University of Toronto website screenshot

University of Toronto

The University of Toronto is Canada's largest public research university, operating three campuses (St. George, Mississauga, Scarborough) and ranked in the QS World University Rankings top 25. Like almost every institution its size it is a federation of buyers rather than a producer of APIs, and this profile is deliberate about which side of that line each surface falls on. Two surfaces are genuinely institution-operated, both on utoronto.ca: the Timetable Builder API at api.easi.utoronto.ca, run by Enterprise Applications and Solutions Integration (EASI) within U of T Information Technology Services, which serves live course, section, meeting-time, enrolment and building data across all divisions with no credential required; and the UTORauth Shibboleth identity provider, which publishes SAML 2.0 metadata registered in the Canadian Access Federation with the REFEDS Research & Scholarship entity category and SIRTFI assurance. Everything else that looks like a University of Toronto API is a vendor or consortium contract running under the University's name — TSpace now lives on Scholaris, the OCUL-operated DSpace service, and its OAI-PMH and REST endpoints are the platform's engineering, not U of T's; the U of T Dataverse is a collection inside Borealis. Those relationships are recorded here as tenant surfaces because the data is the University's even though the contract is not. There is no developer portal, no API documentation, no terms of use for any API, no versioning scheme, no status page and no support channel for developers. The University does publish an llms.txt at its web root, which is more agent-facing provision than most of the cohort makes.

University of Toronto publishes 1 API on the APIs.io network: Timetable Builder API. Tagged areas include University, Higher Education, Education, Canada, and U15.

The University of Toronto catalog on APIs.io includes 2 JSON-LD contexts and 1 Spectral governance ruleset.

University of Toronto’s developer surface includes documentation, status page, engineering blog, support, code examples, and 26 more developer resources.

31.1/100 thin ▲ 13.7 Agent 24/100 agent aware Full breakdown ↓
scored 2026-08-20 · rubric v0.12.0
AccessFree
5 APIs
UniversityHigher EducationEducationCanadaU15ResearchCourse CatalogIdentity FederationResearch DataInstitutional RepositoryLibraryPublic Research University

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-08-20 · rubric v0.12.0
Composite quality — 31.1/100 · thin
Contract Quality 4.3 / 21
Developer Ergonomics 2.8 / 17
Access Clarity 6.7 / 17
Operational Transparency 2.9 / 11
Contract Governance 1.2 / 10
Discoverability 6.1 / 9
Regulatory Posture 6.9 / 15
Agent readiness — 24/100 · agent aware
Machine-Readable Contract 18 / 18
Agentic Access Contract 0 / 10
Documented Reversibility 0 / 6
MCP Server 0 / 12
Machine-Readable Auth 0 / 10
Idempotency 0 / 9
Stable Error Semantics 0 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Regulatory Posture applies to this provider. Its tags matched the Education & Research regime, so Regulatory Posture carries 15 points of the composite. If this regime is wrong for your business, say so on your provider repo — the applicability map is public and we will correct it.
The six quality facets above are damped to 85 points between them, because the conditional facet above carries the other 15. That is why each facet's contribution is shown against a damped maximum: raising a quality facet moves the composite by 85% of its nominal weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/university-of-toronto: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 5

Individual APIs this provider publishes, each with its own machine-readable definition.

Timetable Builder API

The public JSON API behind the official University of Toronto Timetable Builder, operated by Enterprise Applications and Solutions Integration (EASI) within U of T Information T...

UTORauth Shibboleth Identity Provider (SAML 2.0 metadata)

The University of Toronto's Shibboleth identity provider, entityID https://idpz.utorauth.utoronto.ca/shibboleth, serving signed SAML 2.0 metadata from the University's own utora...

TSpace Institutional Repository (OAI-PMH) — tenant on Scholaris

OAI-PMH 2.0 harvesting endpoint for TSpace, the University of Toronto Libraries institutional research repository. The repository is the University's — Identify returns reposito...

TSpace DSpace REST API — tenant on Scholaris

The DSpace 8.4 HAL REST API serving TSpace. Verified live on 2026-08-19: the root document returns dspaceName "TSpace", dspaceVersion "DSpace 8.4" and a link index covering comm...

U of T Dataverse (Borealis) — tenant

The University of Toronto's research data repository collection inside Borealis, the Canadian Dataverse Repository operated by Scholars Portal for the Ontario Council of Univers...

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

FinOps 1

Cost, billing, and metering signals for API financial operations.

Semantic Vocabularies 2

JSON-LD contexts and semantic vocabularies used across these APIs.

University Of Toronto Context

10 classes · 4 properties

JSON-LD

University Of Toronto Timetable Context

14 classes · 8 properties

JSON-LD

Spectral Rules 1

Spectral governance rulesets for linting and validating these APIs.

University of Toronto API Rules

1 rules · 1 warnings

SPECTRAL

JSON Schema 4

Standalone JSON Schema definitions for this provider's data models.

Examples 7

Example request and response payloads for these APIs.

Ttb Gateway 404 Response

2 fields

EXAMPLE

Ttb No Results Response

2 fields

EXAMPLE

Scroll for all 7

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

University Of Toronto Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Scopes 1

OAuth scopes governing access to this provider's APIs.

University Of Toronto Scopes

OAuth 2.0 · no documented scopes

0 scopes

SCOPES

Resources

Documentation 2

Reference material describing how the API behaves

Agent Surfaces 1

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 5

Pagination, idempotency, versioning, errors, and events

Build 5

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Learn 1

Tutorials, courses, talks, and written guidance

Operate 3

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 6

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: university-of-toronto
name: University of Toronto
x-type: university
x-category: Public Research University
description: 'The University of Toronto is Canada''s largest public research university, operating three campuses (St. George,
  Mississauga, Scarborough) and ranked in the QS World University Rankings top 25. Like almost every institution its size
  it is a federation of buyers rather than a producer of APIs, and this profile is deliberate about which side of that line
  each surface falls on. Two surfaces are genuinely institution-operated, both on utoronto.ca: the Timetable Builder API at
  api.easi.utoronto.ca, run by Enterprise Applications and Solutions Integration (EASI) within U of T Information Technology
  Services, which serves live course, section, meeting-time, enrolment and building data across all divisions with no credential
  required; and the UTORauth Shibboleth identity provider, which publishes SAML 2.0 metadata registered in the Canadian Access
  Federation with the REFEDS Research & Scholarship entity category and SIRTFI assurance. Everything else that looks like
  a University of Toronto API is a vendor or consortium contract running under the University''s name — TSpace now lives on
  Scholaris, the OCUL-operated DSpace service, and its OAI-PMH and REST endpoints are the platform''s engineering, not U of
  T''s; the U of T Dataverse is a collection inside Borealis. Those relationships are recorded here as tenant surfaces because
  the data is the University''s even though the contract is not. There is no developer portal, no API documentation, no terms
  of use for any API, no versioning scheme, no status page and no support channel for developers. The University does publish
  an llms.txt at its web root, which is more agent-facing provision than most of the cohort makes.'
type: Index
accessModel:
  pricing: free
  onboarding: none
  trial: false
  try_now: false
  public: true
  label: Free
  confidence: high
  source:
  - probed
  generated: '2026-08-19'
  method: probed
position: Consumer
access: 3rd-Party
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/university-of-toronto.png
url: https://raw.githubusercontent.com/api-evangelist/university-of-toronto/refs/heads/main/apis.yml
tags:
- University
- Higher Education
- Education
- Canada
- U15
- Research
- Course Catalog
- Identity Federation
- Research Data
- Institutional Repository
- Library
- Public Research University
created: '2026-06-03'
modified: '2026-08-19'
specificationVersion: '0.23'
apis:
- aid: university-of-toronto:ttb-course-timetable
  name: Timetable Builder API
  x-operator: institution
  description: 'The public JSON API behind the official University of Toronto Timetable Builder, operated by Enterprise Applications
    and Solutions Integration (EASI) within U of T Information Technology Services on the University''s own host api.easi.utoronto.ca.
    Serves course, section, meeting-time, instructor, enrolment-control and building data for every division and all three
    campuses. Six operations verified live and unauthenticated on 2026-08-19: reference-data, current-session, getMatchingDivisions,
    getPageableCourses, getCourses and getCoursesByCodeAndSectionCode. The University publishes no documentation, no OpenAPI,
    no terms of use and no rate-limit statement for it; CORS is pinned to https://ttb.utoronto.ca so browser clients from
    other origins are blocked while server-side clients are not. The OpenAPI in this repository is an API Evangelist observation,
    not a University artifact.'
  humanURL: https://ttb.utoronto.ca/
  baseURL: https://api.easi.utoronto.ca/ttb
  tags:
  - Course Catalog
  - Timetable
  - Registrar
  - Education
  - Open Data
  - REST
  properties:
  - type: OpenAPI
    url: openapi/university-of-toronto-timetable-builder-openapi.yml
  - type: Documentation
    url: https://ttb.utoronto.ca/
  - type: Authentication
    url: authentication/university-of-toronto-authentication.yml
  - type: Errors
    url: errors/university-of-toronto-errors.yml
  - type: Lifecycle
    url: lifecycle/university-of-toronto-lifecycle.yml
  - type: Examples
    url: examples/index.yml
  x-note: 'The baseURL https://api.easi.utoronto.ca/ttb returns HTTP 404 on its own — the gateway routes operations, not a
    root resource. Verified 2026-08-19: every operation beneath it returns 200. Recorded here so the 404 reads as a measured
    fact rather than a stale pointer.'
- aid: university-of-toronto:utorauth-shibboleth-idp
  name: UTORauth Shibboleth Identity Provider (SAML 2.0 metadata)
  x-operator: institution
  description: The University of Toronto's Shibboleth identity provider, entityID https://idpz.utorauth.utoronto.ca/shibboleth,
    serving signed SAML 2.0 metadata from the University's own utorauth.utoronto.ca host. Registered in the Canadian Access
    Federation (registration authority http://www.canarie.ca, registered 2018-09-21), asserting the REFEDS Research & Scholarship
    entity category and SIRTFI assurance certification. This is a federation login endpoint for humans in a browser rather
    than a developer API, and it is catalogued because it is machine-readable, institution-operated by definition, and the
    University's strongest published standards conformance.
  humanURL: https://its.utoronto.ca/
  baseURL: https://idpz.utorauth.utoronto.ca/idp/shibboleth
  tags:
  - Identity Federation
  - SAML
  - Shibboleth
  - Single Sign-On
  - Education
  - Metadata
  properties:
  - type: Conformance
    url: conformance/university-of-toronto-conformance.yml
  - type: Authentication
    url: authentication/university-of-toronto-authentication.yml
- aid: university-of-toronto:tspace-oai-pmh
  name: TSpace Institutional Repository (OAI-PMH) — tenant on Scholaris
  x-operator: tenant
  description: 'OAI-PMH 2.0 harvesting endpoint for TSpace, the University of Toronto Libraries institutional research repository.
    The repository is the University''s — Identify returns repositoryName "TSpace" with adminEmail tspace@library.utoronto.ca
    and an earliest datestamp of 2003 — but the endpoint runs on utoronto.scholaris.ca, an institution-specific subdomain
    of Scholaris, the DSpace service operated by the Ontario Council of University Libraries. The University''s own vanity
    host tspace.library.utoronto.ca 302-redirects here. Recorded as a tenant relationship: the data and the collection policy
    are U of T''s, the contract and the software are not, and the generic DSpace specification is deliberately NOT saved under
    this institution.'
  humanURL: https://utoronto.scholaris.ca/
  baseURL: https://utoronto.scholaris.ca/server/oai/request
  tags:
  - OAI-PMH
  - Institutional Repository
  - DSpace
  - Library
  - Metadata
  - Research
  - Tenant
  properties:
  - type: Documentation
    url: https://utoronto.scholaris.ca/server/oai/request?verb=Identify
  - type: Conformance
    url: conformance/university-of-toronto-conformance.yml
- aid: university-of-toronto:tspace-dspace-rest
  name: TSpace DSpace REST API — tenant on Scholaris
  x-operator: tenant
  description: 'The DSpace 8.4 HAL REST API serving TSpace. Verified live on 2026-08-19: the root document returns dspaceName
    "TSpace", dspaceVersion "DSpace 8.4" and a link index covering communities, collections, items, bitstreams and authn.
    This is the stock DSpace contract shipped by the Scholaris platform; the University neither designed nor documents it.
    Catalogued as a tenant surface so the relationship is visible without crediting U of T with DSpace''s engineering.'
  humanURL: https://utoronto.scholaris.ca/
  baseURL: https://utoronto.scholaris.ca/server/api
  tags:
  - REST
  - DSpace
  - Institutional Repository
  - Library
  - Research
  - Tenant
  properties:
  - type: Documentation
    url: https://utoronto.scholaris.ca/server/api
- aid: university-of-toronto:uoft-dataverse-borealis
  name: U of T Dataverse (Borealis) — tenant
  x-operator: tenant
  description: The University of Toronto's research data repository collection inside Borealis, the Canadian Dataverse Repository
    operated by Scholars Portal for the Ontario Council of University Libraries. Verified live on 2026-08-19 via the Dataverse
    Native API at https://borealisdata.ca/api/dataverses/toronto, which returns alias "toronto", name "U of T Dataverse",
    affiliation "University of Toronto". The Dataverse Native API contract belongs to the Dataverse Project and the deployment
    to Borealis; U of T operates the collection, the curation and the deposits. No Dataverse specification is saved under
    this institution.
  humanURL: https://borealisdata.ca/dataverse/toronto
  tags:
  - Research Data
  - Dataverse
  - Repository
  - Open Data
  - Tenant
  properties:
  - type: Documentation
    url: https://borealisdata.ca/dataverse/toronto
  x-note: Deliberately carries no baseURL. borealisdata.ca is a shared vendor host serving many Canadian institutions; publishing
    it as a U of T base URL is precisely the misattribution this profile exists to prevent. The relationship is the fact worth
    recording, not the endpoint.
common:
- type: Website
  url: https://www.utoronto.ca/
- type: LLMsTxt
  url: https://www.utoronto.ca/llms.txt
- type: CourseCatalog
  url: https://ttb.utoronto.ca/
- type: IdentityFederation
  url: https://idpz.utorauth.utoronto.ca/idp/shibboleth
- type: ResearchRepository
  url: https://utoronto.scholaris.ca/
- type: LibraryCatalog
  url: https://onesearch.library.utoronto.ca/
- type: ResearchComputing
  url: https://docs.scinet.utoronto.ca/
- type: AIPolicy
  url: https://ai.utoronto.ca/
- type: AITooling
  url: https://its.utoronto.ca/ai/
- type: OpenData
  url: https://data.utoronto.ca/
- type: Documentation
  url: https://easi.its.utoronto.ca/
- type: PrivacyPolicy
  url: https://www.utoronto.ca/privacy
- type: Status
  url: https://www.utoronto.ca/campus-status
- type: Blog
  url: https://www.utoronto.ca/news
- type: Support
  url: https://www.utoronto.ca/contacts
- type: GitHubOrganization
  url: https://github.com/utoronto
- type: SourceCode
  url: https://github.com/utlib
- type: LinkedIn
  url: https://www.linkedin.com/school/university-of-toronto/
- type: DomainSecurity
  url: security/university-of-toronto-domain-security.yml
- type: Plans
  url: plans/university-of-toronto-plans-pricing.yml
- type: RateLimits
  url: rate-limits/university-of-toronto-rate-limits.yml
- type: FinOps
  url: finops/university-of-toronto-finops.yml
- type: Review
  url: review.yml
- type: Conformance
  url: conformance/university-of-toronto-conformance.yml
- type: Lifecycle
  url: lifecycle/university-of-toronto-lifecycle.yml
- type: Vocabulary
  url: vocabulary/university-of-toronto-vocabulary.yml
- type: Rules
  url: rules/university-of-toronto-rules.yml
- type: Scopes
  url: scopes/university-of-toronto-scopes.yml
- type: JSONSchema
  url: json-schema/ttb-course.json
- type: JSONLD
  url: json-ld/university-of-toronto-timetable-context.jsonld
- type: Examples
  url: examples/index.yml
x-coverage:
  state: covered
  reason: institution_operated_surfaces_verified
  detail: 'Full pass on 2026-08-19. Two institution-operated surfaces were found and verified live, both on utoronto.ca: the
    EASI Timetable Builder API (six operations, unauthenticated, real course data) and the UTORauth Shibboleth SAML 2.0 identity
    provider. The June 2026 profile missed the timetable API because it guessed paths under ttb.utoronto.ca; the API actually
    lives on api.easi.utoronto.ca and its operation names are declared in the official client bundle. Three tenant relationships
    were confirmed and re-labelled rather than deleted: TSpace OAI-PMH and TSpace DSpace REST on Scholaris (OCUL), and the
    U of T Dataverse collection in Borealis. The deprecated community Cobalt open-data API was removed — its endpoint returns
    404 and it was never institution-operated. What genuinely does not exist: a developer portal, published API documentation,
    an OpenAPI, terms of use for any API, a versioning scheme, a status page, a rate limit statement, an OAuth surface, or
    any developer support channel. Nothing here was blocked from us.'
  evidence:
  - url: https://api.easi.utoronto.ca/ttb/reference-data
    status: 200
  - url: https://api.easi.utoronto.ca/ttb/current-session
    status: 200
  - url: https://api.easi.utoronto.ca/ttb/getMatchingDivisions?query=arts
    status: 200
  - url: https://api.easi.utoronto.ca/ttb/getPageableCourses
    status: 200
  - url: https://api.easi.utoronto.ca/ttb/getCourses
    status: 200
  - url: https://api.easi.utoronto.ca/ttb/getCoursesByCodeAndSectionCode/CSC108H1
    status: 200
  - url: https://idpz.utorauth.utoronto.ca/idp/shibboleth
    status: 200
  - url: https://utoronto.scholaris.ca/server/oai/request?verb=Identify
    status: 200
  - url: https://utoronto.scholaris.ca/server/api
    status: 200
  - url: https://borealisdata.ca/api/dataverses/toronto
    status: 200
  - url: https://www.utoronto.ca/llms.txt
    status: 200
  - url: https://tspace.library.utoronto.ca/server/oai/request?verb=Identify
    status: 302
  - url: https://onesearch.library.utoronto.ca/api/search?q=test
    status: 200
  - url: https://cobalt.qas.im/1.0/courses
    status: 404
  - url: https://api.easi.utoronto.ca/ttb/v3/api-docs
    status: 404
  - url: https://www.utoronto.ca/.well-known/security.txt
    status: 404
  - url: https://developer.utoronto.ca/
    status: 0
  - url: https://api.utoronto.ca/
    status: 0
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com