EPFL · OAuth Scopes

EPFL OAuth Scopes

OAuth 2.0 probed

EPFL uses OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (e.g. client-credentials or role-based authorization) rather than per-scope consent.

This index is generated from the provider’s OpenAPI security definitions (and, where available, its documented scope reference) and refreshes on every APIs.io network build. Browse every provider’s scopes at scopes.apis.io.

UniversityHigher EducationEducationTechnical UniversityResearchResearch RepositoryOpen AccessIdentity FederationNewsEventSwitzerlandEurope
Scopes: 0 Flows: Method: probed

Scopes (0)

EPFL implements OAuth 2.0 but publishes no discrete scopes — access is governed by the grant itself (client-credentials or role-based authorization) rather than per-scope consent.

EPFL operates NO OAuth 2.0 or OpenID Connect authorization server that is reachable from the public internet — no /.well-known/openid-configuration is served on any EPFL host probed on 2026-08-19, and neither public API declares an oauth2 security scheme. So there are no OAuth scopes to record, and inventing some would be fabrication. What EPFL does operate is a SAML attribute-release surface, and that is the institution's real authorization vocabulary. It is published in the SWITCHaai federation metadata and is recorded here in its place.

Source

OAuth Scopes

Raw ↑
generated: '2026-08-19'
method: probed
source: >-
  openapi/_original/epfl-actu.yaml, openapi/_original/epfl-memento.yaml,
  and the SWITCHaai federation metadata aggregate
  https://metadata.aai.switch.ch/metadata.switchaai.xml
x-operator: institution
note: >-
  EPFL operates NO OAuth 2.0 or OpenID Connect authorization server that is reachable from the
  public internet — no /.well-known/openid-configuration is served on any EPFL host probed on
  2026-08-19, and neither public API declares an oauth2 security scheme. So there are no OAuth
  scopes to record, and inventing some would be fabrication. What EPFL does operate is a SAML
  attribute-release surface, and that is the institution's real authorization vocabulary. It is
  published in the SWITCHaai federation metadata and is recorded here in its place.
oauth:
  present: false
  evidence: >-
    No oauth2 or openIdConnect securityScheme in any EPFL contract; the only schemes the public
    APIs declare are DRF tokenAuth (apiKey in header, "Authorization: Token <key>") and
    basicAuth. Both public APIs are read-only and answer unauthenticated (Allow: GET, HEAD,
    OPTIONS).
saml_attribute_release:
  federation: SWITCHaai (SWITCH edu-ID), exported to eduGAIN
  idp_entity_id: https://idp.epfl.ch/idp/shibboleth
  idp_entity_categories:
  - http://refeds.org/category/research-and-scholarship
  - https://refeds.org/sirtfi
  service_providers:
  - entity_id: https://tequila.epfl.ch/shibboleth
    operator: institution
    status: stale
    status_note: >-
      Registered in the federation aggregate, but tequila.epfl.ch does not resolve in public DNS as
      of 2026-08-19 (empty answer from 8.8.8.8 and 1.1.1.1). The attribute-release request below is
      real published metadata; the service behind it is not publicly reachable.
    acs: https://tequila.epfl.ch/Shibboleth.sso/SAML2/POST
    requested_attributes:
    - {friendly_name: uid, oid: urn:oid:0.9.2342.19200300.100.1.1}
    - {friendly_name: email, oid: urn:oid:0.9.2342.19200300.100.1.3}
    - {friendly_name: givenName, oid: urn:oid:2.5.4.42}
    - {friendly_name: surname, oid: urn:oid:2.5.4.4}
    - {friendly_name: displayName, oid: urn:oid:2.16.840.1.113730.3.1.241}
    - {friendly_name: eduPersonAffiliation, oid: 'urn:oid:1.3.6.1.4.1.5923.1.1.1.1'}
    - {friendly_name: eduPersonTargetedID, oid: 'urn:oid:1.3.6.1.4.1.5923.1.1.1.10'}
    - {friendly_name: eduPersonPrimaryOrgUnitDN, oid: 'urn:oid:1.3.6.1.4.1.5923.1.1.1.8'}
    - {friendly_name: swissEduPersonUniqueID, oid: 'urn:oid:2.16.756.1.2.5.1.1.1'}
    - {friendly_name: swissEduPersonHomeOrganization, oid: 'urn:oid:2.16.756.1.2.5.1.1.4'}
    - {friendly_name: swissEduPersonHomeOrganizationType, oid: 'urn:oid:2.16.756.1.2.5.1.1.5'}
    - {friendly_name: swissEduPersonStudyBranch3, oid: 'urn:oid:2.16.756.1.2.5.1.1.8'}
    - {friendly_name: swissEduPersonStudyLevel, oid: 'urn:oid:2.16.756.1.2.5.1.1.9'}
    - {friendly_name: swissEduPersonStaffCategory, oid: 'urn:oid:2.16.756.1.2.5.1.1.10'}
    - {friendly_name: swissEduPersonMatriculationNumber, oid: 'urn:oid:2.16.756.1.2.5.1.1.11'}
    - {friendly_name: swissEduPersonCardUID, oid: 'urn:oid:2.16.756.1.2.5.1.1.12'}
  - entity_id: https://companion.epfl.ch/shibboleth
    operator: institution
    status: live
    status_note: 'companion.epfl.ch resolves to 128.178.218.80 and returns HTTP 200 (probed 2026-08-19).'
    acs: https://companion.epfl.ch/Shibboleth.sso/SAML2/POST
    requested_attributes:
    - {friendly_name: eduPersonAffiliation, oid: 'urn:oid:1.3.6.1.4.1.5923.1.1.1.1'}
    - {friendly_name: eduPersonScopedAffiliation, oid: 'urn:oid:1.3.6.1.4.1.5923.1.1.1.9'}
    - {friendly_name: eduPersonTargetedID, oid: 'urn:oid:1.3.6.1.4.1.5923.1.1.1.10'}
    - {friendly_name: email, oid: urn:oid:0.9.2342.19200300.100.1.3}
    - {friendly_name: givenName, oid: urn:oid:2.5.4.42}
    - {friendly_name: surname, oid: urn:oid:2.5.4.4}
    - {friendly_name: swissEduPersonUniqueID, oid: 'urn:oid:2.16.756.1.2.5.1.1.1'}
    - {friendly_name: swissEduPersonHomeOrganization, oid: 'urn:oid:2.16.756.1.2.5.1.1.4'}
    - {friendly_name: swissEduPersonHomeOrganizationType, oid: 'urn:oid:2.16.756.1.2.5.1.1.5'}