Monash University website screenshot

Monash University

Monash University is a public research university in Melbourne, Australia, and a member of the Group of Eight. Its genuinely institution-operated programmable footprint is small but real, and it is not where a company's would be. Its three institution-operated surfaces all belong to Monash eResearch and all resolve into Monash's own APNIC address space: the Cloud Resource Allocation and Management System (CRAMS) portal, a public documentation site for the M3/MASSIVE HPC estate, and a Shibboleth service provider federated through the Australian Access Federation. None of the three publishes an open specification, so Monash's only evidenced domain-standard conformance (SAML, Shibboleth) rests on that one federation entry. The Monash-branded identity provider at idp.monash.edu.au looks like the strongest contract here and is not Monash's: it CNAMEs to idp-cname.aaf.edu.au on Amazon address space, making it a tenant of AAF's fully managed Rapid IdP. Everything else that looks like a Monash API is a vendor platform running under a Monash hostname: the Bridges research repository is Figshare (bridges.monash.edu is a CNAME to figshare.com), research.monash.edu is Elsevier Pure, the Handbook course catalog runs on CourseLoop, and library discovery is Ex Libris Primo. Those are recorded here as tenant relationships, not as Monash contracts. No central institutional developer portal, no open data portal, and no institution-operated OAI-PMH endpoint were found.

Monash University publishes 8 APIs on the APIs.io network. Tagged areas include Education, Higher Education, University, Research, and Australia.

Monash University’s developer surface includes GitHub presence and 17 more developer resources.

19.5/100 emerging ▼ -24.6 Agent 5/100 human only Full breakdown ↓
scored 2026-08-20 · rubric v0.12.0
AccessFree
8 APIs
EducationHigher EducationUniversityResearchAustraliaGroup of EightIdentity FederationResearch ComputingResearch RepositoryCourse Catalog

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-20 · rubric v0.12.0
Composite quality — 19.5/100 · emerging
Contract Quality 0.9 / 21
Developer Ergonomics 0.0 / 17
Access Clarity 6.3 / 17
Operational Transparency 2.9 / 11
Contract Governance 0.0 / 10
Discoverability 6.3 / 9
Regulatory Posture 4.4 / 15
Agent readiness — 5/100 · human only
Machine-Readable Contract 0 / 18
Agentic Access Contract 10 / 10
Documented Reversibility 0 / 6
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 0 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Regulatory Posture applies to this provider. Its tags matched the Education & Research regime, so Regulatory Posture carries 15 points of the composite. If this regime is wrong for your business, say so on your provider repo — the applicability map is public and we will correct it.
The six quality facets above are damped to 85 points between them, because the conditional facet above carries the other 15. That is why each facet's contribution is shown against a damped maximum: raising a quality facet moves the composite by 85% of its nominal weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/monash: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 8

Individual APIs this provider publishes, each with its own machine-readable definition.

Monash University Identity Provider (AAF Rapid IdP tenant)

Monash's federated login, published as a signed SAML 2.0 EntityDescriptor at https://idp.monash.edu.au/idp/shibboleth (HTTP 200, application/xml). Declares HTTP-POST and HTTP-Re...

Monash eResearch Center HPC ID (SAML Service Provider)

A second Monash-operated SAML service provider, entityID https://hpc.erc.monash.edu.au/shibboleth, registered in the Australian Access Federation under Organization "Monash Univ...

CRAMS API (Cloud Resource Allocation and Management System)

Monash eResearch operates the Cloud Resource Allocation and Management System (CRAMS), an institutional portal for managing research cloud resource allocations. The host respond...

Monash eResearch Documentation (M3 / MASSIVE)

Public documentation for the compute, storage, application and training services Monash eResearch runs, including the M3 and MonARCH HPC clusters. massive.org.au, www.massive.or...

Bridges — Monash Research Repository (Figshare tenant)

Monash's institutional research data repository, "Bridges", operating on the Figshare platform. bridges.monash.edu and monash.figshare.com both resolve as CNAMEs to figshare.com...

Monash Research Portal (Elsevier Pure tenant)

Monash's research outputs, profiles and publication metadata portal, running on Elsevier Pure. research.monash.edu resolves as a CNAME chain to monash.elsevierpure.com and then ...

Monash University Handbook (CourseLoop tenant)

The official Monash course, unit and area-of-study catalog. The site is a Next.js application on Monash's own hostname, but its runtime configuration (window.__SITE_ENV_CONFIG__...

Monash Library Discovery (Ex Libris Primo tenant)

Monash Library's discovery layer. search.lib.monash.edu redirects to monash.primo.exlibrisgroup.com/discovery/search?vid=61MONASH_AU:MONUI — a Monash-specific view code on Ex Li...

Scroll for all 8

Open Collections 11

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

API Collection

OPEN COLLECTION

Figshare altmetric API

OPEN COLLECTION

Scroll for all 11

Pricing Plans 1

Published pricing tiers and plan structures.

Monash Plans Pricing

2 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Monash Rate Limits

1 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Monash Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Monash Trust Center

ISO 27001, PCI DSS

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Monash Agentic Access

157 operations · 81 acting · 2 human-in-the-loop

157 operations · 81 acting

AGENTIC

Resources

Design & Contract 1

Pagination, idempotency, versioning, errors, and events

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Learn 1

Tutorials, courses, talks, and written guidance

Operate 1

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 2

The organization behind the API

Other 6

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: monash
name: Monash University
description: 'Monash University is a public research university in Melbourne, Australia, and a member of the Group of Eight.
  Its genuinely institution-operated programmable footprint is small but real, and it is not where a company''s would be.
  Its three institution-operated surfaces all belong to Monash eResearch and all resolve into Monash''s own APNIC address
  space: the Cloud Resource Allocation and Management System (CRAMS) portal, a public documentation site for the M3/MASSIVE
  HPC estate, and a Shibboleth service provider federated through the Australian Access Federation. None of the three publishes
  an open specification, so Monash''s only evidenced domain-standard conformance (SAML, Shibboleth) rests on that one federation
  entry. The Monash-branded identity provider at idp.monash.edu.au looks like the strongest contract here and is not Monash''s:
  it CNAMEs to idp-cname.aaf.edu.au on Amazon address space, making it a tenant of AAF''s fully managed Rapid IdP. Everything
  else that looks like a Monash API is a vendor platform running under a Monash hostname: the Bridges research repository
  is Figshare (bridges.monash.edu is a CNAME to figshare.com), research.monash.edu is Elsevier Pure, the Handbook course catalog
  runs on CourseLoop, and library discovery is Ex Libris Primo. Those are recorded here as tenant relationships, not as Monash
  contracts. No central institutional developer portal, no open data portal, and no institution-operated OAI-PMH endpoint
  were found.'
type: Index
accessModel:
  pricing: free
  onboarding: institutional
  trial: false
  try_now: false
  public: false
  label: Free · Institutional affiliation or federation membership required
  confidence: high
  source:
  - identity-federation
  - plans
  generated: '2026-08-19'
  method: derived
position: Consumer
access: 3rd-Party
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/monash.png
url: https://raw.githubusercontent.com/api-evangelist/monash/refs/heads/main/apis.yml
tags:
- Education
- Higher Education
- University
- Research
- Australia
- Group of Eight
- Identity Federation
- Research Computing
- Research Repository
- Course Catalog
created: '2026-06-03'
modified: '2026-08-19'
specificationVersion: '0.23'
apis:
- aid: monash:idp
  name: Monash University Identity Provider (AAF Rapid IdP tenant)
  description: Monash's federated login, published as a signed SAML 2.0 EntityDescriptor at https://idp.monash.edu.au/idp/shibboleth
    (HTTP 200, application/xml). Declares HTTP-POST and HTTP-Redirect SSO bindings, separate signing and encryption key descriptors,
    a shibmd:Scope of monash.edu.au, and release of auEduPersonSharedToken, email and displayName; the entity is registered
    in the Australian Access Federation production aggregate and flows into eduGAIN. It is the most complete machine-readable
    contract in this profile and it is a tenant surface, not a Monash-engineered one — the metadata is captured here, but
    the contract scores against AAF.
  humanURL: https://idp.monash.edu.au/idp/shibboleth
  baseURL: https://idp.monash.edu.au/idp/
  tags:
  - Identity Federation
  - SAML
  - Shibboleth
  - Single Sign-On
  properties:
  - type: IdentityFederation
    url: https://idp.monash.edu.au/idp/shibboleth
  - type: Metadata
    url: identity-federation/monash-idp-saml-metadata.xml
  - type: Conformance
    url: conformance/monash-conformance.yml
  x-operator: tenant
  x-operator-basis: Monash hostname, AAF infrastructure. idp.monash.edu.au CNAMEs to c2d8eee96e6328c487bda2d5476f7050.idp-cname.aaf.edu.au
    and resolves to 18.239.183.0/24, which whois attributes to Amazon Technologies Inc. (AT-88-Z). That CNAME pattern is AAF's
    Rapid IdP, a fully AAF-managed SaaS identity provider; idp.unimelb.edu.au matches it, while self-hosting institutions
    such as UQ resolve into their own address space. The TLS certificate is Amazon-issued rather than the Sectigo OV certificates
    Monash procures for hosts it runs itself. Monash's identity data, attribute release and scope; AAF's engineering.
- aid: monash:eresearch-hpc-sp
  name: Monash eResearch Center HPC ID (SAML Service Provider)
  description: A second Monash-operated SAML service provider, entityID https://hpc.erc.monash.edu.au/shibboleth, registered
    in the Australian Access Federation under Organization "Monash University". The entityID dereferences to an HTML login
    landing page rather than standalone metadata, so the authoritative machine-readable description is the AAF aggregate entry
    rather than a per-entity metadata URL.
  humanURL: https://hpc.erc.monash.edu.au/
  baseURL: https://hpc.erc.monash.edu.au/
  tags:
  - Identity Federation
  - Research Computing
  - SAML
  properties:
  - type: IdentityFederation
    url: https://md.aaf.edu.au/aaf-metadata.xml
  x-operator: institution
  x-operator-basis: Resolves to 118.138.238.241, netname MONASHUNI-NET3 / ORG-MU4-AP "Monash University" (APNIC), with no
    CNAME off Monash infrastructure and a Monash-procured Sectigo OV certificate. The AAF Organization block names Monash
    University. This is the only federation entity of the five that survives an IP-ownership check as institution-operated.
- aid: monash:crams
  name: CRAMS API (Cloud Resource Allocation and Management System)
  description: Monash eResearch operates the Cloud Resource Allocation and Management System (CRAMS), an institutional portal
    for managing research cloud resource allocations. The host responds HTTP 200 with a real application shell (nginx, Django,
    x-frame-options DENY, HSTS 63072000). Access is institutional and gated; /api/, /swagger/ and /docs/ all return 404, and
    no open specification was located. Recorded as an institution-operated surface with no published contract — not as an
    API with a contract we do not have.
  humanURL: https://crams-api.erc.monash.edu/
  baseURL: https://crams-api.erc.monash.edu/
  tags:
  - eResearch
  - Cloud
  - Research Infrastructure
  - Research Computing
  properties:
  - type: Documentation
    url: https://crams-api.erc.monash.edu/
  x-operator: institution
  x-operator-basis: Resolves to 118.138.238.174, netname MONASHUNI-NET3 "Monash University" (APNIC), on a Monash-procured
    Sectigo OV certificate.
- aid: monash:eresearch-docs
  name: Monash eResearch Documentation (M3 / MASSIVE)
  description: Public documentation for the compute, storage, application and training services Monash eResearch runs, including
    the M3 and MonARCH HPC clusters. massive.org.au, www.massive.org.au and docs.massive.org.au all redirect here, to Monash's
    own domain. Institution-operated documentation; no machine-readable contract is published.
  humanURL: https://docs.erc.monash.edu/
  baseURL: https://docs.erc.monash.edu/
  tags:
  - Research Computing
  - HPC
  - Documentation
  properties:
  - type: Documentation
    url: https://docs.erc.monash.edu/
  - type: ResearchComputing
    url: https://docs.erc.monash.edu/Compute/HPC/M3/
  x-operator: institution
  x-operator-basis: Resolves to 130.194.250.205, netname MONASHUNI-AU "Monash University" (APNIC). The intermediate CNAME
    apps.merc-managed.cloud.edu.au reads as third-party but is Monash eResearch Centre's own naming on Monash address space
    — an IP check, not the CNAME, settles this one.
- aid: monash:bridges
  name: Bridges — Monash Research Repository (Figshare tenant)
  description: Monash's institutional research data repository, "Bridges", operating on the Figshare platform. bridges.monash.edu
    and monash.figshare.com both resolve as CNAMEs to figshare.com. The data, the collections and the DOIs are Monash's; the
    REST API and OAI-PMH contract are Figshare's and are shared by every Figshare customer. Recorded as a tenant relationship.
    Figshare's generic specification is deliberately NOT saved under this institution — it was previously attributed here
    and to 24 other universities, and that misattribution is what this profile now corrects.
  humanURL: https://bridges.monash.edu/
  baseURL: https://bridges.monash.edu/
  tags:
  - Research Repository
  - Research Data
  - Open Access
  properties:
  - type: ResearchRepository
    url: https://bridges.monash.edu/
  x-operator: tenant
  x-operator-basis: bridges.monash.edu CNAME -> figshare.com. Institution-specific hostname on a vendor platform. Vendor repo,
    api-evangelist/figshare, is where the contract belongs.
- aid: monash:pure
  name: Monash Research Portal (Elsevier Pure tenant)
  description: Monash's research outputs, profiles and publication metadata portal, running on Elsevier Pure. research.monash.edu
    resolves as a CNAME chain to monash.elsevierpure.com and then to apac.prod.elsevierpure.com. The Pure web services endpoint
    /ws/oai returned HTTP 500 with body {"status":999} — a WAF rejection, not a working OAI-PMH Identify response. Tenant
    relationship; the Pure contract is Elsevier's.
  humanURL: https://research.monash.edu/
  baseURL: https://research.monash.edu/
  tags:
  - Research Repository
  - Research Outputs
  - CRIS
  properties:
  - type: ResearchRepository
    url: https://research.monash.edu/
  x-operator: tenant
  x-operator-basis: research.monash.edu CNAME -> monash.elsevierpure.com -> apac.prod.elsevierpure.com.
- aid: monash:handbook
  name: Monash University Handbook (CourseLoop tenant)
  description: The official Monash course, unit and area-of-study catalog. The site is a Next.js application on Monash's own
    hostname, but its runtime configuration (window.__SITE_ENV_CONFIG__) points every data call at api-ap-southeast-2.prod.courseloop.com
    — a regional CourseLoop host shared across that vendor's customers. handbook.monash.edu/api/ returns the AWS API Gateway
    string {"message":"Missing Authentication Token"}, i.e. an unmatched route on a gateway, not a documented Monash API.
    Course catalog data is Monash's; the contract is CourseLoop's.
  humanURL: https://handbook.monash.edu/
  baseURL: https://handbook.monash.edu/
  tags:
  - Course Catalog
  - Curriculum
  - Student Systems
  properties:
  - type: CourseCatalog
    url: https://handbook.monash.edu/
  x-operator: tenant
  x-operator-basis: handbook.monash.edu is a Monash hostname, but API_DOMAIN is api-ap-southeast-2.prod.courseloop.com, a
    shared vendor host.
- aid: monash:library-discovery
  name: Monash Library Discovery (Ex Libris Primo tenant)
  description: Monash Library's discovery layer. search.lib.monash.edu redirects to monash.primo.exlibrisgroup.com/discovery/search?vid=61MONASH_AU:MONUI
    — a Monash-specific view code on Ex Libris's Primo platform. Tenant relationship; the Primo and Alma contracts are Ex
    Libris's and are documented at developers.exlibrisgroup.com, not by Monash.
  humanURL: https://search.lib.monash.edu/
  baseURL: https://monash.primo.exlibrisgroup.com/discovery/search?vid=61MONASH_AU:MONUI
  tags:
  - Library
  - Discovery
  - Catalog
  properties:
  - type: LibraryCatalog
    url: https://search.lib.monash.edu/
  x-operator: tenant
  x-operator-basis: search.lib.monash.edu 302 -> monash.primo.exlibrisgroup.com with Monash view code 61MONASH_AU:MONUI.
common:
- type: Website
  url: https://www.monash.edu/
- type: IdentityFederation
  url: identity-federation/monash-identity-federation.yml
- type: Conformance
  url: conformance/monash-conformance.yml
- type: ResearchComputing
  url: https://docs.erc.monash.edu/
- type: ResearchRepository
  url: https://bridges.monash.edu/
- type: LibraryCatalog
  url: https://search.lib.monash.edu/
- type: CourseCatalog
  url: https://handbook.monash.edu/
- type: AIPolicy
  url: https://www.monash.edu/ai/tools-training-and-resources/ai-policies-and-guidelines
- type: Research
  url: https://research.monash.edu/
- type: GitHub
  url: https://github.com/monash-university
- type: SourceCode
  url: https://github.com/MonashStudentInnovation
- type: LinkedIn
  url: https://www.linkedin.com/school/monash-university/
- type: TrustCenter
  url: security/monash-trust-center.yml
- type: DomainSecurity
  url: security/monash-domain-security.yml
- type: Plans
  url: plans/monash-plans-pricing.yml
- type: RateLimits
  url: rate-limits/monash-rate-limits.yml
- type: FinOps
  url: finops/monash-finops.yml
- type: Review
  url: review.yml
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com
x-type: university
x-category: Public Research University
x-coverage:
  state: covered
  reason: institution_surface_verified_no_contract
  detail: 'Three institution-operated surfaces confirmed live and confirmed Monash-owned by IP, not by hostname: crams-api.erc.monash.edu
    and hpc.erc.monash.edu.au in MONASHUNI-NET3, and docs.erc.monash.edu in MONASHUNI-AU. None of the three publishes an OpenAPI,
    AsyncAPI or other open specification — CRAMS returns 404 on /api/, /swagger/ and /docs/ — so this profile records institution-operated
    surfaces with no institution-published contract, which is the honest result rather than a gap to be padded. Monash''s
    only evidenced education-regime conformance (SAML, Shibboleth) comes from a single AAF federation entry for the HPC service
    provider.

    Five further surfaces are real institutional facts but tenant relationships on platforms Monash does not run: AAF Rapid
    IdP, Figshare, Elsevier Pure, CourseLoop and Ex Libris. Their contracts are deliberately not saved here. The IdP is the
    notable one — it publishes the single most complete machine-readable contract in this profile and an earlier pass in this
    same run recorded it as institution-operated on hostname evidence, until DNS and whois showed it terminating on Amazon
    address space behind AAF''s managed service.

    The principal web estate at www.monash.edu sits behind a Cloudflare managed challenge (cf-mitigated: challenge) and is
    live-but-unreadable to non-browser clients — a limitation of our probe, not of Monash. No open data portal, no institution-operated
    OAI-PMH endpoint, and no central developer portal exist: data.monash.edu, api.monash.edu and developer.monash.edu do not
    resolve at all.'
  assessed: '2026-08-19'
  method: probed
  evidence:
  - url: https://crams-api.erc.monash.edu/
    status: 200
  - url: https://docs.erc.monash.edu/
    status: 200
  - url: https://hpc.erc.monash.edu.au/shibboleth
    status: 200
  - url: https://md.aaf.edu.au/aaf-metadata.xml
    status: 200
  - url: https://idp.monash.edu.au/idp/shibboleth
    status: 200
  - url: https://handbook.monash.edu/
    status: 200
  - url: https://research.monash.edu/
    status: 200
  - url: https://search.lib.monash.edu/
    status: 200
  - url: https://bridges.monash.edu/
    status: 202
  - url: https://www.monash.edu/
    status: 403
  - url: https://handbook.monash.edu/api/
    status: 403
  - url: https://crams-api.erc.monash.edu/swagger/
    status: 404
  - url: https://research.monash.edu/ws/oai?verb=Identify
    status: 500
  - url: https://data.monash.edu/
    status: 0
  - url: https://api.monash.edu/
    status: 0
  - url: https://developer.monash.edu/
    status: 0