Curtin University · Authentication Profile
Curtin Authentication
Authentication
Curtin University declares 0 security scheme(s) across its OpenAPI definitions.
UniversityHigher EducationEducationResearchOpen AccessOpen DataCourse CatalogLibraryIdentity FederationResearch DataAustraliaWestern AustraliaAustralian Technology Network
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
authentication:
generated: '2026-08-30'
method: derived
x-evidence-method: probed
x-authorship: >-
Generated by API Evangelist from live unauthenticated probes. Curtin University
published none of this; the institution's own material is only the responses quoted.
source:
- https://api.coki.ac/search/curtin
- https://www.curtin.edu.au/wp-json/mimas/v1/search/elastic?query=engineering
- https://www.curtin.edu.au/wp-json/mcp/mcp-adapter-default-server
- https://www.curtin.edu.au/wp-json/wp-abilities/v1/abilities
- https://aefbfwfqc4.execute-api.ap-southeast-2.amazonaws.com/prod/AMP/Catalogs
- https://idpp1.curtin.edu.au/idp/shibboleth
note: >-
Curtin University publishes no developer portal, no API key issuance process and no written
authentication documentation for any surface below. Every statement here is the observed
behaviour of a live, unauthenticated request made on 2026-08-30.
surfaces:
- name: Curtin Web Platform API (mimas/v1)
x-operator: institution
x-operator-note: >-
www.curtin.edu.au CNAMEs to wp183.host.pressdns.com — managed WordPress hosting. That is
infrastructure, not a platform contract Curtin runs under: the mimas theme, its routes and
its Elasticsearch indices are Curtin's own. A DNS-resolving audit will flag this host as a
pressdns.com tenant; that reading is wrong and is recorded here so it is not re-adopted.
base: https://www.curtin.edu.au/wp-json
scheme: none
credential: none
observed: >-
HTTP 200 on GET /mimas/v1, /mimas/v1/global-menu, /mimas/v1/global-menu/html,
/mimas/v1/footer, /mimas/v1/site-menu, /mimas/v1/search/facets,
/mimas/v1/search/quick-links and /mimas/v1/search/elastic with no credential of any kind.
exception: >-
GET /mimas/v1/header returns HTTP 403 rest_forbidden — "Access denied: This endpoint can
only be accessed from allowed domains." A referer/origin allow list, not a credential.
cors: not asserted
- name: WordPress core REST API on www.curtin.edu.au
x-operator: institution
base: https://www.curtin.edu.au/wp-json/wp/v2
scheme: none for read, cookie + nonce for write
credential: none
observed: >-
HTTP 200 on GET /wp/v2/pages and GET /wp/v2/search with no credential. The contract is
WordPress core's, not Curtin's — recorded here because the deployment is Curtin's and the
read surface is genuinely public.
- name: WordPress MCP adapter on www.curtin.edu.au
x-operator: institution
base: https://www.curtin.edu.au/wp-json/mcp
scheme: WordPress application password or cookie + nonce
credential: required
observed: >-
GET /mcp lists two registered MCP servers (mcp-adapter-default-server,
wpdatatables-mcp-server). Both return HTTP 401 rest_forbidden unauthenticated, as does
/wp-abilities/v1/abilities. Curtin has an MCP surface registered on its public web
platform and it is closed to anonymous callers. No deployment manifest or agent card is
published, so no mcp/ artifact is recorded in this repository.
- name: COKI Open Access Dashboard API
x-operator: institution
base: https://api.coki.ac
scheme: none
credential: none
observed: >-
HTTP 200 on /search/{text}, /institutions, /countries, /institution/{ror} and
/country/{iso3} with no credential. Response header access-control-allow-origin is `*`,
so the API is callable directly from a browser. cache-control max-age=14400,
s-maxage=604800. Unknown paths return HTTP 404 with the plain body `Not found`.
rate_limits: none published; none observed during probing
- name: Curtin Data Platform (AMP)
x-operator: institution
base: https://aefbfwfqc4.execute-api.ap-southeast-2.amazonaws.com/prod/AMP
scheme: AWS Cognito user pool via Amplify
credential: required
observed: >-
GET /AMP/Catalogs and GET /AMP/Dashboards both return HTTP 401 {"message":"Unauthorized"}
unauthenticated. The front end at data.curtin.edu.au ships @aws-amplify Auth and a Cognito
identity/idp configuration. Curtin staff and student credentials only; no public
registration path was found.
- name: Curtin Shibboleth Identity Provider
x-operator: tenant
x-operator-evidence: >-
idpp1.curtin.edu.au CNAMEs to 1f0b5d9aaec3f802f7411017de5ea657.idp-cname.aaf.edu.au —
the Australian Access Federation's managed IdP service. Curtin is the identity authority;
AAF operates the Shibboleth deployment. The companion service provider at
auth.lis.curtin.edu.au resolves to Curtin's own Kubernetes cluster and IS
institution-operated.
base: https://idpp1.curtin.edu.au/idp
scheme: SAML 2.0 (Shibboleth IdP)
credential: institutional account
observed: >-
GET https://idpp1.curtin.edu.au/idp/shibboleth returns HTTP 200 application/xml — the
IdP's own SAML 2.0 entity metadata, served without credentials. Bindings advertised:
HTTP-POST, HTTP-Redirect and HTTP-POST-SimpleSign at
/idp/profile/SAML2/{POST,Redirect,POST-SimpleSign}/SSO. shibmd:Scope is curtin.edu.au.
federation: >-
Registered in the Australian Access Federation aggregate (md.aaf.edu.au/aaf-metadata.xml)
as entityID https://idpp1.curtin.edu.au/idp/shibboleth, OrganizationDisplayName
"Curtin University". Curtin also operates the service provider
https://auth.lis.curtin.edu.au/shibboleth, whose metadata is served at
https://auth.lis.curtin.edu.au/Shibboleth.sso/Metadata (HTTP 200,
application/samlmetadata+xml).
- name: Curtin Curate research repository
x-operator: tenant
base: https://curate.curtin.edu.au
scheme: not determinable
credential: unknown
observed: >-
Every request returns HTTP 202 with an AWS WAF JavaScript challenge whose
awsWafCookieDomainList is ["figshare.com"]. No API behaviour could be probed. Figshare
operates the platform; the tenant is Curtin's.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/curtin-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.