Kyoto University · Authentication Profile
Kyoto Authentication
Authentication
Kyoto University secures its APIs with none, saml, and session across 6 declared security schemes, as derived from its OpenAPI definitions.
UniversityHigher EducationEducationJapanNational UniversityResearch RepositoryResearch DataIdentity FederationLearning ManagementOpen AccessResearch ComputingScholarly
Methods: none, saml, session
Schemes: 6
OAuth flows:
API key in:
Security Schemes
KurenaiPublicRead none
KurenaiOaiPmhPublic none
PandaAnonymousRead none
PandaSakaiSession session
KyotoShibbolethIdP saml
KudpcShibbolethSP saml
Source
Authentication Profile
generated: '2026-08-19'
method: probed
source: >-
Live probes on 2026-08-19 of every surface attributed to Kyoto University, plus
openapi/kyoto-lms-api-openapi.yml, openapi/kyoto-rest-api-openapi.yml and
openapi/kyoto-oai-pmh-api-openapi.yml. No credential was sent to any host and no authentication
was attempted; gated surfaces are described by the status they return to an anonymous caller.
provider: Kyoto University
providerId: kyoto
summary:
types:
- none
- saml
- session
institution_operated_public_apis_requiring_no_auth: 3
oauth2: false
api_keys: false
schemes:
- name: KurenaiPublicRead
type: none
operator: institution
applies_to: https://repository.kulib.kyoto-u.ac.jp
description: >-
KURENAI's public surfaces are anonymous reads. The DSpace 7.6 REST root, the community and
collection listings, and the whole OAI-PMH 2.0 endpoint answer with no credential. Item
submission and administrative endpoints require a repository account and were not exercised.
evidence:
url: https://repository.kulib.kyoto-u.ac.jp/server/api/core/communities
status: 200
- name: KurenaiOaiPmhPublic
type: none
operator: institution
applies_to: https://repository.kulib.kyoto-u.ac.jp/server/oai/request
description: >-
OAI-PMH 2.0 harvesting is open by design; verb=Identify, verb=ListMetadataFormats and
verb=ListRecords all answer anonymously.
evidence:
url: https://repository.kulib.kyoto-u.ac.jp/server/oai/request?verb=Identify
status: 200
- name: PandaAnonymousRead
type: none
operator: institution
applies_to: https://panda.ecs.kyoto-u.ac.jp/direct
description: >-
The Sakai Entity Broker answers anonymously on the public prefixes. /direct/tool.json returns
the full 96-entry tool registry; /direct/site.json, /direct/syllabus.json,
/direct/announcement.json, /direct/assignment.json, /direct/calendar.json, /direct/content.json
and /direct/lti.json return their envelope with an empty collection, and /direct/session.json
returns a session object with null id, userId and userEid. No course, roster or personal data is
exposed without a session.
evidence:
url: https://panda.ecs.kyoto-u.ac.jp/direct/tool.json
status: 200
- name: PandaSakaiSession
type: session
operator: institution
applies_to: https://panda.ecs.kyoto-u.ac.jp
description: >-
Privileged PandA entities require an authenticated Sakai session established through the
university login (ECS-ID for students, SPS-ID for faculty and staff), which is itself federated
through the IIMC Shibboleth IdP with multi-factor authentication. The boundary is enforced and
differentiated: /direct/poll.json returns 401, /direct/user.json returns 403, and
/direct/membership.json returns 400 when required parameters are absent.
evidence:
url: https://panda.ecs.kyoto-u.ac.jp/direct/user.json
status: 403
additional_evidence:
- url: https://panda.ecs.kyoto-u.ac.jp/direct/poll.json
status: 401
- url: https://panda.ecs.kyoto-u.ac.jp/portal/login
status: 200
note: Human login entry point published by the IIMC.
- name: KyotoShibbolethIdP
type: saml
operator: institution
applies_to: https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth
entity_id: https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth
description: >-
Kyoto University operates its own Shibboleth SAML 2.0 Identity Provider, run by the Institute
for Information Management and Communication and registered in GakuNin, the Japanese academic
access management federation (National Institute of Informatics), which participates in eduGAIN.
Metadata is public and machine-readable at the canonical /idp/shibboleth location and declares
<shibmd:Scope>kyoto-u.ac.jp</shibmd:Scope>. Single sign-on is offered over SAML 2.0 HTTP-POST
(https://authidp1.iimc.kyoto-u.ac.jp/idp/profile/SAML2/POST/SSO), SAML 2.0 HTTP-Redirect
(.../SAML2/Redirect/SSO) and the legacy Shibboleth 1.0 AuthnRequest profile
(.../profile/Shibboleth/SSO). University accounts are SPS-ID (faculty/staff) and ECS-ID
(students), with multi-factor authentication documented by the IIMC. Service-provider
connections to the federation require committee approval — this is institutional SSO
infrastructure, not a self-service API.
evidence:
url: https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth
status: 200
content_type: application/xml
additional_evidence:
- url: https://metadata.gakunin.nii.ac.jp/gakunin-metadata.xml
status: 200
note: Kyoto's IdP is present in the GakuNin aggregate metadata as entityID https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth.
- url: https://www.iimc.kyoto-u.ac.jp/en/services/account/mfa
status: 200
note: IIMC multi-factor authentication documentation.
local_copy: authentication/kyoto-saml-idp-metadata.xml
- name: KudpcShibbolethSP
type: saml
operator: institution
applies_to: https://web.kudpc.kyoto-u.ac.jp/shibboleth-sp
entity_id: https://web.kudpc.kyoto-u.ac.jp/shibboleth-sp
description: >-
The supercomputer systems of the Academic Center for Computing and Media Studies are fronted by
a Kyoto University-operated Shibboleth service provider registered in GakuNin, with five
AssertionConsumerService endpoints (SAML 2.0 HTTP-POST, POST-SimpleSign and HTTP-Artifact, plus
the SAML 1.0 browser-post and artifact profiles). Contact consult@kudpc.kyoto-u.ac.jp. This is
how researchers reach institution-operated research computing, and it is the access layer for
that service rather than a data API.
evidence:
url: https://metadata.gakunin.nii.ac.jp/gakunin-metadata.xml
status: 200
note: >-
Entity present in the GakuNin aggregate. The SP's own /Shibboleth.sso/Metadata handler returns
500 to a direct anonymous request (2026-08-19), so the federation aggregate is the citable copy.
notes: >-
Kyoto University publishes no OAuth 2.0 authorization server, no API key programme and no
developer registration of any kind. Every institution-operated public interface it runs is either
fully anonymous (KURENAI REST, KURENAI OAI-PMH, the PandA public prefixes) or gated behind
university SSO. This file replaces nothing: before 2026-08-19 the repository carried no
authentication artifact at all.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/kyoto-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.