Universiti Sains Malaysia website screenshot

Universiti Sains Malaysia

Universiti Sains Malaysia (USM) is a public research university founded in 1969 in Penang, Malaysia, holding APEX (Accelerated Programme for Excellence) status. USM operates no developer programme, no API catalog and no developer documentation of any kind, and its programmable footprint is entirely a by-product of the software it runs rather than anything it publishes for integrators. Three institution-operated machine-readable surfaces were verified live on 2026-09-01, all on hosts under usm.my: the OAI-PMH 2.0 endpoint and the EPrints REST/export tree of Repository@USM (eprints.usm.my, EPrints 3.3.16, seventeen export serializations), and USM's own Shibboleth SAML 2.0 identity provider at shibsso.usm.my, registered in the SIFULAN Malaysian Access Federation since 2021 and exported to eduGAIN. USM is a Crossref member (id 8963, prefixes 10.21315 and 10.36777) and holds a ROR record; it is not a DataCite provider or client. The host advertised as an API portal, api.usm.my, is an unmodified commercial HTML template with lorem ipsum body copy and no catalog behind its login — it is scaffolding, not a gated API programme, and this profile no longer counts it as a surface.

Universiti Sains Malaysia publishes 2 APIs on the APIs.io network: USM Repository OAI-PMH and USM Repository EPrints REST and Export. Tagged areas include University, Higher Education, Education, Public Research University, and Malaysia.

The Universiti Sains Malaysia catalog on APIs.io includes 1 JSON-LD context and 1 Spectral governance ruleset.

Universiti Sains Malaysia’s developer surface includes engineering blog, support, code examples, authentication, and 21 more developer resources.

34.5/100 thin ▬ flat Agent 27/100 agent aware self hosted Full breakdown ↓
scored 2026-09-08 · rubric v0.20.0
AccessFree⚡ Free to try
2 APIs
UniversityHigher EducationEducationPublic Research UniversityMalaysiaSoutheast AsiaResearchOpen AccessInstitutional RepositoryOAI-PMHEPrintsIdentity FederationShibbolethSAMLCrossref

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-09-08 · rubric v0.20.0
Regulatory Posture applies to this provider. Its tags matched the Education & Research regime, so Regulatory Posture carries 15 points of the composite. If this regime is wrong for your business, say so on your provider repo — the applicability map is public and we will correct it.
Create-or-Update Ergonomics does not apply to this provider. The published contracts declare no write operations, and a read-only API cannot create-or-update. The facet is excluded from this provider's denominator entirely — not scored zero. A reference or data API is not deficient for being unable to upsert.
The six quality facets above are damped to 85 points between them, because the conditional facet above carries the other 15. That is why each facet's contribution is shown against a damped maximum: raising a quality facet moves the composite by 85% of its nominal weight, not 100%. The full arithmetic is at apis.io/rating/.
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. Every facet and dimension name above is a link: it opens that measurement's own page — what it means, the exact checks that feed it, how the whole catalog distributes on it, and the providers at the top of it. This rating is computed from github.com/api-evangelist/usm: open an issue to ask a question, or submit a pull request to add artifacts. Submit an artifact on GitHub — free → Manage your own listing — the Influence plan, $499/mo →

APIs 6

Individual APIs this provider publishes, each with its own machine-readable definition.

USM Repository OAI-PMH

OAI-PMH 2.0 metadata-harvesting interface for Repository@USM, the EPrints 3.3.16 institutional repository USM runs on its own host. The live Identify response gives repositoryNa...

USM Repository EPrints REST and Export

Anonymous read interface to Repository@USM beyond OAI-PMH, verified route by route on 2026-09-01. /rest/ exposes three datasets (eprint, user, subject); /rest/eprint/{id}.xml re...

USM Shibboleth Identity Provider (SIFULAN / eduGAIN)

USM's own SAML 2.0 Shibboleth identity provider, entityID https://shibsso.usm.my/idp/shibboleth, scope usm.my. Registered in the SIFULAN Malaysian Access Federation on 2021-10-3...

e-Learning@USM Moodle Web Services

Self-hosted Moodle at elearning.usm.my with the REST web-service server enabled and token-gated. An unauthenticated call returns Moodle's own invalidtoken exception, which prove...

Crossref membership — Universiti Sains Malaysia

USM is Crossref member 8963, registering DOIs under prefixes 10.21315 (USM Press journals such as the Malaysian Journal of Medical Sciences, Journal of Physical Science, Kajian ...

ROR record — Universiti Sains Malaysia

USM's Research Organization Registry identifier, https://ror.org/02rgb2k63. The identifier is the join key used by ORCID, Crossref and DataCite to attribute research output to t...

Pricing Plans 1

Published pricing tiers and plan structures.

Usm Plans Pricing

2 plans

PLANS

Rate Limits 1

Documented rate limits and quota policies.

Usm Rate Limits

1 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Usm Finops

FINOPS

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Usm Context

13 classes · 4 properties

JSON-LD

Spectral Rules 1

Spectral governance rulesets for linting and validating these APIs.

Universiti Sains Malaysia API Rules

8 rules · 5 errors 3 warnings

SPECTRAL

JSON Schema 1

Standalone JSON Schema definitions for this provider's data models.

Examples 1

Example request and response payloads for these APIs.

Security Posture 2

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Usm Authentication

0 schemes

SECURITY

Usm Domain Security

TLSv1.3

SECURITY

Resources

Get Started 1

Portal, sign-up, and the first successful call

Documentation 3

Reference material describing how the API behaves

Design & Contract 6

Pagination, idempotency, versioning, errors, and events

Build 2

SDKs, sample code, and the tooling you integrate with

Access & Security 2

Authentication, authorization, and security posture

Operate 2

Status, limits, changes, and where to get help

Commercial 2

Pricing, plans, and the legal terms of use

Company 3

The organization behind the API

Other 4

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: usm
name: Universiti Sains Malaysia
x-type: university
x-category: Public Research University
description: 'Universiti Sains Malaysia (USM) is a public research university founded in 1969 in Penang, Malaysia, holding
  APEX (Accelerated Programme for Excellence) status. USM operates no developer programme, no API catalog and no developer
  documentation of any kind, and its programmable footprint is entirely a by-product of the software it runs rather than anything
  it publishes for integrators. Three institution-operated machine-readable surfaces were verified live on 2026-09-01, all
  on hosts under usm.my: the OAI-PMH 2.0 endpoint and the EPrints REST/export tree of Repository@USM (eprints.usm.my, EPrints
  3.3.16, seventeen export serializations), and USM''s own Shibboleth SAML 2.0 identity provider at shibsso.usm.my, registered
  in the SIFULAN Malaysian Access Federation since 2021 and exported to eduGAIN. USM is a Crossref member (id 8963, prefixes
  10.21315 and 10.36777) and holds a ROR record; it is not a DataCite provider or client. The host advertised as an API portal,
  api.usm.my, is an unmodified commercial HTML template with lorem ipsum body copy and no catalog behind its login — it is
  scaffolding, not a gated API programme, and this profile no longer counts it as a surface.'
type: Index
deliveryModel:
  model: self-hosted
  open_source: false
  commercial: false
  callable_host: true
  label: Institution-hosted service · you call their endpoint
  confidence: high
  source:
  - probe
  generated: '2026-09-01'
  method: probed
accessModel:
  pricing: free
  onboarding: none
  trial: false
  try_now: true
  public: true
  label: Free · anonymous read, no signup
  confidence: high
  source:
  - probe
  generated: '2026-09-01'
  method: probed
position: Consuming
access: 3rd-Party
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/usm.png
url: https://raw.githubusercontent.com/api-evangelist/usm/refs/heads/main/apis.yml
tags:
- University
- Higher Education
- Education
- Public Research University
- Malaysia
- Southeast Asia
- Research
- Open Access
- Institutional Repository
- OAI-PMH
- EPrints
- Identity Federation
- Shibboleth
- SAML
- Crossref
created: '2026-06-03'
modified: '2026-09-01'
specificationVersion: '0.23'
apis:
- aid: usm:eprints-oai
  name: USM Repository OAI-PMH
  x-operator: institution
  description: 'OAI-PMH 2.0 metadata-harvesting interface for Repository@USM, the EPrints 3.3.16 institutional repository
    USM runs on its own host. The live Identify response gives repositoryName "USM Repository", protocolVersion 2.0, adminEmail
    eprints@usm.my, earliestDatestamp 2013-07-13T00:03:59Z, deletedRecord persistent and granularity to the second. Six metadata
    prefixes are advertised — didl, mets, oai_bibl, oai_dc, rdf, uketd_dc. Anonymous read; no key. Two caveats a harvester
    must know: every error condition returns HTTP 200 with the fault in the body, and the repositoryIdentifier is still the
    EPrints default "generic.eprints.org" rather than usm.my, so minted OAI identifiers are not globally distinguishable.'
  humanURL: https://eprints.usm.my/
  baseURL: https://eprints.usm.my/cgi/oai2
  tags:
  - Repository
  - OAI-PMH
  - Research
  - Open Access
  - Metadata
  - EPrints
  properties:
  - type: OpenAPI
    url: openapi/usm-repository-oai-pmh-openapi.yml
  - type: Errors
    url: errors/usm-repository-oai-pmh-errors.yml
  - type: Examples
    url: examples/usm-repository-examples.yml
  - type: Vocabulary
    url: vocabulary/usm-repository-vocabulary.yml
  - type: Lifecycle
    url: lifecycle/usm-repository-lifecycle.yml
  - type: Authentication
    url: authentication/usm-authentication.yml
  - type: Documentation
    url: https://eprints.usm.my/
- aid: usm:eprints-rest
  name: USM Repository EPrints REST and Export
  x-operator: institution
  description: 'Anonymous read interface to Repository@USM beyond OAI-PMH, verified route by route on 2026-09-01. /rest/ exposes
    three datasets (eprint, user, subject); /rest/eprint/{id}.xml returns full EPrints EP2 data XML; /rest/eprint/{id}/{field}.txt
    gives single-field plain-text access; /rest/subject/{id}.xml walks the Library of Congress subject tree; and /cgi/export/eprint/{id}/{format}/{filename}
    serves seventeen verified bibliographic serializations including JSON, RDF/XML, METS, MODS, DIDL, Atom, BibTeX and RIS.
    One soft-404 trap is documented in the contract: /rest/eprint/{id}.json answers HTTP 200 with the repository''s HTML landing
    page, not JSON.'
  humanURL: https://eprints.usm.my/rest/
  baseURL: https://eprints.usm.my
  tags:
  - Repository
  - REST
  - Research
  - Open Access
  - Metadata
  - EPrints
  - Bibliographic
  properties:
  - type: OpenAPI
    url: openapi/usm-repository-eprints-rest-openapi.yml
  - type: JSONSchema
    url: json-schema/usm-eprint-record.json
  - type: Examples
    url: examples/usm-repository-examples.yml
  - type: Authentication
    url: authentication/usm-authentication.yml
  - type: Lifecycle
    url: lifecycle/usm-repository-lifecycle.yml
  - type: Documentation
    url: https://eprints.usm.my/rest/
- aid: usm:shibboleth-idp
  name: USM Shibboleth Identity Provider (SIFULAN / eduGAIN)
  x-operator: federation
  description: 'USM''s own SAML 2.0 Shibboleth identity provider, entityID https://shibsso.usm.my/idp/shibboleth, scope usm.my.
    Registered in the SIFULAN Malaysian Access Federation on 2021-10-30 under registration authority https://sifulan.my, carried
    in SIFULAN''s eduGAIN export, and tagged with the REFEDS Research and Scholarship entity category. Published bindings:
    SSO over HTTP-POST, HTTP-Redirect and POST-SimpleSign plus the Shibboleth 1.0 AuthnRequest profile; SLO over POST, Redirect
    and SOAP; an AttributeAuthority over SAML1 and SAML2 SOAP; artifact resolution over SOAP. In live production use — an
    unauthenticated request to eduvpn.usm.my lands on the IdP''s SAML2 Redirect SSO endpoint. A federation is shared by definition;
    the IdP behind it is USM''s.'
  humanURL: https://www.usm.my
  baseURL: https://shibsso.usm.my/idp/shibboleth
  tags:
  - Identity Federation
  - Shibboleth
  - SAML
  - SSO
  - eduGAIN
  - SIFULAN
  properties:
  - type: Metadata
    url: https://shibsso.usm.my/idp/shibboleth
  - type: FederationMetadata
    url: https://metadata.sifulan.my/metadata.xml
  - type: Authentication
    url: authentication/usm-authentication.yml
  - type: Conformance
    url: conformance/usm-education-standards-conformance.yml
- aid: usm:moodle-ws
  name: e-Learning@USM Moodle Web Services
  x-operator: institution
  description: Self-hosted Moodle at elearning.usm.my with the REST web-service server enabled and token-gated. An unauthenticated
    call returns Moodle's own invalidtoken exception, which proves the service is live rather than absent. The deployment,
    the host and the data are USM's; the contract is Moodle's, so no Moodle specification is saved under this institution
    — the relationship is recorded, the vendor's contract is not.
  humanURL: https://elearning.usm.my/sidang2526/
  baseURL: https://elearning.usm.my/sidang2526/webservice/rest/server.php
  tags:
  - Learning Management
  - Moodle
  - LMS
  - Token Auth
  properties:
  - type: Authentication
    url: authentication/usm-authentication.yml
  - type: Documentation
    url: https://elearning.usm.my/sidang2526/
- aid: usm:crossref-member
  name: Crossref membership — Universiti Sains Malaysia
  x-operator: registry
  description: USM is Crossref member 8963, registering DOIs under prefixes 10.21315 (USM Press journals such as the Malaysian
    Journal of Medical Sciences, Journal of Physical Science, Kajian Malaysia and Tropical Life Sciences Research) and 10.36777.
    As of 2026-09-01 the membership carries 4,955 registered DOIs — 1,365 current and 3,590 backfile. This is a fact about
    USM recorded through a shared registry; Crossref's own contract belongs to Crossref and is not saved here.
  humanURL: https://www.crossref.org/
  baseURL: https://api.crossref.org/members/8963
  tags:
  - Registry
  - DOI
  - Crossref
  - Scholarly Publishing
  - Membership
  properties:
  - type: Registration
    url: https://api.crossref.org/members/8963
  - type: Conformance
    url: conformance/usm-education-standards-conformance.yml
- aid: usm:ror-record
  name: ROR record — Universiti Sains Malaysia
  x-operator: registry
  description: USM's Research Organization Registry identifier, https://ror.org/02rgb2k63. The identifier is the join key
    used by ORCID, Crossref and DataCite to attribute research output to the institution — 4,821 ORCID records carried an
    affiliation to this ROR id on 2026-09-01. Hospital Universiti Sains Malaysia holds a separate ROR record (0090j2029) and
    is not this entity.
  humanURL: https://ror.org/02rgb2k63
  baseURL: https://api.ror.org/v2/organizations/02rgb2k63
  tags:
  - Registry
  - ROR
  - Research Identifiers
  - Membership
  properties:
  - type: Registration
    url: https://ror.org/02rgb2k63
  - type: Conformance
    url: conformance/usm-education-standards-conformance.yml
common:
- type: Website
  url: https://www.usm.my/en/
- type: ResearchRepository
  url: https://eprints.usm.my/
- type: IdentityFederation
  url: https://shibsso.usm.my/idp/shibboleth
- type: LibraryCatalog
  url: https://lib.usm.my/
- type: DeveloperPortal
  url: https://api.usm.my/
- type: Blog
  url: https://news.usm.my/
- type: Support
  url: https://ppkt.usm.my/
- type: AIPolicy
  url: https://cdae.usm.my/images/DownloadPDF/GARIS%20PANDUAN%20PENGGUNAAN%20TEKNOLOGI%20KECERDASAN%20BUATAN%20GENERATIF%20KBG%20DALAM%20PENGAJARAN%20DAN%20PEMBELAJARAN%20PdP%20PENDIDIKAN%20TINGGI.pdf
- type: LinkedIn
  url: https://www.linkedin.com/school/universiti-sains-malaysia-official/
- type: OpenAPI
  url: openapi/usm-repository-oai-pmh-openapi.yml
- type: OpenAPI
  url: openapi/usm-repository-eprints-rest-openapi.yml
- type: JSONSchema
  url: json-schema/usm-eprint-record.json
- type: Examples
  url: examples/usm-repository-examples.yml
- type: Errors
  url: errors/usm-repository-oai-pmh-errors.yml
- type: Authentication
  url: authentication/usm-authentication.yml
- type: Conformance
  url: conformance/usm-education-standards-conformance.yml
- type: Vocabulary
  url: vocabulary/usm-repository-vocabulary.yml
- type: Lifecycle
  url: lifecycle/usm-repository-lifecycle.yml
- type: Rules
  url: rules/usm-rules.yml
- type: JSONLD
  url: json-ld/usm-context.jsonld
- type: DomainSecurity
  url: security/usm-domain-security.yml
- type: Plans
  url: plans/usm-plans-pricing.yml
- type: RateLimits
  url: rate-limits/usm-rate-limits.yml
- type: FinOps
  url: finops/usm-finops.yml
- type: Review
  url: review.yml
x-coverage:
  state: covered
  reason: covered
  detail: 'Three institution-operated machine-readable surfaces were found, probed and contracted on 2026-09-01 — the Repository@USM
    OAI-PMH endpoint, the Repository@USM EPrints REST and export tree, and USM''s own Shibboleth SAML identity provider in
    SIFULAN and eduGAIN — plus a token-gated self-hosted Moodle web-service endpoint and two registry memberships (Crossref
    8963, ROR 02rgb2k63). What USM does NOT have is a developer programme: no catalog, no documentation, no terms, no status
    page, no changelog, no GitHub organization (github.com/usm-my 404), no open-data portal (data.usm.my does not resolve),
    and no declared metadata or data policy — the repository still ships the EPrints default "this server has not yet been
    fully configured" text. The api.usm.my "developer portal" carried in the June 2026 profile as a gated catalog was re-examined
    and is an unmodified TemplateMo "Chain App Dev" HTML template with lorem ipsum copy and info@company.co as its contact;
    it has been removed from apis[] and is retained only as a DeveloperPortal pointer. A previously recorded 403 on www.usm.my
    was a bot challenge, not a dead host — it returns 200 to a browser User-Agent. On the AI axis, the only guidance found
    on a USM host is the Ministry of Higher Education''s national generative-AI guideline (Garis Panduan Penggunaan Teknologi
    Kecerdasan Buatan Generatif dalam PdP Pendidikan Tinggi), republished as a PDF by USM''s Centre for Development of Academic
    Excellence at cdae.usm.my — it is recorded as the AIPolicy pointer because it is the operative guidance, but it is MOHE''s
    document, not a USM-authored policy, and no USM-authored AI policy was found in English or Malay.'
  evidence:
  - url: https://eprints.usm.my/cgi/oai2?verb=Identify
    status: 200
  - url: https://eprints.usm.my/cgi/oai2?verb=ListMetadataFormats
    status: 200
  - url: https://eprints.usm.my/rest/
    status: 200
  - url: https://eprints.usm.my/rest/eprint/16.xml
    status: 200
  - url: https://eprints.usm.my/cgi/export/eprint/16/JSON/x
    status: 200
  - url: https://metadata.sifulan.my/metadata.xml
    status: 200
  - url: https://shibsso.usm.my/idp/shibboleth
    status: 200
  - url: https://elearning.usm.my/sidang2526/webservice/rest/server.php
    status: 200
  - url: https://api.crossref.org/members/8963
    status: 200
  - url: https://api.ror.org/v2/organizations?query=Universiti+Sains+Malaysia
    status: 200
  - url: https://api.datacite.org/providers?query=Universiti+Sains+Malaysia
    status: 200
  - url: https://www.usm.my/en/
    status: 200
  - url: https://api.usm.my/
    status: 200
  - url: https://api.usm.my/openapi.json
    status: 404
  - url: https://github.com/usm-my
    status: 404
  - url: https://data.usm.my/
    status: 0
  - url: https://developer.usm.my/
    status: 0
x-enrichment:
  pipeline: pipeline-university.md
  generated: '2026-09-01'
  method: probed
  note: Re-profiled under the university pipeline's operator axis. No vendor contract was present in this repo to remove;
    the correction here is the api.usm.my portal, which was credited as a gated API catalog and is a stock HTML template.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every provider here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for providers

9 MCP tools reach this
  • find_providersBrowse and filter every provider in the catalog.
  • get_provider_artifactsEvery artifact this provider publishes, grouped by type.
  • get_provider_operationsEvery operation across all of their OpenAPIs — one call instead of parsing every spec.
  • get_provider_toolsEvery MCP tool they ship, with the operation each wraps.
  • get_provider_evidenceHow each part of their score was established. Free — the basis for a claim should not sit behind it.
  • get_provider_ratingPRO — composite, band, trend and facet scores.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This provider
curl "https://apis.io/api/v1/providers/usm"
All providers
curl "https://apis.io/api/v1/providers?limit=25"
Every operation they expose
curl "https://apis.io/api/v1/providers/usm/operations?limit=25"
How their score was established
curl "https://apis.io/api/v1/providers/usm/evidence"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.