Ghent University · Authentication Profile

Ghent Authentication

Authentication

Ghent University declares 0 security scheme(s) across its OpenAPI definitions.

UniversityHigher EducationEducationResearchResearch DataLibraryOpen DataIdentity FederationOAI-PMHBelgiumFlandersEurope
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-09-01'
method: probed
source: https://biblio.ugent.be/doc/api
x-operator: institution
note: >-
  How each Ghent University surface authenticates. Verified by live probe on 2026-09-01
  except where a contract is cited. No credential, key-request flow or OAuth endpoint was
  invented; where a surface is genuinely open, that is recorded as open.
surfaces:
  - surface: Ghent University Academic Bibliography (REST search, exports, OAI-PMH, SRU, unAPI, feeds, dumps)
    base_url: https://biblio.ugent.be
    scheme: none
    public: true
    detail: >-
      No API key, token or registration. Anonymous GET returned 200 on the search API, both
      OAI-PMH verbs, SRU searchRetrieve, unAPI, the sitemap index and the RSS feeds.
      Metadata is licensed ODbL, so reuse is permitted with attribution and share-alike.
    evidence:
      - { url: 'https://biblio.ugent.be/publication?q=dna&format=json', status: 200 }
      - { url: 'https://biblio.ugent.be/oai?verb=Identify', status: 200 }
      - { url: 'https://biblio.ugent.be/sru?version=1.1&operation=searchRetrieve&query=dna', status: 200 }
  - surface: Hydra Resto API
    base_url: https://hydra.ugent.be/api/2.0/resto
    scheme: none
    public: true
    detail: Anonymous GET returned 200 on every documented endpoint.
    evidence:
      - { url: 'https://hydra.ugent.be/api/2.0/resto/meta.json', status: 200 }
      - { url: 'https://hydra.ugent.be/api/2.0/resto/menu/en/2026/9/1.json', status: 200 }
  - surface: People Service
    contract: openapi/ghent-people-service-openapi.yaml
    scheme: apiKey
    location: header
    parameter_name: X-Api-Key
    public: false
    detail: >-
      Stated in the service's own README - PEOPLE_API_KEY is "used in authentication header
      X-Api-Key for server (openapi)". The service is deployed inside the university estate;
      no public base URL is published and no key issuance process is public.
    evidence:
      - { url: 'https://raw.githubusercontent.com/ugent-library/people-service/main/README.md', status: 200 }
  - surface: Projects Service
    contract: openapi/ghent-projects-service-openapi.yaml
    scheme: apiKey
    public: false
    detail: PROJECTS_API_KEY is a required environment variable named "REST API Key" in the service README.
    evidence:
      - { url: 'https://raw.githubusercontent.com/ugent-library/projects-service/main/README.md', status: 200 }
  - surface: OAI Service (administrative write API behind the bibliography's OAI-PMH endpoint)
    contract: openapi/ghent-oai-service-openapi.yaml
    scheme: unknown
    public: false
    detail: >-
      The contract declares no securitySchemes. The operations are all writes
      (add-metadata-format, add-set, add-item, add-record, delete-record) against an internal
      deployment, so an unauthenticated public deployment is not implied. Recorded as unknown
      rather than none.
  - surface: Ghent University SAML 2.0 Identity Provider
    base_url: https://identity.ugent.be/simplesaml/saml2/idp/metadata.php
    scheme: saml2
    public: true
    detail: >-
      Metadata document is publicly readable and signed; authentication through it is
      federated via the Belnet R&E Federation. This is the institution's own IdP, operated by
      Directie ICT.
    evidence:
      - { url: 'https://identity.ugent.be/simplesaml/saml2/idp/metadata.php', status: 200 }

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/ghent-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.