The University of York is a public research university in York, United Kingdom, and a member of the Russell Group. It operates no central developer portal, no API gateway, no self-service key issuance and no documented course, timetable or student-information API — and this profile says so rather than padding it. What it does operate, found by probing rather than by reading claims, is a genuinely first-party machine-readable estate around its digitised collections: a keyless JSON search API over 415,165 archive, library and cultural-heritage records at discover.york.ac.uk, a IIIF Image API 3.0 deployment at compliance level 2, IIIF Presentation API 3.0 manifests and canvases, all under the University's own ARK namespace (NAAN 36941); plus a live OAI-PMH 2.0 harvesting endpoint on its own research-portal host that emits ORCID iDs in its MODS records, and a Shibboleth SAML 2.0 identity provider. Everything else that looks like a York API is someone else's contract running under York's name: the Elsevier Pure REST Web Service, Ex Libris Primo/Alma discovery (YorSearch), and the White Rose Research Online and White Rose eTheses Online EPrints repositories shared with Leeds and Sheffield. Those are recorded here as tenant relationships, which they are, and not as York engineering, which they are not.
University of York publishes 3 APIs on the APIs.io network: Digital Collections Search API, Digital Collections IIIF APIs, and Research Portal OAI-PMH. Tagged areas include University, Higher Education, Education, United Kingdom, and Russell Group.
The University of York catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.
University of York’s developer surface includes documentation, status page, support, engineering blog, and 29 more developer resources.
Regulatory Posture applies to this provider. Its tags matched the
Education & Research regime, so
Regulatory Posture carries 15 points of the composite.
If this regime is wrong for your business, say so on your
provider repo — the
applicability map is public and we will correct it.
Create-or-Update Ergonomics does not apply to this provider. The published contracts declare
no write operations, and a read-only API cannot create-or-update. The facet is excluded from this provider's
denominator entirely — not scored zero. A reference or data API is not deficient for being unable to
upsert.
The six quality facets above are damped to 85 points between them,
because the conditional facet above carries the other
15. That is why each facet's contribution is shown against a damped
maximum: raising a quality facet moves the composite by 85% of its nominal
weight, not 100%. The full arithmetic is at apis.io/rating/.
The keyless JSON search interface behind discover.york.ac.uk, the University of York's Digital Collections. Two live endpoints — /api/search-simple, which the public search page...
The University of York serves its digitised material through two IIIF specifications on its own host: IIIF Image API 3.0 at compliance level 2 (the served info.json declares "pr...
OAI-PMH 2.0 harvesting on the University's own registrable domain. The Identify response names the repository "The University of York", gives adminEmail pure-support@york.ac.uk ...
The University's own SAML 2.0 identity provider at shib.york.ac.uk, running Shibboleth. It is the authentication surface through which every bought platform — Pure, Primo, the V...
The Elsevier Pure REST Web Service running on the University of York's tenant host. The documentation index answers without a key and the versioned API serves a 1.1 MB OpenAPI d...
YorSearch is the University of York library discovery service, an Ex Libris Primo front end over an Alma backend (view id 44YORK_INST:NUI). The discovery UI is live on a York ho...
White Rose Research Online is the shared EPrints institutional repository of the Universities of York, Leeds and Sheffield, on the consortium's own whiterose.ac.uk domain. Its O...
White Rose eTheses Online is the shared EPrints theses repository of York, Leeds and Sheffield, running on the consortium's own domain. Its OAI-PMH 2.0 interface Identifies as "...
aid: university-of-york
name: University of York
x-type: university
x-category: Public Research University
description: 'The University of York is a public research university in York, United Kingdom, and a member of the Russell
Group. It operates no central developer portal, no API gateway, no self-service key issuance and no documented course, timetable
or student-information API — and this profile says so rather than padding it. What it does operate, found by probing rather
than by reading claims, is a genuinely first-party machine-readable estate around its digitised collections: a keyless JSON
search API over 415,165 archive, library and cultural-heritage records at discover.york.ac.uk, a IIIF Image API 3.0 deployment
at compliance level 2, IIIF Presentation API 3.0 manifests and canvases, all under the University''s own ARK namespace (NAAN
36941); plus a live OAI-PMH 2.0 harvesting endpoint on its own research-portal host that emits ORCID iDs in its MODS records,
and a Shibboleth SAML 2.0 identity provider. Everything else that looks like a York API is someone else''s contract running
under York''s name: the Elsevier Pure REST Web Service, Ex Libris Primo/Alma discovery (YorSearch), and the White Rose Research
Online and White Rose eTheses Online EPrints repositories shared with Leeds and Sheffield. Those are recorded here as tenant
relationships, which they are, and not as York engineering, which they are not.'
type: Index
position: Producing
access: Public
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/university-of-york.png
url: https://raw.githubusercontent.com/api-evangelist/university-of-york/refs/heads/main/apis.yml
tags:
- University
- Higher Education
- Education
- United Kingdom
- Russell Group
- Digital Collections
- Cultural Heritage
- Archives
- IIIF
- Research Data
- Open Access
- OAI-PMH
- Identity Federation
- Library
- Research Computing
created: '2026-06-03'
modified: '2026-08-30'
specificationVersion: '0.23'
deliveryModel:
model: self-hosted
open_source: false
commercial: false
callable_host: true
label: Institution-hosted collections APIs · you call their endpoint
confidence: high
source:
- openapi
- probed
generated: '2026-08-30'
method: probed
accessModel:
pricing: free
onboarding: open
trial: false
try_now: true
public: true
label: Free · keyless, no registration, CORS open
confidence: high
source:
- authentication
- probed
generated: '2026-08-30'
method: probed
x-coverage:
state: covered
reason: covered
detail: 'The University of York does operate real, first-party, machine-readable APIs and they were found and verified by
live probe on 2026-08-30, not inferred from links. Three contracts are saved: a keyless Elasticsearch-backed search API
at discover.york.ac.uk/api/search-simple and /api/search over 415,165 digital-collections records; IIIF Image API 3.0
(info.json declares profile level2) and IIIF Presentation API 3.0 manifests and canvases on the same host; and OAI-PMH
2.0 at pure.york.ac.uk/ws/oai, whose Identify response names the repository "The University of York" with adminEmail pure-support@york.ac.uk,
and whose MODS records carry typed ORCID iDs. The footprint is nonetheless narrow and undocumented: York publishes no
OpenAPI, no developer portal, no changelog, no licence and no terms for any of it, and every field in this repository''s
contracts was measured rather than read. No course, timetable, campus-life, transit or open-data API was found — data.york.ac.uk,
courses.york.ac.uk, sis.york.ac.uk, opendata.york.ac.uk and developer(s).york.ac.uk do not resolve at all. api.york.ac.uk
DOES resolve and serves the University''s own branded "403 local" page, an institution-operated API host restricted to
the campus network; that is a real internal estate we cannot see, and it is recorded rather than counted. The library
discovery layer and the research repositories are real institutional facts but vendor-operated, and are recorded as tenant.
One route referenced by the site''s own JavaScript, /api/annotations/{manifest}/{canvas}, returns a 200 carrying the HTML
404 shell and is NOT deployed — it was deliberately excluded.'
generated: '2026-08-30'
method: probed
evidence:
- url: https://discover.york.ac.uk/api/search-simple?q=york&page=1&size=2
status: 200
- url: https://discover.york.ac.uk/api/search?q=york&size=2
status: 200
- url: https://discover.york.ac.uk/iiif/3/ark:/36941/common/objects/uoy-logo/info.json
status: 200
- url: https://discover.york.ac.uk/iiif/3/ark:/36941/common/objects/uoy-logo/full/max/0/default.jpg
status: 200
- url: https://discover.york.ac.uk/ark:/36941/9952973300001381/presentation/3/manifest
status: 200
- url: https://discover.york.ac.uk/ark:/36941/796351/presentation/3/canvas/802563
status: 200
- url: https://discover.york.ac.uk/ark:/36941/796351/presentation/3/collection
status: 403
- url: https://discover.york.ac.uk/api/annotations/796351/802563
status: 200
note: HTML 404 shell, not deployed
- url: https://pure.york.ac.uk/ws/oai?verb=Identify
status: 200
- url: https://pure.york.ac.uk/ws/oai?verb=ListSets
status: 200
- url: https://pure.york.ac.uk/ws/api/documentation/index.html
status: 200
- url: https://pure.york.ac.uk/ws/api/524/openapi.json
status: 401
- url: https://shib.york.ac.uk/idp/profile/SAML2/Redirect/SSO
status: 400
- url: https://shib.york.ac.uk/idp/profile/Metadata/SAML
status: 200
note: returns the Shibboleth error page, not SAML metadata
- url: https://api.york.ac.uk/
status: 403
note: '"403 local - University of York" — campus-network restricted'
- url: https://www.york.ac.uk/static/stable/opensearch.xml
status: 200
note: OpenSearch 1.1 description document; HTML results only, no JSON interface
- url: https://data.york.ac.uk/
status: 0
- url: https://courses.york.ac.uk/
status: 0
- url: https://sis.york.ac.uk/
status: 0
- url: https://opendata.york.ac.uk/
status: 0
- url: https://developer.york.ac.uk/
status: 0
- url: https://www.york.ac.uk/llms.txt
status: 404
- url: https://www.york.ac.uk/.well-known/security.txt
status: 404
- url: https://discover.york.ac.uk/llms.txt
status: 404
x-attribution-correction:
date: '2026-08-30'
pipeline: pipeline-university
removed:
contracts: 3
derived_artifacts: 9
reason: 'The 2026-06-03 profile saved the White Rose EPrints consortium''s OAI-PMH contract under York''s slug. openapi/_original/
held university-of-york-white-rose-etheses-oai.yaml and university-of-york-white-rose-research-oai.yaml, whose servers
are etheses.whiterose.ac.uk and eprints.whiterose.ac.uk and whose contacts are etheses@whiterose.ac.uk and eprints@whiterose.ac.uk
— a shared repository the University of York co-owns with Leeds and Sheffield, on a domain York does not own. refine-openapis
welded the two into university-of-york-oai2-api-openapi.yml, and the audit flagged the result as a weld: three specs
naming a host the repo does not own while apis.yml based the entry on one it does. Every schema, structure, example,
ruleset, collection, agentic-access and capability file in the repository was derived from those two documents and inherited
their provenance, so they were removed too, file by file. The vocabulary, JSON-LD context and Spectral ruleset were
rewritten rather than deleted, because the paths are canonical and the replacements describe the institution''s own
surfaces.'
retained_as_tenant:
- White Rose Research Online (EPrints, consortium with Leeds and Sheffield)
- White Rose eTheses Online (EPrints, consortium with Leeds and Sheffield)
- Elsevier Pure Web Services REST API
- Ex Libris Primo / Alma (YorSearch)
added_as_institution:
- University of York Digital Collections Search API
- University of York Digital Collections IIIF APIs
- University of York Research Portal OAI-PMH
- University of York Shibboleth Identity Provider
score_expectation: Removing a consortium contract and adding three verified first-party ones changes what is being measured,
not just how much of it there is. A correction that lowers a score is a success.
apis:
- aid: university-of-york:digital-collections-search
name: University of York Digital Collections Search API
x-operator: institution
description: The keyless JSON search interface behind discover.york.ac.uk, the University of York's Digital Collections.
Two live endpoints — /api/search-simple, which the public search page calls, and /api/search, which returns a different
aggregation set — query an Elasticsearch index of 415,165 records drawn from the University Library, the Borthwick Institute
for Archives and cultural-heritage partners. Faceted by creator, type, work type, collection and by collection-specific
families for the York Cause Papers and archival records. No key, no registration, CORS open to any origin. York publishes
no documentation for it; this contract was written from live probes and from the request construction in the site's own
JavaScript.
humanURL: https://discover.york.ac.uk/
baseURL: https://discover.york.ac.uk
tags:
- Digital Collections
- Search
- Archives
- Cultural Heritage
- Open Access
properties:
- type: OpenAPI
url: openapi/university-of-york-digital-collections-search-openapi.yml
- type: Documentation
url: https://discover.york.ac.uk/about/
- type: x-json-schema
url: json-schema/university-of-york-digital-collections-item-schema.json
- type: x-example
url: examples/university-of-york-digital-collections-search-example.json
- type: x-authentication
url: authentication/university-of-york-authentication.yml
- type: x-errors
url: errors/university-of-york-errors.yml
- type: x-lifecycle
url: lifecycle/university-of-york-lifecycle.yml
- aid: university-of-york:digital-collections-iiif
name: University of York Digital Collections IIIF APIs
x-operator: institution
description: 'The University of York serves its digitised material through two IIIF specifications on its own host: IIIF
Image API 3.0 at compliance level 2 (the served info.json declares "profile": "level2", "type": "ImageService3" and its
own extraFeatures, extraFormats and extraQualities), and IIIF Presentation API 3.0 manifests and canvases. Identifiers
are ARKs under the University''s Name Assigning Authority Number 36941. Keyless and CORS open. The IIIF Collection endpoint
is not deployed, so there is no machine-readable entry point that enumerates the collections — a harvester has to start
from the search API.'
humanURL: https://discover.york.ac.uk/collections/
baseURL: https://discover.york.ac.uk
tags:
- IIIF
- Digital Collections
- Image
- Cultural Heritage
- Archives
- JSON-LD
tags_raw:
- IIIF
- Digital Collections
- Images
- Cultural Heritage
- Archives
- JSON-LD
properties:
- type: OpenAPI
url: openapi/university-of-york-digital-collections-iiif-openapi.yml
- type: Documentation
url: https://discover.york.ac.uk/about/
- type: x-json-schema
url: json-schema/university-of-york-iiif-image-info-schema.json
- type: x-example
url: examples/university-of-york-iiif-image-info-example.json
- type: x-example
url: examples/university-of-york-iiif-presentation-manifest-example.json
- type: Conformance
url: conformance/university-of-york-conformance.yml
- type: x-errors
url: errors/university-of-york-errors.yml
- aid: university-of-york:research-portal-oai-pmh
name: University of York Research Portal OAI-PMH
x-operator: institution
description: OAI-PMH 2.0 harvesting on the University's own registrable domain. The Identify response names the repository
"The University of York", gives adminEmail pure-support@york.ac.uk and an earliest datestamp of 2014-10-14. All six verbs
are live. Five metadata formats are served — mods, xmetadiss, nl_didl, oai_dc and qdc — and the MODS records carry typed
ORCID iDs and DOIs. Sets cover persons, publications, publications with files, and publications by year. The deletedRecord
policy is "no", so incremental harvesting cannot detect withdrawals. The underlying product is Elsevier Pure; its proprietary
REST API is a separate, tenant surface and its contract is deliberately not saved here.
humanURL: https://pure.york.ac.uk/portal/
baseURL: https://pure.york.ac.uk/ws/oai
tags:
- OAI-PMH
- Research Data
- Open Access
- ORCID
- Metadata Harvesting
properties:
- type: OpenAPI
url: openapi/university-of-york-research-portal-oai-pmh-openapi.yml
- type: x-example
url: examples/university-of-york-oai-pmh-identify-example.xml
- type: x-example
url: examples/university-of-york-oai-pmh-getrecord-example.xml
- type: Conformance
url: conformance/university-of-york-conformance.yml
- type: Portal
url: https://pure.york.ac.uk/portal/
- aid: university-of-york:shibboleth-idp
name: University of York Shibboleth Identity Provider
x-operator: institution
description: 'The University''s own SAML 2.0 identity provider at shib.york.ac.uk, running Shibboleth. It is the authentication
surface through which every bought platform — Pure, Primo, the VLE — is actually reached, and it is institution-operated
by definition. Confirmed by behaviour: the SAML2 HTTP-Redirect SSO profile endpoint answers, and the IdP status handler
is present but access-restricted. Its SAML metadata is NOT published from a University host; it is distributed through
the UK Access Management Federation, so no machine-readable artifact could be retrieved and none has been invented. Recorded
as a surface, not as a contract.'
humanURL: https://www.york.ac.uk/it-services/
baseURL: https://shib.york.ac.uk/idp
tags:
- Identity Federation
- Shibboleth
- SAML
- Single Sign-On
properties:
- type: Conformance
url: conformance/university-of-york-conformance.yml
- type: Documentation
url: https://www.york.ac.uk/it-services/
- aid: university-of-york:pure-web-services
name: Elsevier Pure Web Services (University of York tenant)
x-operator: tenant
description: The Elsevier Pure REST Web Service running on the University of York's tenant host. The documentation index
answers without a key and the versioned API serves a 1.1 MB OpenAPI document, but the API itself returns 401 to an unauthenticated
caller and keys are issued by the institution's Pure administrators rather than self-service. This is York's research
information — and Elsevier's contract. The vendor specification is deliberately NOT saved under this institution's slug;
that misattribution is exactly what this pipeline exists to prevent. What IS saved is the OAI-PMH surface above, which
is protocol-standard and self-identifies as the University of York.
humanURL: https://pure.york.ac.uk/portal/
baseURL: https://pure.york.ac.uk/ws/api
tags:
- Research Information
- CRIS
- Elsevier Pure
- Tenant
properties:
- type: Documentation
url: https://pure.york.ac.uk/ws/api/documentation/index.html
- type: Portal
url: https://pure.york.ac.uk/portal/
- aid: university-of-york:yorsearch-primo
name: YorSearch Library Discovery (Ex Libris Primo / Alma)
x-operator: tenant
description: YorSearch is the University of York library discovery service, an Ex Libris Primo front end over an Alma backend
(view id 44YORK_INST:NUI). The discovery UI is live on a York host, but programmatic access runs through Ex Libris's own
gateway at api-eu.hosted.exlibrisgroup.com and requires an Ex Libris key. York's catalogue, Ex Libris's contract — recorded
as a tenant relationship, not as York engineering.
humanURL: https://www.york.ac.uk/library/resources/yorsearch-help/
baseURL: https://yorsearch.york.ac.uk/discovery/search?vid=44YORK_INST:NUI
tags:
- Library
- Discovery
- Primo
- Alma
- Ex Libris
- Tenant
properties:
- type: Documentation
url: https://www.york.ac.uk/library/resources/yorsearch-help/
- type: Portal
url: https://yorsearch.york.ac.uk/discovery/search?vid=44YORK_INST:NUI
- aid: university-of-york:wrro-oai
name: White Rose Research Online OAI-PMH (consortium)
x-operator: tenant
description: White Rose Research Online is the shared EPrints institutional repository of the Universities of York, Leeds
and Sheffield, on the consortium's own whiterose.ac.uk domain. Its OAI-PMH 2.0 interface is live and harvests York research
outputs alongside those of the other two members. York co-owns the deployment; EPrints wrote the protocol implementation
and the consortium, not York, operates the host. The 2026-06-03 profile saved this contract under York's slug; it has
been removed and the relationship recorded here instead.
humanURL: https://eprints.whiterose.ac.uk/
baseURL: https://eprints.whiterose.ac.uk/cgi/oai2
tags:
- Research Repository
- OAI-PMH
- EPrints
- Open Access
- Consortium
- Tenant
properties:
- type: Portal
url: https://eprints.whiterose.ac.uk/
- type: Documentation
url: https://eprints.whiterose.ac.uk/information.html
- aid: university-of-york:wreo-oai
name: White Rose eTheses Online OAI-PMH (consortium)
x-operator: tenant
description: White Rose eTheses Online is the shared EPrints theses repository of York, Leeds and Sheffield, running on
the consortium's own domain. Its OAI-PMH 2.0 interface Identifies as "White Rose eTheses Online" and harvests University
of York thesis metadata. Consortium- operated on vendor software; recorded as a tenant relationship rather than as a York
contract.
humanURL: https://etheses.whiterose.ac.uk/
baseURL: https://etheses.whiterose.ac.uk/cgi/oai2
tags:
- Research Repository
- OAI-PMH
- EPrints
- Theses
- Open Access
- Consortium
- Tenant
properties:
- type: Portal
url: https://etheses.whiterose.ac.uk/
common:
- type: Website
url: https://www.york.ac.uk/
- type: Documentation
url: https://discover.york.ac.uk/about/
- type: GitHubOrganization
url: https://github.com/university-of-york
- type: LinkedIn
url: https://uk.linkedin.com/school/uniofyork/
- type: Status
url: https://status.york.ac.uk/
- type: TermsOfService
url: https://www.york.ac.uk/about/legal-statements/
- type: PrivacyPolicy
url: https://www.york.ac.uk/about/legal-statements/#privacy
- type: Support
url: https://www.york.ac.uk/it-services/
- type: Blog
url: https://www.york.ac.uk/news-and-events/
- type: OpenData
url: https://discover.york.ac.uk/
- type: ResearchRepository
url: https://pure.york.ac.uk/portal/
- type: ResearchRepository
url: https://eprints.whiterose.ac.uk/
- type: ResearchRepository
url: https://etheses.whiterose.ac.uk/
- type: LibraryCatalog
url: https://yorsearch.york.ac.uk/discovery/search?vid=44YORK_INST:NUI
- type: CourseCatalog
url: https://www.york.ac.uk/study/undergraduate/courses/
- type: ResearchComputing
url: https://vikingdocs.york.ac.uk/
- type: ResearchComputing
url: https://www.york.ac.uk/it-services/tools/viking/
- type: AIPolicy
url: https://www.york.ac.uk/about/ai/
- type: AIPolicy
url: https://www.york.ac.uk/students/studying/assessment-and-examination/ai/taught-student-guidance/
- type: AITooling
url: https://www.york.ac.uk/it-services/tools/generative-ai-tools/
- type: DomainSecurity
url: security/university-of-york-domain-security.yml
- type: Plans
url: plans/university-of-york-plans-pricing.yml
- type: RateLimits
url: rate-limits/university-of-york-rate-limits.yml
- type: FinOps
url: finops/university-of-york-finops.yml
- type: Review
url: review.yml
- type: Conformance
url: conformance/university-of-york-conformance.yml
- type: x-authentication
url: authentication/university-of-york-authentication.yml
- type: x-errors
url: errors/university-of-york-errors.yml
- type: x-lifecycle
url: lifecycle/university-of-york-lifecycle.yml
- type: x-vocabulary
url: vocabulary/university-of-york-vocabulary.yml
- type: x-rules
url: rules/university-of-york-rules.yml
- type: x-rules
url: rules/university-of-york-jsonschema-spectral-rules.yml
- type: x-json-ld
url: json-ld/university-of-york-context.jsonld
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.