Kyoto University · Authentication Profile

Kyoto Authentication

Authentication

Kyoto University secures its APIs with none, saml, and session across 6 declared security schemes, as derived from its OpenAPI definitions.

UniversityHigher EducationEducationJapanNational UniversityResearch RepositoryResearch DataIdentity FederationLearning ManagementOpen AccessResearch ComputingScholarly
Methods: none, saml, session Schemes: 6 OAuth flows: API key in:

Security Schemes

KurenaiPublicRead none
KurenaiOaiPmhPublic none
PandaAnonymousRead none
PandaSakaiSession session
KyotoShibbolethIdP saml
KudpcShibbolethSP saml

Source

Authentication Profile

Raw ↑
generated: '2026-08-19'
method: probed
source: >-
  Live probes on 2026-08-19 of every surface attributed to Kyoto University, plus
  openapi/kyoto-lms-api-openapi.yml, openapi/kyoto-rest-api-openapi.yml and
  openapi/kyoto-oai-pmh-api-openapi.yml. No credential was sent to any host and no authentication
  was attempted; gated surfaces are described by the status they return to an anonymous caller.
provider: Kyoto University
providerId: kyoto
summary:
  types:
  - none
  - saml
  - session
  institution_operated_public_apis_requiring_no_auth: 3
  oauth2: false
  api_keys: false
schemes:
- name: KurenaiPublicRead
  type: none
  operator: institution
  applies_to: https://repository.kulib.kyoto-u.ac.jp
  description: >-
    KURENAI's public surfaces are anonymous reads. The DSpace 7.6 REST root, the community and
    collection listings, and the whole OAI-PMH 2.0 endpoint answer with no credential. Item
    submission and administrative endpoints require a repository account and were not exercised.
  evidence:
    url: https://repository.kulib.kyoto-u.ac.jp/server/api/core/communities
    status: 200
- name: KurenaiOaiPmhPublic
  type: none
  operator: institution
  applies_to: https://repository.kulib.kyoto-u.ac.jp/server/oai/request
  description: >-
    OAI-PMH 2.0 harvesting is open by design; verb=Identify, verb=ListMetadataFormats and
    verb=ListRecords all answer anonymously.
  evidence:
    url: https://repository.kulib.kyoto-u.ac.jp/server/oai/request?verb=Identify
    status: 200
- name: PandaAnonymousRead
  type: none
  operator: institution
  applies_to: https://panda.ecs.kyoto-u.ac.jp/direct
  description: >-
    The Sakai Entity Broker answers anonymously on the public prefixes. /direct/tool.json returns
    the full 96-entry tool registry; /direct/site.json, /direct/syllabus.json,
    /direct/announcement.json, /direct/assignment.json, /direct/calendar.json, /direct/content.json
    and /direct/lti.json return their envelope with an empty collection, and /direct/session.json
    returns a session object with null id, userId and userEid. No course, roster or personal data is
    exposed without a session.
  evidence:
    url: https://panda.ecs.kyoto-u.ac.jp/direct/tool.json
    status: 200
- name: PandaSakaiSession
  type: session
  operator: institution
  applies_to: https://panda.ecs.kyoto-u.ac.jp
  description: >-
    Privileged PandA entities require an authenticated Sakai session established through the
    university login (ECS-ID for students, SPS-ID for faculty and staff), which is itself federated
    through the IIMC Shibboleth IdP with multi-factor authentication. The boundary is enforced and
    differentiated: /direct/poll.json returns 401, /direct/user.json returns 403, and
    /direct/membership.json returns 400 when required parameters are absent.
  evidence:
    url: https://panda.ecs.kyoto-u.ac.jp/direct/user.json
    status: 403
  additional_evidence:
  - url: https://panda.ecs.kyoto-u.ac.jp/direct/poll.json
    status: 401
  - url: https://panda.ecs.kyoto-u.ac.jp/portal/login
    status: 200
    note: Human login entry point published by the IIMC.
- name: KyotoShibbolethIdP
  type: saml
  operator: institution
  applies_to: https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth
  entity_id: https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth
  description: >-
    Kyoto University operates its own Shibboleth SAML 2.0 Identity Provider, run by the Institute
    for Information Management and Communication and registered in GakuNin, the Japanese academic
    access management federation (National Institute of Informatics), which participates in eduGAIN.
    Metadata is public and machine-readable at the canonical /idp/shibboleth location and declares
    <shibmd:Scope>kyoto-u.ac.jp</shibmd:Scope>. Single sign-on is offered over SAML 2.0 HTTP-POST
    (https://authidp1.iimc.kyoto-u.ac.jp/idp/profile/SAML2/POST/SSO), SAML 2.0 HTTP-Redirect
    (.../SAML2/Redirect/SSO) and the legacy Shibboleth 1.0 AuthnRequest profile
    (.../profile/Shibboleth/SSO). University accounts are SPS-ID (faculty/staff) and ECS-ID
    (students), with multi-factor authentication documented by the IIMC. Service-provider
    connections to the federation require committee approval — this is institutional SSO
    infrastructure, not a self-service API.
  evidence:
    url: https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth
    status: 200
    content_type: application/xml
  additional_evidence:
  - url: https://metadata.gakunin.nii.ac.jp/gakunin-metadata.xml
    status: 200
    note: Kyoto's IdP is present in the GakuNin aggregate metadata as entityID https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth.
  - url: https://www.iimc.kyoto-u.ac.jp/en/services/account/mfa
    status: 200
    note: IIMC multi-factor authentication documentation.
  local_copy: authentication/kyoto-saml-idp-metadata.xml
- name: KudpcShibbolethSP
  type: saml
  operator: institution
  applies_to: https://web.kudpc.kyoto-u.ac.jp/shibboleth-sp
  entity_id: https://web.kudpc.kyoto-u.ac.jp/shibboleth-sp
  description: >-
    The supercomputer systems of the Academic Center for Computing and Media Studies are fronted by
    a Kyoto University-operated Shibboleth service provider registered in GakuNin, with five
    AssertionConsumerService endpoints (SAML 2.0 HTTP-POST, POST-SimpleSign and HTTP-Artifact, plus
    the SAML 1.0 browser-post and artifact profiles). Contact consult@kudpc.kyoto-u.ac.jp. This is
    how researchers reach institution-operated research computing, and it is the access layer for
    that service rather than a data API.
  evidence:
    url: https://metadata.gakunin.nii.ac.jp/gakunin-metadata.xml
    status: 200
    note: >-
      Entity present in the GakuNin aggregate. The SP's own /Shibboleth.sso/Metadata handler returns
      500 to a direct anonymous request (2026-08-19), so the federation aggregate is the citable copy.
notes: >-
  Kyoto University publishes no OAuth 2.0 authorization server, no API key programme and no
  developer registration of any kind. Every institution-operated public interface it runs is either
  fully anonymous (KURENAI REST, KURENAI OAI-PMH, the PandA public prefixes) or gated behind
  university SSO. This file replaces nothing: before 2026-08-19 the repository carried no
  authentication artifact at all.
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com