École Normale Supérieure de Paris · Authentication Profile

Ens Paris Authentication

Authentication

Authentication posture across the surfaces École Normale Supérieure - PSL actually operates. This file replaces an earlier version derived from the French Ministry (MESR) Opendatasoft Explore API, a contract ENS does not operate; that surface and everything derived from it was removed from this repository on 2026-08-30.

École Normale Supérieure de Paris secures its APIs with saml, basic, and none across 4 declared security schemes, as derived from its OpenAPI definitions.

UniversityHigher EducationEducationFranceUniversité PSLResearchIdentity FederationLibraryOpen AccessOAI-PMH
Methods: saml, basic, none Schemes: 4 OAuth flows: API key in:

Security Schemes

shibboleth-saml2 saml
koha-public-anonymous none
koha-basic basic
oai-pmh-anonymous none

Source

Authentication Profile

ens-paris-authentication.yml Raw ↑
generated: '2026-08-30'
method: probed
authorship: generated by API Evangelist from live probes; not authored by the institution.
source: live HTTP probes of federation.ens.psl.eu and catalogue.bib.ens.psl.eu on 2026-08-30
description: >-
  Authentication posture across the surfaces École Normale Supérieure - PSL actually operates.
  This file replaces an earlier version derived from the French Ministry (MESR) Opendatasoft
  Explore API, a contract ENS does not operate; that surface and everything derived from it was
  removed from this repository on 2026-08-30.
summary:
  types:
    - saml
    - basic
    - none
  api_key_in: []
  notes: >-
    ENS-PSL publishes no API key programme, no OAuth authorization server, and no developer
    registration of any kind. Machine access is either unauthenticated (public catalogue reads,
    OAI-PMH harvesting) or federated through the institution's own SAML IdP.
schemes:
  - name: shibboleth-saml2
    type: saml
    surface: ENS-PSL Identity Provider
    x-operator: institution
    entityID: https://federation.ens.psl.eu/idp/shibboleth
    metadata: https://federation.ens.psl.eu/idp/shibboleth
    bindings:
      - urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
      - urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect
      - urn:mace:shibboleth:1.0:profiles:AuthnRequest
    scopes:
      - ens.fr
      - ens.psl.eu
    federation: RENATER Fédération Éducation-Recherche
    description: >-
      Institutional single sign-on. Access is granted to federation members, not to self-serve
      developers; there is no way for an unaffiliated caller to obtain a credential.
    sources:
      - https://federation.ens.psl.eu/idp/shibboleth
      - https://metadata.federation.renater.fr/renater/main/main-idps-renater-metadata.xml
  - name: koha-public-anonymous
    type: none
    surface: ENS-PSL library catalogue REST API (public routes)
    x-operator: institution
    description: >-
      The /api/v1/public/* routes of the ENS-PSL Koha deployment answer without credentials.
      Verified against /api/v1/public/libraries (HTTP 200, application/json, real ENS library
      records) and /api/v1/public/items (HTTP 200).
    sources:
      - https://catalogue.bib.ens.psl.eu/api/v1/public/libraries
  - name: koha-basic
    type: basic
    surface: ENS-PSL library catalogue REST API (patron and staff routes)
    x-operator: institution
    description: >-
      Non-public Koha REST routes require a patron or staff credential issued by the library.
      Not obtainable by an outside caller; no registration surface is published.
    sources:
      - https://catalogue.bib.ens.psl.eu/api/v1/.html
  - name: oai-pmh-anonymous
    type: none
    surface: OAI-PMH harvesting (ENS-PSL catalogue, and the HAL ENS-PARIS collection)
    x-operator: institution + tenant
    description: >-
      Both OAI-PMH providers answer unauthenticated. The catalogue provider is ENS-operated; the
      HAL provider is operated by CCSD/CNRS and ENS is a collection within it.
    sources:
      - https://catalogue.bib.ens.psl.eu/cgi-bin/koha/oai.pl?verb=Identify
      - https://api.archives-ouvertes.fr/oai/hal/?verb=Identify

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ens-paris-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.