King Saud University · Authentication Profile

King Saud University Authentication

Authentication

King Saud University declares 0 security scheme(s) across its OpenAPI definitions.

EducationHigher EducationUniversityPublic Research UniversitySaudi ArabiaMiddle EastRiyadhOpen DataResearch DataIdentity FederationSingle Sign-OnResearchLinked Data
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-09-01'
method: probed
source: >-
  Live anonymous HTTP probes of https://data.ksu.edu.sa on 2026-09-01, plus the
  SAML AuthnRequest issued by https://lms.ksu.edu.sa and the King Saud University
  entity record in the eduGAIN interfederation metadata.
x-operator: institution
summary: >-
  King Saud University runs two entirely separate authentication postures. Its
  open-data distribution surface is fully anonymous — no key, no token, no
  registration. Everything else the university exposes is behind a single
  institutional SAML 2.0 identity provider, and there is no OAuth/OIDC developer
  authorization path of any kind.
surfaces:
  - surface: Open Data distributions
    host: data.ksu.edu.sa
    x-operator: institution
    scheme: none
    anonymous: true
    registration_required: false
    detail: >-
      All 852 dataset distribution files were served to an unauthenticated client
      with no cookie, key or referer. 20 of 20 sampled files returned HTTP 200.
      The open-data licence at https://data.ksu.edu.sa/ar/node/1178 grants use
      "to all persons without discrimination or charge" and asks only for source
      attribution.
    evidence:
      - url: https://data.ksu.edu.sa/sites/data.ksu.edu.sa/files/users/user976/KSU-DMO-OD-DATASET-Employees-1444-AH.json
        status: 200
      - url: https://data.ksu.edu.sa/ar/node/1178
        status: 200
  - surface: Institutional single sign-on (SAML 2.0 identity provider)
    host: iam.ksu.edu.sa
    x-operator: institution
    scheme: saml2
    protocol_binding: HTTP-POST / HTTP-Redirect SP-initiated SSO
    idp_entity_id: http://SSO.ksu.edu.sa/adfs/services/trust
    idp_sso_endpoint: https://iam.ksu.edu.sa/idp/startSSO.ping
    software: PingFederate (the eduGAIN-registered entityID still carries the
      university's earlier ADFS identifier)
    scope: ksu.edu.sa
    registration_authority: https://www.maeen.sa
    federation: Maeen Identity Federation (SA-MIF), a member of eduGAIN since
      2019-07-02; the King Saud University IdP entity has been in eduGAIN since
      2020-02-02.
    detail: >-
      Requesting https://lms.ksu.edu.sa/ returns a self-submitting SAML
      AuthnRequest form whose action is
      https://iam.ksu.edu.sa/idp/startSSO.ping?PartnerSpId=https%3A%2F%2Flms.ksu.edu.sa
      — direct evidence that KSU operates the IdP itself rather than delegating
      identity to a vendor. The IdP's own SAML metadata is not served anonymously
      (/idp/shibboleth and /idp/metadata both 404); it is distributed through the
      Maeen federation into the eduGAIN aggregate.
    evidence:
      - url: https://lms.ksu.edu.sa/
        status: 200
      - url: https://iam.ksu.edu.sa/
        status: 200
      - url: https://mds.edugain.org/edugain-v2.xml
        status: 200
      - url: https://technical.edugain.org/entities?id=671188
        status: 200
      - url: https://iam.ksu.edu.sa/idp/shibboleth
        status: 404
  - surface: Gated end-user applications
    hosts:
      - edugate.ksu.edu.sa
      - my.ksu.edu.sa
      - e.ksu.edu.sa
      - faculty.ksu.edu.sa
    x-operator: institution
    scheme: institutional-login
    detail: >-
      The Edugate student information system, the MyKSU portal, the KSUEgate
      single-sign-on gateway and the faculty portal are end-user web applications
      behind institutional credentials. No public API reference, token endpoint or
      developer registration exists for any of them.
absent:
  - scheme: oauth2
    reason: No authorization server, client registration or token endpoint published.
  - scheme: apiKey
    reason: No key issuance path; the open-data surface needs none.
  - scheme: openIdConnect
    reason: >-
      No .well-known/openid-configuration served on ksu.edu.sa, iam.ksu.edu.sa or
      data.ksu.edu.sa.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/king-saud-university-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.