Kyoto University · Authentication Profile
Kyoto Authentication
Authentication
Kyoto University secures its APIs with none, saml, and session across 6 declared security schemes, as derived from its OpenAPI definitions.
UniversityHigher EducationEducationJapanNational UniversityResearch RepositoryResearch DataIdentity FederationLearning ManagementOpen AccessResearch ComputingScholarly
Methods: none, saml, session
Schemes: 6
OAuth flows:
API key in:
Security Schemes
KurenaiPublicRead none
KurenaiOaiPmhPublic none
PandaAnonymousRead none
PandaSakaiSession session
KyotoShibbolethIdP saml
KudpcShibbolethSP saml
Source
Authentication Profile
generated: '2026-08-19'
method: probed
source: >-
Live probes on 2026-08-19 of every surface attributed to Kyoto University, plus
openapi/kyoto-lms-api-openapi.yml, openapi/kyoto-rest-api-openapi.yml and
openapi/kyoto-oai-pmh-api-openapi.yml. No credential was sent to any host and no authentication
was attempted; gated surfaces are described by the status they return to an anonymous caller.
provider: Kyoto University
providerId: kyoto
summary:
types:
- none
- saml
- session
institution_operated_public_apis_requiring_no_auth: 3
oauth2: false
api_keys: false
schemes:
- name: KurenaiPublicRead
type: none
operator: institution
applies_to: https://repository.kulib.kyoto-u.ac.jp
description: >-
KURENAI's public surfaces are anonymous reads. The DSpace 7.6 REST root, the community and
collection listings, and the whole OAI-PMH 2.0 endpoint answer with no credential. Item
submission and administrative endpoints require a repository account and were not exercised.
evidence:
url: https://repository.kulib.kyoto-u.ac.jp/server/api/core/communities
status: 200
- name: KurenaiOaiPmhPublic
type: none
operator: institution
applies_to: https://repository.kulib.kyoto-u.ac.jp/server/oai/request
description: >-
OAI-PMH 2.0 harvesting is open by design; verb=Identify, verb=ListMetadataFormats and
verb=ListRecords all answer anonymously.
evidence:
url: https://repository.kulib.kyoto-u.ac.jp/server/oai/request?verb=Identify
status: 200
- name: PandaAnonymousRead
type: none
operator: institution
applies_to: https://panda.ecs.kyoto-u.ac.jp/direct
description: >-
The Sakai Entity Broker answers anonymously on the public prefixes. /direct/tool.json returns
the full 96-entry tool registry; /direct/site.json, /direct/syllabus.json,
/direct/announcement.json, /direct/assignment.json, /direct/calendar.json, /direct/content.json
and /direct/lti.json return their envelope with an empty collection, and /direct/session.json
returns a session object with null id, userId and userEid. No course, roster or personal data is
exposed without a session.
evidence:
url: https://panda.ecs.kyoto-u.ac.jp/direct/tool.json
status: 200
- name: PandaSakaiSession
type: session
operator: institution
applies_to: https://panda.ecs.kyoto-u.ac.jp
description: >-
Privileged PandA entities require an authenticated Sakai session established through the
university login (ECS-ID for students, SPS-ID for faculty and staff), which is itself federated
through the IIMC Shibboleth IdP with multi-factor authentication. The boundary is enforced and
differentiated: /direct/poll.json returns 401, /direct/user.json returns 403, and
/direct/membership.json returns 400 when required parameters are absent.
evidence:
url: https://panda.ecs.kyoto-u.ac.jp/direct/user.json
status: 403
additional_evidence:
- url: https://panda.ecs.kyoto-u.ac.jp/direct/poll.json
status: 401
- url: https://panda.ecs.kyoto-u.ac.jp/portal/login
status: 200
note: Human login entry point published by the IIMC.
- name: KyotoShibbolethIdP
type: saml
operator: institution
applies_to: https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth
entity_id: https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth
description: >-
Kyoto University operates its own Shibboleth SAML 2.0 Identity Provider, run by the Institute
for Information Management and Communication and registered in GakuNin, the Japanese academic
access management federation (National Institute of Informatics), which participates in eduGAIN.
Metadata is public and machine-readable at the canonical /idp/shibboleth location and declares
<shibmd:Scope>kyoto-u.ac.jp</shibmd:Scope>. Single sign-on is offered over SAML 2.0 HTTP-POST
(https://authidp1.iimc.kyoto-u.ac.jp/idp/profile/SAML2/POST/SSO), SAML 2.0 HTTP-Redirect
(.../SAML2/Redirect/SSO) and the legacy Shibboleth 1.0 AuthnRequest profile
(.../profile/Shibboleth/SSO). University accounts are SPS-ID (faculty/staff) and ECS-ID
(students), with multi-factor authentication documented by the IIMC. Service-provider
connections to the federation require committee approval — this is institutional SSO
infrastructure, not a self-service API.
evidence:
url: https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth
status: 200
content_type: application/xml
additional_evidence:
- url: https://metadata.gakunin.nii.ac.jp/gakunin-metadata.xml
status: 200
note: Kyoto's IdP is present in the GakuNin aggregate metadata as entityID https://authidp1.iimc.kyoto-u.ac.jp/idp/shibboleth.
- url: https://www.iimc.kyoto-u.ac.jp/en/services/account/mfa
status: 200
note: IIMC multi-factor authentication documentation.
local_copy: authentication/kyoto-saml-idp-metadata.xml
- name: KudpcShibbolethSP
type: saml
operator: institution
applies_to: https://web.kudpc.kyoto-u.ac.jp/shibboleth-sp
entity_id: https://web.kudpc.kyoto-u.ac.jp/shibboleth-sp
description: >-
The supercomputer systems of the Academic Center for Computing and Media Studies are fronted by
a Kyoto University-operated Shibboleth service provider registered in GakuNin, with five
AssertionConsumerService endpoints (SAML 2.0 HTTP-POST, POST-SimpleSign and HTTP-Artifact, plus
the SAML 1.0 browser-post and artifact profiles). Contact consult@kudpc.kyoto-u.ac.jp. This is
how researchers reach institution-operated research computing, and it is the access layer for
that service rather than a data API.
evidence:
url: https://metadata.gakunin.nii.ac.jp/gakunin-metadata.xml
status: 200
note: >-
Entity present in the GakuNin aggregate. The SP's own /Shibboleth.sso/Metadata handler returns
500 to a direct anonymous request (2026-08-19), so the federation aggregate is the citable copy.
notes: >-
Kyoto University publishes no OAuth 2.0 authorization server, no API key programme and no
developer registration of any kind. Every institution-operated public interface it runs is either
fully anonymous (KURENAI REST, KURENAI OAI-PMH, the PandA public prefixes) or gated behind
university SSO. This file replaces nothing: before 2026-08-19 the repository carried no
authentication artifact at all.
maintainers:
- FN: Kin Lane
email: kin@apievangelist.com