École Normale Supérieure de Lyon · Authentication Profile

Ens Lyon Authentication

Authentication

École Normale Supérieure de Lyon declares 0 security scheme(s) across its OpenAPI definitions.

UniversityHigher EducationEducationFranceGrande ÉcoleIdentity FederationShibbolethSAMLResearch RepositoryOpen AccessOAI-PMHResearch Computing
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

ens-lyon-authentication.yml Raw ↑
---
# How access to École Normale Supérieure de Lyon's programmable surfaces is actually established.
# NOT an OAuth developer program: ENS de Lyon publishes no API keys and no client registration.
name: École Normale Supérieure de Lyon — authentication and federated identity
slug: ens-lyon
generated: '2026-09-01'
method: probed
source: https://idp.ens-lyon.fr/idp/shibboleth
summary: >-
  ENS de Lyon has no public developer authentication surface — no API key issuance, no OAuth
  client registration, no documented token endpoint for third parties, no developer portal.
  What it does operate is institutional federated identity for its own members, in three
  stacks, all of which answer unauthenticated metadata or protocol requests even though every
  useful operation behind them requires an ENS de Lyon account.
mechanisms:
  - id: shibboleth-idp
    type: saml2-idp
    operator: institution
    entity_id: https://idp.ens-lyon.fr/idp/shibboleth
    metadata_url: https://idp.ens-lyon.fr/idp/shibboleth
    authoritative_metadata_url: https://mdq.federation.renater.fr/fer/entities/https%3A%2F%2Fidp.ens-lyon.fr%2Fidp%2Fshibboleth
    scopes_asserted:
      - ens-lyon.fr
    protocols:
      - urn:mace:shibboleth:1.0
      - urn:oasis:names:tc:SAML:1.1:protocol
      - urn:oasis:names:tc:SAML:2.0:protocol
    sso_endpoints:
      - binding: urn:mace:shibboleth:1.0:profiles:AuthnRequest
        location: https://idp.ens-lyon.fr/idp/profile/Shibboleth/SSO
      - binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
        location: https://idp.ens-lyon.fr/idp/profile/SAML2/POST/SSO
      - binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect
        location: https://idp.ens-lyon.fr/idp/profile/SAML2/Redirect/SSO
    federation: Fédération Éducation-Recherche (RENATER), exported to eduGAIN
    registration_authority: https://federation.renater.fr/
    entity_categories:
      - http://refeds.org/category/research-and-scholarship
    technical_contact: admin-system@ens-lyon.fr
    host_resolution: idp.ens-lyon.fr -> lxc-idp.ens-lyon.fr -> 140.77.167.96 (ENS de Lyon allocation)
    audience: ENS de Lyon staff, students and federated service providers
    public_client_registration: false
    probed:
      status: 200
      content_type: application/xml;charset=UTF-8
      bytes: 12129
      date: '2026-09-01'
    note: >-
      The copy served from idp.ens-lyon.fr is the Shibboleth stock template — it still carries
      the "This is example metadata only" comment and the commented-out mdui block. It is
      nonetheless a valid EntityDescriptor with the real entityID, the real ens-lyon.fr scope
      and the real signing key. The signed, curated metadata is RENATER's, recorded below.
    method: probed
    source: https://idp.ens-lyon.fr/idp/shibboleth
  - id: renater-fer-entity
    type: federation-metadata
    operator: federation
    mdq_base: https://mdq.federation.renater.fr/
    namespaces_present:
      - fer
      - edugain
      - fer+edugain
    entity_id: https://idp.ens-lyon.fr/idp/shibboleth
    required_accept_header: application/samlmetadata+xml
    aggregate_url: https://metadata.federation.renater.fr/renater/main/main-idps-renater-metadata.xml
    organization_name: Ecole Normale Supérieure de Lyon
    display_name:
      fr: ENS de Lyon
      en: ENS de Lyon
    probed:
      status: 200
      bytes_fer: 9123
      bytes_edugain: 9541
      aggregate_entities: 344
      aggregate_contains_ens_lyon: true
      date: '2026-09-01'
    note: >-
      A federation is shared by definition; recording it is not a misattribution. The IdP the
      metadata describes is ENS de Lyon's own, and RENATER is the registration authority.
    method: probed
    source: https://mdq.federation.renater.fr/fer/entities/https%3A%2F%2Fidp.ens-lyon.fr%2Fidp%2Fshibboleth
  - id: entra-id-tenant
    type: oidc-and-saml2
    operator: federation
    tenant_id: c30cf67d-aee4-44f6-8f1b-12f4935b7d2c
    tenant_region_scope: EU
    issuer: https://login.microsoftonline.com/c30cf67d-aee4-44f6-8f1b-12f4935b7d2c/v2.0
    discovery_url: https://login.microsoftonline.com/ens-lyon.fr/v2.0/.well-known/openid-configuration
    authorization_endpoint: https://login.microsoftonline.com/c30cf67d-aee4-44f6-8f1b-12f4935b7d2c/oauth2/v2.0/authorize
    token_endpoint: https://login.microsoftonline.com/c30cf67d-aee4-44f6-8f1b-12f4935b7d2c/oauth2/v2.0/token
    jwks_uri: https://login.microsoftonline.com/c30cf67d-aee4-44f6-8f1b-12f4935b7d2c/discovery/v2.0/keys
    saml_metadata_url: https://login.microsoftonline.com/c30cf67d-aee4-44f6-8f1b-12f4935b7d2c/federationmetadata/2007-06/federationmetadata.xml
    audience: ENS de Lyon accounts on Microsoft 365 and SAML-integrated internal systems
    public_client_registration: false
    probed:
      oidc_status: 200
      oidc_bytes: 1964
      saml_status: 200
      saml_bytes: 28441
      date: '2026-09-01'
    note: >-
      login.microsoftonline.com is Microsoft's host and Microsoft's contract. The TENANT is
      ENS de Lyon's, resolved from the ens-lyon.fr domain hint, which is why this is recorded
      as federation and no Microsoft specification is saved under this institution.
    method: probed
    source: https://login.microsoftonline.com/ens-lyon.fr/v2.0/.well-known/openid-configuration
  - id: cas-sso
    type: cas3
    operator: institution
    base_url: https://cas.ens-lyon.fr/cas/
    login_endpoint: https://cas.ens-lyon.fr/cas/login
    validate_endpoint: https://cas.ens-lyon.fr/cas/p3/serviceValidate
    host_resolution: cas.ens-lyon.fr -> 140.77.51.3 (ENS de Lyon allocation)
    audience: ENS de Lyon accounts on internally integrated web services
    public_client_registration: false
    probed:
      status: 200
      bytes: 167
      response: >-
        <cas:serviceResponse xmlns:cas='http://www.yale.edu/tp/cas'><cas:authenticationFailure
        code="INVALID_REQUEST"/></cas:serviceResponse>
      date: '2026-09-01'
    note: >-
      Apereo CAS on ENS de Lyon's own host. The protocol surface is real and probeable; there
      is no third-party client registration and no published integration guide, so it is
      institutional plumbing rather than a developer program.
    method: probed
    source: https://cas.ens-lyon.fr/cas/p3/serviceValidate
tenant_access:
  - id: hal-deposit
    platform: HAL (CCSD / CNRS)
    operator: tenant
    note: >-
      Depositing into the ens-lyon collection uses HAL's own credentials and HAL's SWORD
      endpoint at api.archives-ouvertes.fr/sword/. That endpoint is generic — it carries no
      ENS de Lyon scope — so it is HAL's contract, not ENS de Lyon's, and it is not recorded
      as one of this institution's APIs. Read access to the ens-lyon scope is unauthenticated.
    method: probed
    source: https://api.archives-ouvertes.fr/docs/sword
absent:
  - api_keys: not issued
  - oauth_client_registration: none published
  - developer_portal: none; api.ens-lyon.fr and developer.ens-lyon.fr do not resolve
  - scim_provisioning: not publicly exposed

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ens-lyon-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.