Curtin University · Authentication Profile

Curtin Authentication

Authentication

Curtin University declares 0 security scheme(s) across its OpenAPI definitions.

UniversityHigher EducationEducationResearchOpen AccessOpen DataCourse CatalogLibraryIdentity FederationResearch DataAustraliaWestern AustraliaAustralian Technology Network
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
authentication:
  generated: '2026-08-30'
  method: derived
  x-evidence-method: probed
  x-authorship: >-
    Generated by API Evangelist from live unauthenticated probes. Curtin University
    published none of this; the institution's own material is only the responses quoted.
  source:
    - https://api.coki.ac/search/curtin
    - https://www.curtin.edu.au/wp-json/mimas/v1/search/elastic?query=engineering
    - https://www.curtin.edu.au/wp-json/mcp/mcp-adapter-default-server
    - https://www.curtin.edu.au/wp-json/wp-abilities/v1/abilities
    - https://aefbfwfqc4.execute-api.ap-southeast-2.amazonaws.com/prod/AMP/Catalogs
    - https://idpp1.curtin.edu.au/idp/shibboleth
  note: >-
    Curtin University publishes no developer portal, no API key issuance process and no written
    authentication documentation for any surface below. Every statement here is the observed
    behaviour of a live, unauthenticated request made on 2026-08-30.
  surfaces:
    - name: Curtin Web Platform API (mimas/v1)
      x-operator: institution
      x-operator-note: >-
        www.curtin.edu.au CNAMEs to wp183.host.pressdns.com — managed WordPress hosting. That is
        infrastructure, not a platform contract Curtin runs under: the mimas theme, its routes and
        its Elasticsearch indices are Curtin's own. A DNS-resolving audit will flag this host as a
        pressdns.com tenant; that reading is wrong and is recorded here so it is not re-adopted.
      base: https://www.curtin.edu.au/wp-json
      scheme: none
      credential: none
      observed: >-
        HTTP 200 on GET /mimas/v1, /mimas/v1/global-menu, /mimas/v1/global-menu/html,
        /mimas/v1/footer, /mimas/v1/site-menu, /mimas/v1/search/facets,
        /mimas/v1/search/quick-links and /mimas/v1/search/elastic with no credential of any kind.
      exception: >-
        GET /mimas/v1/header returns HTTP 403 rest_forbidden — "Access denied: This endpoint can
        only be accessed from allowed domains." A referer/origin allow list, not a credential.
      cors: not asserted
    - name: WordPress core REST API on www.curtin.edu.au
      x-operator: institution
      base: https://www.curtin.edu.au/wp-json/wp/v2
      scheme: none for read, cookie + nonce for write
      credential: none
      observed: >-
        HTTP 200 on GET /wp/v2/pages and GET /wp/v2/search with no credential. The contract is
        WordPress core's, not Curtin's — recorded here because the deployment is Curtin's and the
        read surface is genuinely public.
    - name: WordPress MCP adapter on www.curtin.edu.au
      x-operator: institution
      base: https://www.curtin.edu.au/wp-json/mcp
      scheme: WordPress application password or cookie + nonce
      credential: required
      observed: >-
        GET /mcp lists two registered MCP servers (mcp-adapter-default-server,
        wpdatatables-mcp-server). Both return HTTP 401 rest_forbidden unauthenticated, as does
        /wp-abilities/v1/abilities. Curtin has an MCP surface registered on its public web
        platform and it is closed to anonymous callers. No deployment manifest or agent card is
        published, so no mcp/ artifact is recorded in this repository.
    - name: COKI Open Access Dashboard API
      x-operator: institution
      base: https://api.coki.ac
      scheme: none
      credential: none
      observed: >-
        HTTP 200 on /search/{text}, /institutions, /countries, /institution/{ror} and
        /country/{iso3} with no credential. Response header access-control-allow-origin is `*`,
        so the API is callable directly from a browser. cache-control max-age=14400,
        s-maxage=604800. Unknown paths return HTTP 404 with the plain body `Not found`.
      rate_limits: none published; none observed during probing
    - name: Curtin Data Platform (AMP)
      x-operator: institution
      base: https://aefbfwfqc4.execute-api.ap-southeast-2.amazonaws.com/prod/AMP
      scheme: AWS Cognito user pool via Amplify
      credential: required
      observed: >-
        GET /AMP/Catalogs and GET /AMP/Dashboards both return HTTP 401 {"message":"Unauthorized"}
        unauthenticated. The front end at data.curtin.edu.au ships @aws-amplify Auth and a Cognito
        identity/idp configuration. Curtin staff and student credentials only; no public
        registration path was found.
    - name: Curtin Shibboleth Identity Provider
      x-operator: tenant
      x-operator-evidence: >-
        idpp1.curtin.edu.au CNAMEs to 1f0b5d9aaec3f802f7411017de5ea657.idp-cname.aaf.edu.au —
        the Australian Access Federation's managed IdP service. Curtin is the identity authority;
        AAF operates the Shibboleth deployment. The companion service provider at
        auth.lis.curtin.edu.au resolves to Curtin's own Kubernetes cluster and IS
        institution-operated.
      base: https://idpp1.curtin.edu.au/idp
      scheme: SAML 2.0 (Shibboleth IdP)
      credential: institutional account
      observed: >-
        GET https://idpp1.curtin.edu.au/idp/shibboleth returns HTTP 200 application/xml — the
        IdP's own SAML 2.0 entity metadata, served without credentials. Bindings advertised:
        HTTP-POST, HTTP-Redirect and HTTP-POST-SimpleSign at
        /idp/profile/SAML2/{POST,Redirect,POST-SimpleSign}/SSO. shibmd:Scope is curtin.edu.au.
      federation: >-
        Registered in the Australian Access Federation aggregate (md.aaf.edu.au/aaf-metadata.xml)
        as entityID https://idpp1.curtin.edu.au/idp/shibboleth, OrganizationDisplayName
        "Curtin University". Curtin also operates the service provider
        https://auth.lis.curtin.edu.au/shibboleth, whose metadata is served at
        https://auth.lis.curtin.edu.au/Shibboleth.sso/Metadata (HTTP 200,
        application/samlmetadata+xml).
    - name: Curtin Curate research repository
      x-operator: tenant
      base: https://curate.curtin.edu.au
      scheme: not determinable
      credential: unknown
      observed: >-
        Every request returns HTTP 202 with an AWS WAF JavaScript challenge whose
        awsWafCookieDomainList is ["figshare.com"]. No API behaviour could be probed. Figshare
        operates the platform; the tenant is Curtin's.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/curtin-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.