Brown Authentication
Brown's programmable surface has two authentication stories and they do not meet. The public BDR API has no authentication at all — no key, no OAuth, no registration, nothing to obtain. The institution's real identity infrastructure is a SAML 2.0 Shibboleth identity provider registered in InCommon, which is a browser SSO protocol and is not usable as API credentials. There is no bridge: no OAuth authorization server, no token endpoint, no OIDC discovery document, no dynamic client registration, no protected-resource metadata. An agent or a script cannot authenticate to anything at Brown; it can only read what is already public.
Brown University declares 0 security scheme(s) across its OpenAPI definitions.
Security Schemes
Source
Authentication Profile
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.