Stockholm University
Stockholm University (Stockholms universitet) is a public research university in Sweden and one of the country's largest, with roughly 33,000 students across four faculties. It operates no public developer portal, no API gateway and no first-party documented API: api.su.se, data.su.se and developer.su.se do not resolve, and www.su.se/api returns 404. What the institution genuinely runs and serves anonymously is narrow — a Shibboleth SAML2 identity provider at idp.it.su.se whose entity metadata is published by the university and registered in the SWAMID federation (and so in eduGAIN), the Bolin Centre Database research data repository on bolin.su.se minting its own DataCite DOIs under prefix 10.17043 since 2014, and a SiteVision REST sitemap on www.su.se that indexes every course syllabus in the education archive. Its two harvestable research surfaces are both tenancies rather than SU engineering: the DiVA OAI-PMH endpoint at su.diva-portal.org is operated by the DiVA consortium at Uppsala University Library, and su.figshare.com is a Figshare deployment. This profile previously credited Stockholm University with eleven APIs that were all one Figshare contract at api.figshare.com/v2; those contracts and everything derived from them have been removed and the two repository relationships recorded as tenant surfaces instead.
Stockholm University publishes 4 APIs on the APIs.io network. Tagged areas include Education, Higher Education, University, Research, and Research Data.
Stockholm University’s developer surface includes support and 18 more developer resources.
4 APIs
Individual APIs this provider publishes, each with its own machine-readable definition.
Published pricing tiers and plan structures.
Documented rate limits and quota policies.
Cost, billing, and metering signals for API financial operations.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
aid: stockholm
name: Stockholm University
x-type: university
x-category: Public Research University
description: 'Stockholm University (Stockholms universitet) is a public research university in Sweden and one of the country''s
largest, with roughly 33,000 students across four faculties. It operates no public developer portal, no API gateway and
no first-party documented API: api.su.se, data.su.se and developer.su.se do not resolve, and www.su.se/api returns 404.
What the institution genuinely runs and serves anonymously is narrow — a Shibboleth SAML2 identity provider at idp.it.su.se
whose entity metadata is published by the university and registered in the SWAMID federation (and so in eduGAIN), the Bolin
Centre Database research data repository on bolin.su.se minting its own DataCite DOIs under prefix 10.17043 since 2014,
and a SiteVision REST sitemap on www.su.se that indexes every course syllabus in the education archive. Its two harvestable
research surfaces are both tenancies rather than SU engineering: the DiVA OAI-PMH endpoint at su.diva-portal.org is operated
by the DiVA consortium at Uppsala University Library, and su.figshare.com is a Figshare deployment. This profile previously
credited Stockholm University with eleven APIs that were all one Figshare contract at api.figshare.com/v2; those contracts
and everything derived from them have been removed and the two repository relationships recorded as tenant surfaces instead.'
type: Index
deliveryModel:
model: unknown
open_source: false
commercial: false
callable_host: false
label: Delivery model not determined — needs a product licence on record
confidence: high
source:
- apis.yml
generated: '2026-08-30'
method: probed
accessModel:
pricing: free
onboarding: unknown
trial: false
try_now: true
public: true
label: Free
confidence: high
source:
- plans
- rate-limits
generated: '2026-08-30'
method: probed
position: Consuming
access: 3rd-Party
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/stockholm.png
url: https://raw.githubusercontent.com/api-evangelist/stockholm/refs/heads/main/apis.yml
tags:
- Education
- Higher Education
- University
- Research
- Research Data
- Open Access
- Repository
- Identity Federation
- Course Catalog
- Sweden
- Europe
created: '2026-06-03'
modified: '2026-08-30'
specificationVersion: '0.23'
apis:
- aid: stockholm:identity-federation
name: Stockholm University Shibboleth Identity Provider (SAML2 Metadata)
x-operator: institution
description: Stockholm University operates its own Shibboleth Identity Provider and publishes its SAML 2.0 entity metadata
anonymously on its registrable domain. The document declares entityID https://idp.it.su.se/idp/shibboleth, an IDPSSODescriptor
supporting urn:oasis:names:tc:SAML:2.0:protocol, and shibmd:Scope "su.se". The same entityID appears in the SWAMID IdP
metadata aggregate published by SUNET, which makes SU machine-discoverable as an identity provider to every eduGAIN-federated
service. This is the one surface in this profile that is unambiguously institution-operated engineering. It is a metadata
document, not a REST API — there is no OpenAPI for it and none has been invented.
humanURL: https://www.su.se/
baseURL: https://idp.it.su.se/idp/shibboleth
tags:
- Identity Federation
- SAML
- Shibboleth
- Authentication
properties:
- type: x-conformance
url: conformance/stockholm-conformance.yml
- type: Documentation
url: https://www.swamid.se/
- aid: stockholm:diva-oai
name: DiVA Institutional Repository (OAI-PMH)
x-operator: tenant
description: Stockholm University's publication records are harvestable over OAI-PMH 2.0 from its DiVA instance at su.diva-portal.org,
with an institution-scoped set (all-su) and eight metadata formats (oai_dc, oai_etdms, marc21, marc21electronic, swepub_mods,
uppsok, gmd, mets_kb). The records are Stockholm University's; the service is not. The Identify response names DiVA.org
as the repository identifier and diva-support@ub.uu.se as the administrative contact — DiVA is a shared Swedish system
whose technical development is run by the EPC at Uppsala University Library. Recorded as the deployment relationship,
not as an SU contract.
humanURL: https://su.diva-portal.org/
baseURL: https://su.diva-portal.org/dice/oai
tags:
- Repository
- OAI-PMH
- Metadata
- Research
- Open Access
properties:
- type: x-conformance
url: conformance/stockholm-conformance.yml
- type: Documentation
url: https://www.su.se/english/library/
- aid: stockholm:figshare-repository
name: Stockholm University Research Data Repository (Figshare tenancy)
x-operator: tenant
description: su.figshare.com is Stockholm University's research data repository, running on Figshare. The data, the DOIs
and the institutional group are SU's; the contract behind it is Figshare's generic api.figshare.com/v2 API, shared by
every Figshare customer. Eleven per-tag copies of that Figshare OpenAPI were previously saved into this repository and
attributed to Stockholm University; they have been removed, along with the schemas, structures, examples, rules, vocabulary,
JSON-LD context, scopes, authentication summary, agentic-access card, capability edges and Postman/OpenCollection files
derived from them. The relationship is kept here because it is a real institutional fact; the vendor's contract belongs
in Figshare's own repo. The host answers anonymous requests with HTTP 202 and an empty body (bot challenge).
humanURL: https://su.figshare.com/
baseURL: https://su.figshare.com/
tags:
- Research Data
- Repository
- Open Access
properties:
- type: Documentation
url: https://docs.figshare.com/
- aid: stockholm:education-archive-sitemap
name: Stockholm University Education Archive Sitemap (SiteVision REST)
x-operator: institution
description: 'www.su.se runs SiteVision, whose REST framework is reachable at /rest-api/ and answers with structured JSON.
No public RestApp is exposed there (a request to /rest-api/search returns {"success":false,"type":"invalidParameter","message":"No
RestApp found for /rest-api/search"}), but one machine-readable surface is served and advertised in robots.txt: a sitemap
index at /rest-api/sitemap whose educationArchiveSitemap child is a 3.9 MB XML enumeration of every course syllabus in
the university''s planarkiv, each with a course code and a lastmod timestamp. It is an index, not an API, and it is listed
here because it is the only institution-operated, anonymously fetchable machine-readable description of Stockholm University''s
course catalog that was found. The catalog UI itself is a SiteVision web app backed by opaque node-id JSON endpoints with
no documented contract.'
humanURL: https://www.su.se/utbildning/utbildningskatalog
baseURL: https://www.su.se/rest-api/sitemap
tags:
- Course Catalog
- Education
- Sitemap
properties:
- type: Documentation
url: https://www.su.se/robots.txt
common:
- type: Website
url: https://www.su.se/english/
- type: PrivacyPolicy
url: https://www.su.se/english/about-the-university/university-facts/about-this-website-and-processing-of-personal-data
- type: Support
url: https://www.su.se/english/about-the-university/contact
- type: GitHubOrganization
url: https://github.com/stockholmuniversity
- type: SourceCode
url: https://github.com/stockholmuniversity/shib-keygen-api
- type: LinkedIn
url: https://www.linkedin.com/school/stockholm-university/
- type: IdentityFederation
url: https://idp.it.su.se/idp/shibboleth
- type: ResearchRepository
url: https://bolin.su.se/data/
- type: ResearchRepository
url: https://su.diva-portal.org/
- type: ResearchRepository
url: https://su.figshare.com/
- type: CourseCatalog
url: https://www.su.se/utbildning/utbildningskatalog
- type: LibraryCatalog
url: https://www.su.se/english/library/
- type: Conformance
url: conformance/stockholm-conformance.yml
- type: VulnerabilityDisclosure
url: security/stockholm-vulnerability-disclosure.yml
- type: DomainSecurity
url: security/stockholm-domain-security.yml
- type: Plans
url: plans/stockholm-plans-pricing.yml
- type: RateLimits
url: rate-limits/stockholm-rate-limits.yml
- type: FinOps
url: finops/stockholm-finops.yml
- type: Review
url: review.yml
x-coverage:
state: none
reason: no_public_api
detail: 'Stockholm University publishes no public, documented API of its own, and this profile now says so. The operator
axis is the entire finding. Everything the June 2026 pass credited to SU — eleven per-tag OpenAPIs titled "Figshare altmetric
... API", all with servers[0] https://api.figshare.com/v2 and info.contact "Figshare Support" — was one vendor contract
that twelve other institutions in this cohort also ship. Those 48 files (10 refined specs, the pristine Figshare source
in openapi/_original, the refine report, 3 JSON Schemas, 2 JSON Structures, 2 examples, a JSON-LD context, 2 rulesets,
a vocabulary, scopes, an authentication summary, an agentic-access card, a capability map and 21 collection files) have
been removed file by file with git rm. Two tenant relationships were kept rather than deleted, because they are real institutional
facts: the DiVA OAI-PMH endpoint (operated by the DiVA consortium at Uppsala University Library) and su.figshare.com.
Two institution-operated surfaces were found by live probe and are new to this profile: the Shibboleth SAML2 IdP metadata
at idp.it.su.se, registered in SWAMID and therefore eduGAIN, and the SiteVision /rest-api/sitemap education archive index
on www.su.se. A third institution-operated asset, the Bolin Centre Database on bolin.su.se, mints DataCite DOIs under
prefix 10.17043 (DataCite repository snd.bolin, active since 2014) but publishes no REST API, so it is recorded as a ResearchRepository
pointer and as DataCite conformance rather than as an API. Four education-regime domain standards are evidenced in conformance/:
shibboleth, saml, oai-pmh and datacite. Eight more (scim, lti, oneroster, ed-fi, caliper, qti, orcid, crossref) were probed
and not found. Absences confirmed by negative probe rather than assumed: no developer portal, no API gateway, no open
data portal, no llms.txt, no sitemap at the conventional path, no first-party security contact (su.se/.well-known/security.txt
exists but names soc@sitevision.se, the CMS vendor''s SOC, not the university''s).'
generated: '2026-08-30'
method: probed
checked: '2026-08-30'
evidence:
- url: https://idp.it.su.se/idp/shibboleth
status: 200
note: INSTITUTION. application/xml, 5,263 bytes. SAML2 IdP metadata, entityID https://idp.it.su.se/idp/shibboleth, shibmd:Scope
su.se.
- url: https://mds.swamid.se/md/swamid-idp.xml
status: 200
note: SWAMID IdP aggregate contains exactly one su.se entity — SU's IdP. Aggregate is SUNET's.
- url: https://www.su.se/rest-api/sitemap
status: 404
note: INSTITUTION. Serves a valid <sitemapindex> body (315 bytes, text/xml) despite the 404 status code, naming sitemap1,
sitemap2 and educationArchiveSitemap. Advertised in robots.txt.
- url: https://www.su.se/rest-api/sitemap/educationArchiveSitemap
status: 200
note: 3,921,519 bytes of text/xml — every course syllabus in the planarkiv, with course codes.
- url: https://www.su.se/rest-api/search
status: 400
note: 'SiteVision REST framework is live and answers JSON, but exposes no public RestApp: {"success":false,"type":"invalidParameter","message":"No
RestApp found for /rest-api/search"}.'
- url: https://bolin.su.se/data/
status: 200
note: INSTITUTION. Bolin Centre Database, SU-operated research data repository. No REST API.
- url: https://api.datacite.org/clients/snd.bolin
status: 200
note: DataCite repository "Bolin Centre Database", year 2014, url https://bolin.su.se/data/.
- url: https://su.diva-portal.org/dice/oai?verb=Identify
status: 200
note: TENANT. OAI-PMH 2.0, repositoryName "DiVA - Academic Archive On-line", adminEmail diva-support@ub.uu.se, repositoryIdentifier
DiVA.org.
- url: https://su.figshare.com/
status: 202
note: TENANT. Empty body, bot challenge. Figshare deployment; contract is api.figshare.com/v2.
- url: https://api.su.se/
status: 0
note: Negative probe. No API gateway; host does not resolve.
- url: https://developer.su.se/
status: 0
note: Negative probe. No developer portal; host does not resolve.
- url: https://data.su.se/
status: 0
note: Negative probe. No open data portal; host does not resolve.
- url: https://www.su.se/api/
status: 404
note: Negative probe. No API path on the institutional website.
- url: https://www.su.se/llms.txt
status: 404
note: Negative probe. No agent-directed content policy.
- url: https://www.su.se/sitemap.xml
status: 404
note: Negative probe. Sitemap lives at /rest-api/sitemap instead, per robots.txt.
- url: https://www.su.se/.well-known/security.txt
status: 200
note: 'Present but not the institution''s own contact — Contact: mailto:soc@sitevision.se, the SiteVision CMS vendor''s
security operations centre. Expires 2026-09-30.'
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Every provider here is available over the APIs.io API and to AI agents over MCP.