The University of Manchester is a public research university in Manchester, England, a founding member of the Russell Group and, on the QS World University Rankings, a consistent global top-40 institution. Its programmable footprint is small, real, and almost entirely mis-stated by its own domain names. The University operates exactly three machine-readable surfaces of its own: a IIIF Presentation API and a IIIF Image API serving the John Rylands Library's digitised manuscripts from the University's own hosts and its own JANET address space, and a Shibboleth SAML 2.0 Identity Provider registered in the Jisc UK Access Management Federation under entityID https://shib.manchester.ac.uk/shibboleth. Everything else that looks like a Manchester API is a tenancy: pure.manchester.ac.uk and research.manchester.ac.uk both CNAME to uom-aws.elsevierpure.com and serve Elsevier's Pure product API and OAI-PMH implementation; figshare.manchester.ac.uk CNAMEs to figshare.com. Those are Manchester's records on a supplier's platform, under a supplier's contract, and they are recorded here as tenant relationships rather than credited as the University's engineering. There is no central developer portal, no self-service API keys, no open data portal at data.manchester.ac.uk, and no public course, timetable or SIS API. Thirty-six OpenAPI documents previously held in this repository were Elsevier's Pure 5.35.2-2 specification split by tag and re-titled; they have been quarantined, not counted.
University of Manchester publishes 2 APIs on the APIs.io network: Manchester Digital Collections — IIIF Presentation API and Manchester Digital Collections — IIIF Image API. Tagged areas include University, Higher Education, Education, Research, and United Kingdom.
The University of Manchester catalog on APIs.io includes 1 JSON-LD context and 1 Spectral governance ruleset.
University of Manchester’s developer surface includes engineering blog, support, GitHub presence, authentication, and 26 more developer resources.
Regulatory Posture applies to this provider. Its tags matched the
Education & Research regime, so
Regulatory Posture carries 15 points of the composite.
If this regime is wrong for your business, say so on your
provider repo — the
applicability map is public and we will correct it.
The six quality facets above are damped to 85 points between them,
because the conditional facet above carries the other
15. That is why each facet's contribution is shown against a damped
maximum: raising a quality facet moves the composite by 85% of its nominal
weight, not 100%. The full arithmetic is at apis.io/rating/.
IIIF Presentation API 2.1 over the University of Manchester Library's digitised manuscripts, archives and rare books. Serves sc:Manifest documents at /iiif/{documentId} and sc:C...
IIIF Image API 2.0 at compliance level 1, serving regions, scaled derivatives, rotations and quality variants of the Library's digitised page images. Self-describes through info...
The University's own Shibboleth Identity Provider, entityID https://shib.manchester.ac.uk/shibboleth, asserting the scope manchester.ac.uk. Its entity descriptor is published as...
The University's tenancy of Elsevier Pure, its Current Research Information System, reached at pure.manchester.ac.uk and surfaced publicly as Research Explorer at research.manch...
The University's institutional research data repository, presented at figshare.manchester.ac.uk, which CNAMEs to figshare.com. Manchester's researchers deposit here and the depo...
aid: university-of-manchester
name: University of Manchester
description: 'The University of Manchester is a public research university in Manchester, England, a founding member of the
Russell Group and, on the QS World University Rankings, a consistent global top-40 institution. Its programmable footprint
is small, real, and almost entirely mis-stated by its own domain names. The University operates exactly three machine-readable
surfaces of its own: a IIIF Presentation API and a IIIF Image API serving the John Rylands Library''s digitised manuscripts
from the University''s own hosts and its own JANET address space, and a Shibboleth SAML 2.0 Identity Provider registered
in the Jisc UK Access Management Federation under entityID https://shib.manchester.ac.uk/shibboleth. Everything else that
looks like a Manchester API is a tenancy: pure.manchester.ac.uk and research.manchester.ac.uk both CNAME to uom-aws.elsevierpure.com
and serve Elsevier''s Pure product API and OAI-PMH implementation; figshare.manchester.ac.uk CNAMEs to figshare.com. Those
are Manchester''s records on a supplier''s platform, under a supplier''s contract, and they are recorded here as tenant
relationships rather than credited as the University''s engineering. There is no central developer portal, no self-service
API keys, no open data portal at data.manchester.ac.uk, and no public course, timetable or SIS API. Thirty-six OpenAPI documents
previously held in this repository were Elsevier''s Pure 5.35.2-2 specification split by tag and re-titled; they have been
quarantined, not counted.'
type: Index
accessModel:
pricing: free
onboarding: none
trial: false
try_now: true
public: true
label: Free · No registration (institution-operated surfaces)
confidence: high
source:
- authentication
- probe
generated: '2026-08-19'
method: probed
note: The two institution-operated IIIF APIs are anonymous, unauthenticated and free — verified by live retrieval on 2026-08-19
with no credentials. There is no signup, no key and no plan. The previous accessModel said "self-serve signup", which
was read off Elsevier Pure's api-key scheme; that is a tenant surface and its onboarding is not the institution's.
position: Consumer
access: 3rd-Party
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/university-of-manchester.png
url: https://raw.githubusercontent.com/api-evangelist/university-of-manchester/refs/heads/main/apis.yml
tags:
- University
- Higher Education
- Education
- Research
- United Kingdom
- Russell Group
- Library
- Digital Collections
- IIIF
- Identity Federation
- Research Data
- Research Computing
created: '2026-06-03'
modified: '2026-08-19'
specificationVersion: '0.23'
apis:
- aid: university-of-manchester:iiif-presentation-api
name: Manchester Digital Collections — IIIF Presentation API
description: 'IIIF Presentation API 2.1 over the University of Manchester Library''s digitised manuscripts, archives and
rare books. Serves sc:Manifest documents at /iiif/{documentId} and sc:Collection documents at /iiif/collection/{collectionId}.
Verified live on 2026-08-19: MS-LATIN-00006 returned a 378 KB manifest of 398 canvases, the `latin` collection returned
61 manifests, and a negative probe on a real path shape returned a genuine 404. The host resolves to 130.88.101.74 inside
the University''s own JANET allocation — not a vendor CNAME — and every manifest is attributed to the University of Manchester
Library. This is institution-engineered.'
humanURL: https://www.digitalcollections.manchester.ac.uk/
baseURL: https://www.digitalcollections.manchester.ac.uk/iiif
tags:
- IIIF
- Library
- Digital Collections
- Manuscripts
- Open Access
- Cultural Heritage
properties:
- type: OpenAPI
url: openapi/university-of-manchester-iiif-presentation-api-openapi.yml
- type: JSONSchema
url: json-schema/university-of-manchester-iiif-manifest-schema.json
- type: Examples
url: examples/university-of-manchester-iiif-manifest-example.json
- type: Documentation
url: https://www.digitalcollections.manchester.ac.uk/about/
- type: TermsOfService
url: https://www.digitalcollections.manchester.ac.uk/terms/
x-operator: institution
x-operator-evidence: www.digitalcollections.manchester.ac.uk -> 130.88.101.74 (University of Manchester JANET allocation,
no CNAME); manifest attribution reads 'Provided by The University of Manchester ... (c) University of Manchester Library'.
x-probe:
baseURL_status: 404
note: 'The API base path itself returns 404 by design — it exposes no index. Verified 200 endpoints under it: /iiif/MS-LATIN-00006
and /iiif/collection/latin.'
verified_endpoint: https://www.digitalcollections.manchester.ac.uk/iiif/collection/latin
verified_status: 200
probed: '2026-08-19'
- aid: university-of-manchester:iiif-image-api
name: Manchester Digital Collections — IIIF Image API
description: 'IIIF Image API 2.0 at compliance level 1, serving regions, scaled derivatives, rotations and quality variants
of the Library''s digitised page images. Self-describes through info.json: formats [jpg]; qualities [native, color, gray,
bitonal]; supports regionByPct, regionSquare, sizeByForcedWh, sizeByWh, sizeAboveFull, rotationBy90s and mirroring; maxWidth
and maxHeight 2000; 256x256 tiles at scale factors 1-32. Verified live on 2026-08-19 with both a simple and a compound
request, plus a negative probe returning a genuine 404. Host resolves to 130.88.101.75, adjacent to the Presentation API
host in the University''s own address space.'
humanURL: https://www.digitalcollections.manchester.ac.uk/
baseURL: https://image.digitalcollections.manchester.ac.uk/iiif
tags:
- IIIF
- Image
- Tiles
- Library
- Digital Collections
- Open Access
properties:
- type: OpenAPI
url: openapi/university-of-manchester-iiif-image-api-openapi.yml
- type: JSONSchema
url: json-schema/university-of-manchester-iiif-image-info-schema.json
- type: Examples
url: examples/university-of-manchester-iiif-image-info-example.json
- type: Documentation
url: https://www.digitalcollections.manchester.ac.uk/about/
- type: TermsOfService
url: https://www.digitalcollections.manchester.ac.uk/terms/
x-operator: institution
x-operator-evidence: image.digitalcollections.manchester.ac.uk -> 130.88.101.75 (University of Manchester JANET allocation,
no CNAME); referenced as the image service by every canvas in the University's own manifests.
x-probe:
baseURL_status: 404
note: 'The API base path returns 404 and the host root returns 403 — no directory listing is exposed. Verified 200 endpoint
under it: /iiif/MS-LATIN-00006-000-00001.jp2/info.json.'
verified_endpoint: https://image.digitalcollections.manchester.ac.uk/iiif/MS-LATIN-00006-000-00001.jp2/info.json
verified_status: 200
probed: '2026-08-19'
- aid: university-of-manchester:shibboleth-saml-idp
name: Shibboleth SAML Identity Provider (UK Access Management Federation)
description: 'The University''s own Shibboleth Identity Provider, entityID https://shib.manchester.ac.uk/shibboleth, asserting
the scope manchester.ac.uk. Its entity descriptor is published as signed, machine-readable SAML metadata through the Jisc
UK Access Management Federation MDQ service and onward into eduGAIN — retrieved live on 2026-08-19 (200, 9647 bytes) and
saved to this repo. Advertises SAML 2.0, SAML 1.1 and the native Shibboleth authn profile over HTTP-Redirect, HTTP-POST,
HTTP-POST-SimpleSign and SOAP artifact resolution. Institution-operated by definition, and the single most under-catalogued
programmable asset a university runs. Note that the IdP is not a public developer API: an application cannot obtain an
assertion without being registered as a service provider in the federation.'
humanURL: https://www.itservices.manchester.ac.uk/
baseURL: http://mdq.ukfederation.org.uk/entities/https%3A%2F%2Fshib.manchester.ac.uk%2Fshibboleth
tags:
- Identity
- SSO
- SAML
- Shibboleth
- Federation
- eduGAIN
properties:
- type: Authentication
url: authentication/university-of-manchester-authentication.yml
- type: IdentityFederation
url: http://mdq.ukfederation.org.uk/entities/https%3A%2F%2Fshib.manchester.ac.uk%2Fshibboleth
- type: Documentation
url: https://www.itservices.manchester.ac.uk/
x-operator: institution
x-operator-evidence: Signed EntityDescriptor from the UK Access Management Federation names OrganizationName 'The University
of Manchester' and shibmd:Scope 'manchester.ac.uk'; shib.manchester.ac.uk resolves to 130.88.36.102 in the University's
own address space.
x-sso-endpoint: https://shib.manchester.ac.uk/shibboleth-idp/profile/SAML2/Redirect/SSO
x-entity-id: https://shib.manchester.ac.uk/shibboleth
x-probe:
baseURL_status: 200
note: baseURL is the federation MDQ location because that is the machine-readable artifact an agent can actually retrieve
— 200, 9647 bytes of signed SAML metadata. The SSO endpoint itself returns 500 to a bare GET because it requires a SAMLRequest;
that is protocol behaviour, not an outage, and it is recorded in x-sso-endpoint rather than as a pointer.
sso_endpoint_bare_get_status: 500
probed: '2026-08-19'
- aid: university-of-manchester:pure-cris-tenancy
name: Elsevier Pure CRIS tenancy (REST + OAI-PMH)
description: 'The University''s tenancy of Elsevier Pure, its Current Research Information System, reached at pure.manchester.ac.uk
and surfaced publicly as Research Explorer at research.manchester.ac.uk. Both hostnames CNAME to uom-aws.elsevierpure.com.
The OAI-PMH 2.0 endpoint is live and fully functional — Identify returns repositoryName ''Pure OAI Repository'' with adminEmail
Pure@manchester.ac.uk and an earliest datestamp of 2016-03-17, ListMetadataFormats offers seven formats including oai_cerif_openaire
and uketd_dc, and ListRecords returns real batches. The REST API is documented at /ws/api and gated by an api-key header.
All of that is Manchester''s data and Manchester''s administration on Elsevier''s platform under Elsevier''s contract:
the specification declares info.title ''Pure API'', info.contact.email pure-support@elsevier.com and info.version 5.35.2-2,
with a relative servers[] entry naming no institution at all. Recorded here as a tenant relationship. The specification
itself is not held under this slug.'
humanURL: https://research.manchester.ac.uk/
baseURL: https://pure.manchester.ac.uk/ws/oai
tags:
- Research
- CRIS
- Pure
- OAI-PMH
- Repository
- Metadata
- Open Access
- Tenant
properties:
- type: Documentation
url: https://pure.manchester.ac.uk/ws/api/
- type: ResearchRepository
url: https://research.manchester.ac.uk/
- type: Conformance
url: conformance/university-of-manchester-conformance.yml
x-operator: tenant
x-operator-evidence: 'DNS: pure.manchester.ac.uk CNAME uom-aws.elsevierpure.com; research.manchester.ac.uk CNAME uom-aws.elsevierpure.com.
Spec self-declaration: title ''Pure API'', contact pure-support@elsevier.com, version 5.35.2-2, servers[0].url ''/ws/api''.'
x-vendor: Elsevier (Pure)
- aid: university-of-manchester:figshare-tenancy
name: Figshare research data repository tenancy
description: 'The University''s institutional research data repository, presented at figshare.manchester.ac.uk, which CNAMEs
to figshare.com. Manchester''s researchers deposit here and the deposits carry Manchester''s branding, but the platform,
the REST API and the DOI minting are Figshare''s. Probed 2026-08-19: the tenant host returns an AWS WAF interstitial (HTTP
202) rather than a page body — a bot challenge, which grades as live-and-blocked, not dead. Recorded as a tenant relationship;
the generic api.figshare.com/v2 contract that previously appeared under this slug is a vendor surface and has been removed.
One Figshare contract was at one point attributed to twenty-five separate universities in this catalog; this entry exists
so the relationship survives the correction without the misattribution.'
humanURL: https://www.openresearch.manchester.ac.uk/
baseURL: https://figshare.manchester.ac.uk/
tags:
- Research Data
- Repository
- Figshare
- Open Data
- Tenant
properties:
- type: Documentation
url: https://www.openresearch.manchester.ac.uk/
x-operator: tenant
x-operator-evidence: 'DNS: figshare.manchester.ac.uk CNAME figshare.com.'
x-vendor: Figshare
common:
- type: Website
url: https://www.manchester.ac.uk/
- type: Blog
url: https://www.manchester.ac.uk/rss
- type: Support
url: https://www.manchester.ac.uk/connect/contact-us/
- type: TermsOfService
url: https://www.manchester.ac.uk/disclaimer/
- type: PrivacyPolicy
url: https://www.manchester.ac.uk/about/privacy-information/data-protection/
- type: Copyright
url: https://www.manchester.ac.uk/copyright/
- type: LinkedIn
url: https://www.linkedin.com/school/the-university-of-manchester/
- type: GitHub
url: https://github.com/University-of-Manchester
- type: GitHubOrganization
url: https://github.com/UoMResearchIT
- type: IdentityFederation
url: http://mdq.ukfederation.org.uk/entities/https%3A%2F%2Fshib.manchester.ac.uk%2Fshibboleth
- type: LibraryCatalog
url: https://www.library.manchester.ac.uk/
- type: DigitalCollections
url: https://www.digitalcollections.manchester.ac.uk/
- type: ResearchRepository
url: https://research.manchester.ac.uk/
- type: CourseCatalog
url: https://www.manchester.ac.uk/study/undergraduate/courses/
- type: ResearchComputing
url: https://research-it.manchester.ac.uk/
- type: AIPolicy
url: https://www.staffnet.manchester.ac.uk/ai-hub/ai-guidelines-and-policies/
- type: AITooling
url: https://www.staffnet.manchester.ac.uk/ai-hub/tools-and-resources/
- type: Authentication
url: authentication/university-of-manchester-authentication.yml
- type: Conformance
url: conformance/university-of-manchester-conformance.yml
- type: Errors
url: errors/university-of-manchester-errors.yml
- type: Lifecycle
url: lifecycle/university-of-manchester-lifecycle.yml
- type: Rules
url: rules/university-of-manchester-rules.yml
- type: Vocabulary
url: vocabulary/university-of-manchester-vocabulary.yml
- type: JSONLD
url: json-ld/university-of-manchester-context.jsonld
- type: AgenticAccess
url: agentic-access/university-of-manchester-agentic-access.yml
- type: DomainSecurity
url: security/university-of-manchester-domain-security.yml
- type: Plans
url: plans/university-of-manchester-plans-pricing.yml
- type: RateLimits
url: rate-limits/university-of-manchester-rate-limits.yml
- type: FinOps
url: finops/university-of-manchester-finops.yml
- type: Review
url: review.yml
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
x-type: university
x-coverage:
state: covered
reason: institution_operated_contract
detail: 'Three institution-operated surfaces found and verified by live probe on 2026-08-19: the IIIF Presentation API and
IIIF Image API at Manchester Digital Collections (both on the University''s own hosts inside its own JANET address space,
both returning genuine 404s on negative probes against real path shapes), and the Shibboleth SAML 2.0 Identity Provider
whose signed entity descriptor was retrieved from the UK Access Management Federation MDQ service. Two contracts were
written from those probes and saved. Two further surfaces, spanning three hostnames, are real but tenant-operated and
are recorded as relationships without holding the supplier''s specification: the Elsevier Pure tenancy (pure.manchester.ac.uk
and research.manchester.ac.uk, both CNAME uom-aws.elsevierpure.com) and the Figshare tenancy (figshare.manchester.ac.uk
CNAME figshare.com). The profile is thin because the institution is thin, not because the probe was: no open data portal
exists (data.manchester.ac.uk and opendata.manchester.ac.uk do not resolve), no api.manchester.ac.uk or developer.manchester.ac.uk
exists, and no public course, timetable or SIS API was found. Thirty-six OpenAPI documents previously scored under this
slug were Elsevier''s Pure 5.35.2-2 specification split by tag; they are quarantined in _vendor-quarantine/ with the evidence.'
assessed: '2026-08-19'
method: pipeline-university + live probe
institution_surfaces: 3
tenant_surfaces: 2
vendor_surfaces_removed: 1
contracts_saved: 2
contracts_quarantined: 36
evidence:
- url: https://www.digitalcollections.manchester.ac.uk/iiif/MS-LATIN-00006
status: 200
- url: https://www.digitalcollections.manchester.ac.uk/iiif/collection/latin
status: 200
- url: https://www.digitalcollections.manchester.ac.uk/iiif/NOT-A-REAL-ID-12345
status: 404
- url: https://image.digitalcollections.manchester.ac.uk/iiif/MS-LATIN-00006-000-00001.jp2/info.json
status: 200
- url: https://image.digitalcollections.manchester.ac.uk/iiif/MS-LATIN-00006-000-00001.jp2/0,0,500,500/200,/90/gray.jpg
status: 200
- url: https://image.digitalcollections.manchester.ac.uk/iiif/NOT-REAL.jp2/info.json
status: 404
- url: http://mdq.ukfederation.org.uk/entities/https%3A%2F%2Fshib.manchester.ac.uk%2Fshibboleth
status: 200
- url: https://pure.manchester.ac.uk/ws/oai?verb=Identify
status: 200
- url: https://pure.manchester.ac.uk/ws/oai?verb=ListMetadataFormats
status: 200
- url: https://pure.manchester.ac.uk/ws/api/
status: 200
- url: https://research.manchester.ac.uk/
status: 200
- url: https://figshare.manchester.ac.uk/
status: 202
note: AWS WAF bot challenge; live and blocked, not dead.
- url: https://www.staffnet.manchester.ac.uk/ai-hub/ai-guidelines-and-policies/
status: 200
- url: https://www.staffnet.manchester.ac.uk/ai-hub/tools-and-resources/
status: 200
- url: https://research-it.manchester.ac.uk/
status: 200
- url: https://www.manchester.ac.uk/study/undergraduate/courses/
status: 200
- url: https://www.linkedin.com/school/the-university-of-manchester/
status: 999
note: LinkedIn bot challenge; live and blocked, not dead.
- url: https://shib.manchester.ac.uk/
status: 500
note: DEAD as a pointer; removed from common[]. The IdP SSO profile endpoints are functional and the federation metadata
is the correct machine-readable pointer.
- url: https://data.manchester.ac.uk/
status: 0
note: Does not resolve. No open data portal.
- url: https://api.manchester.ac.uk/
status: 0
note: Does not resolve. No central API host.
- url: https://developer.manchester.ac.uk/
status: 0
note: Does not resolve. No developer portal.
- url: https://raw.githubusercontent.com/eScienceLab/rocrate-microservice-api/main/cratey-api.json
status: 200
note: Real OpenAPI 3.0.3 in a University of Manchester eScience Lab repo, but servers[0].url is https://api.server.test/v1
— a placeholder. Rejected, not saved.
tenant_hosts: 3
audit_script_caveat: 'audit-university-contracts.py classifies every *.manchester.ac.uk host as institution-operated because
its verdict is host-name based. That heuristic cannot see a vanity CNAME: it reports pure.manchester.ac.uk and figshare.manchester.ac.uk
as institution when DNS shows them pointing at uom-aws.elsevierpure.com and figshare.com. The x-operator values in this
file are set from DNS plus the specification''s own self-declaration, not from the script, and they should be treated
as the authority where the two disagree. The same blind spot will under-count tenants across the rest of the cohort wherever
an institution fronts a vendor platform with its own hostname.'
x-category: Public Research University
x-attribution-correction:
date: '2026-08-19'
summary: 36 OpenAPI documents, 70 collections and every derived schema, example, structure, vocabulary, ruleset, JSON-LD
context and authentication artifact under this slug were generated from Elsevier's Pure product specification and scored
as the University's own. They have been moved to _vendor-quarantine/ and are no longer referenced. The Figshare entry
has been re-pointed from the generic vendor host api.figshare.com/v2 to Manchester's actual tenancy at figshare.manchester.ac.uk.
Expect this repository's Kin Score to fall; the previous score was measuring Elsevier's engineering.
quarantine: _vendor-quarantine/README.md