · no documented scopes

0 scopes

SCOPES

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Columbia Agentic Access

0 operations

0 operations · 0 acting

AGENTIC

Resources

Get Started 1

Portal, sign-up, and the first successful call

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 4

SDKs, sample code, and the tooling you integrate with

Access & Security 4

Authentication, authorization, and security posture

Learn 1

Tutorials, courses, talks, and written guidance

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 4

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: columbia
name: Columbia University
description: 'Columbia University is a private Ivy League research university in New York City, ranked seventeenth in the
  QS World University Rankings. Its programmable footprint is small, real, and almost entirely invisible from the outside.
  Columbia operates exactly one publicly consumable, unauthenticated API of its own: the Columbia University Libraries Hours
  API at hours.library.columbia.edu, two read operations returning JSON with CORS enabled, built on Columbia''s own openly
  published Rails codebase and documented by nobody. Alongside it the university runs a production Shibboleth Identity Provider
  that publishes signed SAML 2.0 metadata under the InCommon entityID urn:mace:incommon:columbia.edu, mints DOIs under its
  own DataCite prefix 10.7916 across 1.1 million registered identifiers, deposits into Crossref as member 6984, and releases
  the entire CLIO library catalogue as CC0 MARCXML bulk extracts. That is the whole of it. The Open Data Service that Columbia
  describes as its developer-facing service is gated behind a UNI login, and the IRI/LDEO Climate Data Library now redirects
  its data paths to a login form. Columbia publishes no OpenAPI, no developer portal reachable without affiliation, no changelog,
  no llms.txt and no API terms, and it reserves the hostname api.library.columbia.edu while serving nothing but a placeholder
  there. Most consequentially for machine access, Columbia defends its estate with two different anti-bot products: a Cloudflare
  managed challenge across the central web estate, and an Anubis proof-of-work challenge in front of the Libraries'' entire
  discovery layer — the CLIO catalogue, Academic Commons and GeoData — which returns HTTP 200 with a bot-check body and made
  the institution''s OAI-PMH endpoint unverifiable. Learning management runs on Instructure''s Canvas and the research data
  platform on Redivis; both are tenant relationships, recorded as such and scored against their vendors.'
type: Index
accessModel:
  pricing: free
  onboarding: none
  trial: false
  try_now: true
  public: true
  label: Partly open, mostly affiliation-gated
  confidence: high
  source:
  - plans
  - authentication
  - agentic-access
  generated: '2026-08-19'
  method: probed
position: Consumer
access: 3rd-Party
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/columbia.png
url: https://raw.githubusercontent.com/api-evangelist/columbia/refs/heads/main/apis.yml
tags:
- University
- Higher Education
- Education
- Ivy League
- Private Research University
- United States
- New York
- Identity Federation
- Library
- Open Data
- Research Repository
- Research Data
- Course Catalog
- Campus Life
created: '2026-06-03'
modified: '2026-08-19'
specificationVersion: '0.23'
x-type: university
x-category: Private Research University
apis:
- aid: columbia:library-hours
  name: Columbia University Libraries Hours API
  description: 'The only institution-operated, publicly consumable, unauthenticated API found anywhere in Columbia University''s
    estate. Two read operations: which library locations are open right now, and the posted hours for one location over a
    date or a date range. Returns JSON with Access-Control-Allow-Origin set to *, so it is directly callable from a browser
    or an agent with no key, no registration and no click-through. Columbia publishes no OpenAPI, no reference documentation
    and no changelog for it; the contract in this repository was reverse-engineered from live probes and from Columbia''s
    own openly published application source. Small, undocumented, and genuinely theirs.'
  humanURL: https://hours.library.columbia.edu/
  baseURL: https://hours.library.columbia.edu/api/v1
  tags:
  - Campus Life
  - Library
  - Hours
  - Locations
  - Open Data
  - JSON
  - CORS
  properties:
  - type: OpenAPI
    url: openapi/columbia-library-hours-openapi.yml
  - type: OpenAPI Source
    url: openapi/_original/columbia-library-hours-openapi.yml
  - type: JSONSchema
    url: json-schema/columbia-library-hours-schema.json
  - type: Examples
    url: examples/index.yml
  - type: Errors
    url: errors/columbia-errors.yml
  - type: Rules
    url: rules/columbia-rules.yml
  - type: Vocabulary
    url: vocabulary/columbia-vocabulary.yml
  - type: Authentication
    url: authentication/columbia-authentication.yml
  - type: Lifecycle
    url: lifecycle/columbia-lifecycle.yml
  - type: GitHubRepository
    url: https://github.com/cul/ldpd-hours
  x-operator: institution
  x-operator-evidence: hours.library.columbia.edu resolves to diglib-rails-prod1.cul.columbia.edu / 128.59.222.118, inside
    Columbia University's own address space, under a TLS certificate with subject C=US, ST=New York, O=Columbia University,
    CN=library.columbia.edu issued by InCommon RSA Server CA 2. The application source is published by Columbia University
    Libraries at github.com/cul/ldpd-hours.
  x-access: public
  x-status: 200 application/json, probed 2026-08-19
- aid: columbia:identity
  name: Columbia Identity — Shibboleth IdP and CAS
  description: 'Columbia University Information Technology operates the university''s own identity infrastructure: a production
    Shibboleth Identity Provider publishing signed SAML 2.0 metadata anonymously under the InCommon entityID urn:mace:incommon:columbia.edu,
    and a CAS server handling browser single sign-on with UNI credentials and MFA. The metadata is the most substantial machine-readable
    artifact Columbia publishes about itself — two X.509 key descriptors, four SSO endpoints, three SAML bindings, a declared
    scope of columbia.edu and a logout handoff to CAS. It is readable by anyone and actionable by nobody outside the university:
    relying parties are registered by CUIT and there is no public or dynamic registration. No OpenID Connect discovery document
    is published.'
  humanURL: https://www.cuit.columbia.edu/web-authentication-federation
  baseURL: https://shibboleth.columbia.edu/idp
  tags:
  - Identity
  - Identity Federation
  - Authentication
  - SAML
  - Shibboleth
  - CAS
  - InCommon
  - SSO
  properties:
  - type: IdentityFederation
    url: identity-federation/columbia-identity-federation.yml
  - type: Authentication
    url: authentication/columbia-authentication.yml
  - type: Conformance
    url: conformance/columbia-conformance.yml
  - type: Documentation
    url: https://www.cuit.columbia.edu/shibboleth
  - type: Documentation
    url: https://www.cuit.columbia.edu/cas-authentication
  - type: Signup
    url: https://www.cuit.columbia.edu/cas-authentication/registration
  x-operator: institution
  x-operator-evidence: shibboleth.columbia.edu -> 128.59.105.181 and cas.columbia.edu -> 128.59.105.39, both in Columbia University
    address space, under a TLS certificate subject O=Columbia University, CN=*.columbia.edu issued by InCommon RSA OV SSL
    CA 3. The metadata document self-describes as "Columbia Shibboleth idp production instance metadata".
  x-access: public
  x-status: 200 application/xml, probed 2026-08-19
- aid: columbia:clio-opendata
  name: CLIO Library Catalog Open Data
  description: Columbia University Libraries publishes its full catalogue — bibliographic and holdings records from the integrated
    library system behind CLIO — as gzipped MARCXML bulk extracts under a CC0 1.0 Public Domain Dedication, refreshed monthly,
    alongside a deletes file. 108 files were present in the extract directory at probe time, served from an open Apache directory
    index with no credential and no rate limit. Covers books, serials, music, video and manuscripts; excludes Law Library
    and ReCAP partner records. There is no manifest, no checksum, no change feed and no harvesting protocol — a consumer diffs
    the directory listing.
  humanURL: https://library.columbia.edu/bts/clio-data.html
  baseURL: https://lito.cul.columbia.edu/extracts/ColumbiaLibraryCatalog/full/
  tags:
  - Library
  - Catalog
  - MARCXML
  - Open Data
  - Bulk Download
  - CC0
  properties:
  - type: Documentation
    url: https://library.columbia.edu/bts/clio-data.html
  - type: GitHubRepository
    url: https://github.com/cul/clio-spectrum
  - type: Lifecycle
    url: lifecycle/columbia-lifecycle.yml
  x-operator: institution
  x-operator-evidence: lito.cul.columbia.edu resolves to lito-apache-prod2.cul.columbia.edu / 128.59.222.64, in Columbia University
    Libraries' own address space. The extracts are generated from Columbia's own ILS and released under Columbia's own CC0
    dedication.
  x-access: public
  x-status: 200, 108 extract files listed, probed 2026-08-19
- aid: columbia:opendata
  name: Columbia Open Data Service
  description: 'The central university service publishing data feeds to software developers in programming-friendly formats
    such as JSON and XML — the course directory, the CLIO library catalogue and building access among them — with documented
    refresh schedules, data diagrams and element documentation. It is the closest thing Columbia has to a developer portal,
    and access is affiliation-gated: any member of the University community may log in with their UNI to consume the feeds,
    and there is no external, partner or application tier for anyone else. On this run the service and its documentation were
    unreadable — the host sits behind a Cloudflare managed challenge that returns HTTP 403 to every non-browser client, including
    one presenting full browser headers. The access model described here is carried forward from the June 2026 profile and
    is not re-verified.'
  humanURL: https://opendataservice.columbia.edu/
  tags:
  - Open Data
  - Data Feeds
  - JSON
  - XML
  - Gated
  - Developer Portal
  properties:
  - type: Documentation
    url: https://opendataservice.columbia.edu/about
  - type: Authentication
    url: authentication/columbia-authentication.yml
  x-operator: institution
  x-operator-evidence: Host is under columbia.edu, the institution's own registrable domain.
  x-access: affiliation_gated
  x-status: 403 Cloudflare managed challenge, probed 2026-08-19
- aid: columbia:directory-of-classes
  name: CU Directory of Classes
  description: The public web directory of Columbia University class offerings, browsable by subject, department, semester,
    instruction method, weekday and start time. Live and fully readable, and HTML only — there is no documented API, no JSON
    feed and no machine-readable expression of Columbia's course vocabulary published by the university anywhere. The registrar's
    own Vergil course search sits behind the Cloudflare challenge. Recorded because course catalog is one of the surface classes
    a university genuinely operates, and Columbia operates this one without a contract. Third-party projects crawl this directory
    and republish it as JSON; those are not Columbia's and are deliberately not linked here as Columbia's.
  humanURL: https://doc.sis.columbia.edu/
  tags:
  - Courses
  - Course Catalog
  - Directory
  - Registrar
  - HTML Only
  - No API
  properties:
  - type: Documentation
    url: https://doc.sis.columbia.edu/
  x-operator: institution
  x-operator-evidence: doc.sis.columbia.edu resolves to miscredirect-prod.cc.columbia.edu / 128.59.44.55, in Columbia University
    address space.
  x-access: public
  x-status: 200 text/html, no machine-readable representation, probed 2026-08-19
- aid: columbia:academic-commons
  name: Columbia Academic Commons
  description: 'Columbia University''s institutional research repository, holding the scholarly output, theses and research
    data of the university. Unusually for this cohort it is NOT a vendor tenancy: it runs on Hyrax/Blacklight — open-source
    repository software the Libraries help maintain — on Columbia''s own host and hardware, with Columbia''s own DOIs. The
    repository is therefore institution-operated in full. It could not be verified on this run: every request, including the
    OAI-PMH path and including requests presenting full browser headers, returns an Anubis proof-of-work interstitial with
    HTTP 200 and a bot-check body. No contract, schema or OAI Identify response is claimed for it, and no scored pointer is
    emitted to the host, because an Anubis-challenged host is indistinguishable from a soft-404 to an automated prober.'
  humanURL: https://academiccommons.columbia.edu/
  tags:
  - Research Repository
  - Institutional Repository
  - Open Access
  - Hyrax
  - Blacklight
  - Blocked
  properties:
  - type: Conformance
    url: conformance/columbia-conformance.yml
  x-operator: institution
  x-operator-evidence: academiccommons.columbia.edu resolves to ac-rails-prod1.cul.columbia.edu / 128.59.222.111, in Columbia
    University Libraries' own address space. No vendor CNAME. Columbia University Libraries maintains its own forks of hyrax,
    blacklight and blacklight_oai_provider in the cul GitHub organisation.
  x-access: blocked
  x-status: 200 Anubis proof-of-work challenge body, probed 2026-08-19
- aid: columbia:dlc
  name: Digital Library Collections and the 10.7916 DOI namespace
  description: Columbia University Libraries' digital collections platform and the resolution target for Columbia's own DOI
    namespace. Columbia is a registered DataCite repository client (CUL.COLUMBIA, active since 2018) minting under prefix
    10.7916, with 1,111,628 DOIs registered at probe time, resolving to dlc.library.columbia.edu. It is Columbia's own persistent-identifier
    infrastructure — only the registry is DataCite's. Columbia University Libraries separately deposits into Crossref as member
    6984. The platform serves HTML; no IIIF manifest endpoint or JSON API was reachable, and iiif.library.columbia.edu does
    not resolve.
  humanURL: https://dlc.library.columbia.edu/
  tags:
  - Digital Collections
  - DOI
  - DataCite
  - Crossref
  - Persistent Identifiers
  - Research Data
  properties:
  - type: Conformance
    url: conformance/columbia-conformance.yml
  - type: Examples
    url: examples/index.yml
  x-operator: institution
  x-operator-evidence: DataCite client CUL.COLUMBIA is registered to Columbia University Libraries against library.columbia.edu;
    DOIs under prefix 10.7916 resolve to dlc.library.columbia.edu, a Columbia host. Crossref member 6984 is Columbia University
    Libraries.
  x-access: public
  x-status: 200 text/html, probed 2026-08-19
- aid: columbia:iri-data-library
  name: IRI/LDEO Climate Data Library
  description: 'The Climate Data Library run by the International Research Institute for Climate and Society and the Lamont-Doherty
    Earth Observatory, both Columbia University units. A long-running research-computing surface with its own URL-based dataset
    query language, OPeNDAP access and OGC WMS output, and historically one of the more genuinely programmable things any
    university operated. It is recorded here with a material access change: the landing pages still return 200, but every
    data path probed — /SOURCES/, the OPeNDAP endpoints and a WMS GetCapabilities request — now redirects to /auth/login.
    Presence without access, announced nowhere machine-readable.'
  humanURL: https://iridl.ldeo.columbia.edu/
  baseURL: https://iridl.ldeo.columbia.edu/SOURCES/
  tags:
  - Research Computing
  - Climate Data
  - OPeNDAP
  - WMS
  - Earth Science
  - Gated
  properties:
  - type: Documentation
    url: https://iridl.ldeo.columbia.edu/dochelp/
  - type: Lifecycle
    url: lifecycle/columbia-lifecycle.yml
  x-operator: institution
  x-operator-evidence: iridl.ldeo.columbia.edu resolves to iridls0.iri.columbia.edu / 129.236.110.88, Columbia University
    address space, operated by Columbia's IRI and Lamont-Doherty Earth Observatory.
  x-access: gated
  x-status: 302 to /auth/login on every data path, probed 2026-08-19
- aid: columbia:courseworks
  name: CourseWorks (Instructure Canvas)
  description: Columbia's learning management system. The REST API is live and returns a well-structured JSON 401 to unauthenticated
    callers, and the LTI 1.3 tool-platform JWKS is publicly readable — the best-formed error envelope and the only LTI conformance
    in Columbia's estate, and neither of them is Columbia's engineering. Columbia's courses and students, Instructure's contract.
    Recorded as a tenant relationship; the contract is deliberately not saved under this institution and the LTI conformance
    is credited to the tenant.
  humanURL: https://courseworks2.columbia.edu/
  baseURL: https://courseworks2.columbia.edu/api/v1
  tags:
  - Learning Management
  - LTI
  - Canvas
  - Course Delivery
  - Gated
  properties:
  - type: Conformance
    url: conformance/columbia-conformance.yml
  x-operator: tenant
  x-operator-evidence: courseworks2.columbia.edu CNAMEs to columbiasce.instructure.com -> cluster377.instructure.com and terminates
    on an AWS us-east-1 load balancer. No Columbia-operated infrastructure is involved.
  x-access: gated
  x-status: 401 application/json on /api/v1/accounts, 200 on the LTI JWKS, probed 2026-08-19
- aid: columbia:redivis
  name: Columbia University Data Platform (Redivis)
  description: 'Columbia''s research data platform runs on Redivis as an institution-specific tenancy, and the university
    has registered two distinct DataCite repository clients against it — CUL.CUIT "Columbia University Data Platform" and
    CUL.REDIVIS "Academic Commons Data Collection", the latter created in 2026. This is a real and recent institutional fact:
    a slice of Columbia''s research data publishing has moved onto a commercial platform under Columbia''s own DOI registrations.
    The data and the DOI registrations are Columbia''s; the platform, the API and the contract are Redivis''s, so no Redivis
    contract is saved under this institution.'
  humanURL: https://columbia.redivis.com/
  tags:
  - Research Data
  - Data Platform
  - Tenant
  - DataCite
  properties:
  - type: Documentation
    url: https://columbia.redivis.com/academic_commons
  x-operator: tenant
  x-operator-evidence: columbia.redivis.com is an institution-specific subdomain on the Redivis platform, not a Columbia host.
    DataCite clients CUL.CUIT and CUL.REDIVIS both register redivis.com URLs.
common:
- type: Website
  url: https://www.columbia.edu/
- type: DeveloperPortal
  url: https://opendataservice.columbia.edu/
- type: OpenData
  url: https://library.columbia.edu/bts/clio-data.html
- type: LibraryCatalog
  url: https://library.columbia.edu/
- type: CourseCatalog
  url: https://doc.sis.columbia.edu/
- type: IdentityFederation
  url: https://shibboleth.columbia.edu/idp/shibboleth
- type: ResearchComputing
  url: https://iridl.ldeo.columbia.edu/
- type: Authentication
  url: https://www.cuit.columbia.edu/web-authentication-federation
- type: GitHubOrganization
  url: https://github.com/cul
- type: GitHubOrganization
  url: https://github.com/columbia-it
- type: LinkedIn
  url: https://www.linkedin.com/school/columbia-university/
- type: OpenAPI
  url: openapi/columbia-library-hours-openapi.yml
- type: JSONSchema
  url: json-schema/columbia-library-hours-schema.json
- type: Examples
  url: examples/index.yml
- type: Rules
  url: rules/columbia-rules.yml
- type: Vocabulary
  url: vocabulary/columbia-vocabulary.yml
- type: JSONLD
  url: json-ld/columbia-context.jsonld
- type: Authentication
  url: authentication/columbia-authentication.yml
- type: Scopes
  url: scopes/columbia-scopes.yml
- type: Errors
  url: errors/columbia-errors.yml
- type: Conformance
  url: conformance/columbia-conformance.yml
- type: Lifecycle
  url: lifecycle/columbia-lifecycle.yml
- type: AgenticAccess
  url: agentic-access/columbia-agentic-access.yml
- type: DomainSecurity
  url: security/columbia-domain-security.yml
- type: Plans
  url: plans/columbia-plans-pricing.yml
- type: RateLimits
  url: rate-limits/columbia-rate-limits.yml
- type: FinOps
  url: finops/columbia-finops.yml
- type: Review
  url: review.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
x-coverage:
  state: covered
  reason: thin_but_fully_probed
  detail: 'Columbia University''s programmable footprint is small, and this profile is thin because the footprint is thin,
    not because the probe failed. More than forty URLs were fetched successfully across fourteen Columbia hosts, and the institution''s
    one public API was exercised end to end including both error paths. What was found is genuinely Columbia''s: a live two-operation
    JSON API with CORS enabled at hours.library.columbia.edu, a production Shibboleth IdP publishing SAML 2.0 metadata under
    the InCommon entityID urn:mace:incommon:columbia.edu, a CC0 MARCXML bulk release of the entire CLIO catalogue across 108
    files, and Columbia''s own DataCite prefix 10.7916 and Crossref membership 6984. Four of the twelve education-regime domain
    standards were confirmed against institution-operated surfaces, which is an unusually strong result for this cohort.


    Two access limits are recorded as findings about our reach, not about Columbia. The central columbia.edu Drupal estate
    — www, the Open Data Service, CUIT, the Provost, university policies, news and ai.columbia.edu — sits behind a Cloudflare
    managed challenge returning 403 to every non-browser client including one presenting full browser navigation headers,
    so the Open Data Service documentation, the AI guidance and the acceptable-use policy could not be read and are not claimed
    as verified content. Separately, Columbia University Libraries has deployed the Anubis proof-of-work challenge in front
    of its Blacklight discovery estate — clio.columbia.edu, academiccommons.columbia.edu and geodata.library.columbia.edu
    — which returns HTTP 200 with a bot-check body for every path. That is why oai-pmh is recorded as not_confirmed rather
    than credited, and why no scored pointer is emitted to any Anubis host: a 200 with an identical body on every path is
    indistinguishable from a soft-404 to an automated prober and would grade as dead.


    Genuine absences, verified: no OpenAPI is published by Columbia for anything; no llms.txt, no ai.txt and no .well-known/api-catalog
    on any host; no security.txt on www.columbia.edu or library.columbia.edu; no robots.txt on either (hours.library.columbia.edu
    serves the stock empty Rails template); no OpenID Connect discovery document on the identity estate; no SCIM endpoint;
    no MCP server, agent card or agent skills; and no changelog or deprecation policy on any institution-operated surface.
    api.columbia.edu and data.columbia.edu do not resolve. api.library.columbia.edu resolves and serves a page whose entire
    body is the words "API Home. CUL API." with a 404 placeholder beneath every path.'
  evidence:
  - url: https://hours.library.columbia.edu/api/v1/locations/open_now
    status: 200
    note: live JSON, seven locations, Access-Control-Allow-Origin *
  - url: https://hours.library.columbia.edu/api/v1/locations/butler?date=today
    status: 200
  - url: https://hours.library.columbia.edu/api/v1/locations/butler?start_date=2026-08-19&end_date=2026-08-21
    status: 200
  - url: https://hours.library.columbia.edu/api/v1/locations/butler?date=notadate
    status: 400
  - url: https://hours.library.columbia.edu/api/v1/locations/nosuchplace?date=today
    status: 404
  - url: https://hours.library.columbia.edu/api/v1/locations/butler
    status: 200
    note: soft-200 defect - required parameter omitted returns the HTML web page, not a 400
  - url: https://shibboleth.columbia.edu/idp/shibboleth
    status: 200
    note: SAML 2.0 metadata, entityID urn:mace:incommon:columbia.edu
  - url: https://cas.columbia.edu/cas/login
    status: 200
  - url: https://lito.cul.columbia.edu/extracts/ColumbiaLibraryCatalog/full/
    status: 200
    note: 108 MARCXML extract files plus deletes.del.txt, CC0
  - url: https://doc.sis.columbia.edu/
    status: 200
    note: HTML only, no machine-readable course representation
  - url: https://api.datacite.org/clients/cul.columbia
    status: 200
    note: Columbia's own DataCite repository client, prefix 10.7916, 1,111,628 DOIs
  - url: https://api.crossref.org/members/6984
    status: 200
    note: Columbia University Libraries, 2,348 deposited DOIs
  - url: https://dlc.library.columbia.edu/resolve/10.7916/x4bf-v234
    status: 200
    note: a Columbia DOI resolving to a Columbia host
  - url: https://courseworks2.columbia.edu/api/lti/security/jwks
    status: 200
    note: LTI 1.3 JWKS - Instructure's conformance, credited to the tenant
  - url: https://courseworks2.columbia.edu/api/v1/accounts
    status: 401
  - url: https://columbia.redivis.com/academic_commons
    status: 200
    note: tenant research data platform
  - url: https://iridl.ldeo.columbia.edu/
    status: 200
  - url: https://iridl.ldeo.columbia.edu/SOURCES/
    status: 302
    note: redirects to /auth/login - data paths are now gated
  - url: https://api.library.columbia.edu/
    status: 200
    note: reserved API hostname, body is the words "API Home. CUL API."
  - url: https://api.library.columbia.edu/openapi.json
    status: 404
  - url: https://opendataservice.columbia.edu/
    status: 403
    note: Cloudflare managed challenge - live, unreadable; blocked probe about us
  - url: https://www.cuit.columbia.edu/web-authentication-federation
    status: 403
    note: Cloudflare managed challenge
  - url: https://ai.columbia.edu/
    status: 403
    note: Cloudflare managed challenge - AI hub exists, content unreadable, not claimed as a pointer
  - url: https://academiccommons.columbia.edu/catalog/oai?verb=Identify
    status: 200
    note: Anubis proof-of-work challenge body, not an OAI-PMH response - oai-pmh not credited
  - url: https://clio.columbia.edu/
    status: 200
    note: Anubis proof-of-work challenge body
  - url: https://geodata.library.columbia.edu/
    status: 200
    note: Anubis proof-of-work challenge body
  - url: https://www.columbia.edu/llms.txt
    status: 404
  - url: https://www.columbia.edu/ai.txt
    status: 404
  - url: https://www.columbia.edu/robots.txt
    status: 404
  - url: https://www.columbia.edu/.well-known/security.txt
    status: 404
  - url: https://hours.library.columbia.edu/.well-known/api-catalog
    status: 404
  - url: https://hours.library.columbia.edu/robots.txt
    status: 200
    note: stock empty Rails template, no directives
  - url: https://shibboleth.columbia.edu/.well-known/openid-configuration
    status: 404
  - url: https://shibboleth.columbia.edu/idp/profile/oidc/keyset
    status: 500
  - url: https://api.columbia.edu/
    status: 0
    note: does not resolve
  - url: https://data.columbia.edu/
    status: 0
    note: NXDOMAIN
  - url: https://sedac.ciesin.columbia.edu/
    status: 0
    note: DNS resolves to 129.236.39.66, no TCP connection from this vantage point
  - url: https://iiif.library.columbia.edu/
    status: 0
    note: does not resolve
  assessed: '2026-08-19'
  method: university pipeline live probe sweep
  added: 6
  added_detail: 'Six surfaces were added that the June 2026 profile missed entirely, five of them institution-operated: the
    Libraries Hours API (the institution''s only public API, verified live end to end), Academic Commons, the Digital Library
    Collections DOI namespace, the IRI/LDEO Climate Data Library, plus two tenant relationships - CourseWorks on Instructure
    Canvas and the Columbia University Data Platform on Redivis.'
  removed: 1
  removed_detail: One pointer was removed. The CU Directory of Classes entry carried a GitHub property pointing at soid/columbia-catalog-data,
    a third-party project that crawls Columbia's class directory and republishes it. It is not Columbia's repository and crediting
    it to the institution is the same artifact-presence-is-not-provenance error this pipeline exists to prevent. The relationship
    is described in the entry's prose instead.