Landgate · Authentication Profile

Landgate Authentication

Authentication

Landgate secures its APIs with none, oauth2, and openIdConnect across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, implicit, clientCredentials, refreshToken, deviceCode, tokenExchange, jwtBearer, saml2Bearer, ciba, and password flow(s).

Real EstateAustraliaLand RegistryTitleValuationProperty DataOpen DataGeospatialGovernmentConveyancingPropTech
Methods: none, oauth2, openIdConnect Schemes: 2 OAuth flows: authorizationCode, implicit, clientCredentials, refreshToken, deviceCode, tokenExchange, jwtBearer, saml2Bearer, ciba, password API key in:

Security Schemes

MyLandgateOIDC openIdConnect
MyLandgateOAuth2 oauth2
· flows: authorizationCode, implicit, clientCredentials, deviceCode

Source

Authentication Profile

Raw ↑
generated: '2026-07-26'
method: searched
source: live probes of the SLIP public services, the Data WA CKAN catalogue and the
  MyLandgate PingFederate discovery documents
docs: https://www.landgate.wa.gov.au/location-data-and-services/discovering-landgate-data/licensing/
note: |
  Landgate's authentication story is split three ways and the split is the whole finding.
  The public tier takes NO credential at all; the subscription tier takes a credential that
  cannot be self-issued (it is granted after a licence is signed); and the identity provider
  that fronts the gated tier is a real, standards-compliant OAuth 2.0 / OIDC authorization
  server that publishes no public client registration path.
summary:
  types: [none, oauth2, openIdConnect]
  api_key_in: []
  oauth2_flows: [authorizationCode, implicit, clientCredentials, refreshToken, deviceCode,
    tokenExchange, jwtBearer, saml2Bearer, ciba, password]
  self_service_signup: false
  public_client_registration: false
surfaces:
  - name: SLIP Public Services (ArcGIS REST)
    base: https://public-services.slip.wa.gov.au/public/rest
    auth: none
    evidence:
      url: https://public-services.slip.wa.gov.au/public/rest/info?f=json
      status: 200
      probed: '2026-07-26'
      body: '{"authInfo":{"isTokenBasedSecurity":false}}'
    note: Confirmed anonymous — a live feature query returned real LGA boundary features
      with no credential.
  - name: SLIP Public OGC Services (WMS / WFS)
    base: https://public-services.slip.wa.gov.au/public/services
    auth: none
    evidence:
      url: https://public-services.slip.wa.gov.au/public/services/SLIP_Public_Services/Boundaries/MapServer/WMSServer?request=GetCapabilities&service=WMS
      status: 200
      probed: '2026-07-26'
  - name: Data WA CKAN Action API
    base: https://catalogue.data.wa.gov.au/api/3/action
    auth: none (read)
    evidence:
      url: https://catalogue.data.wa.gov.au/api/3/action/status_show
      status: 200
      probed: '2026-07-26'
    note: |
      Read actions are anonymous. CKAN write actions require an API key sent in the
      `Authorization` header, but Data WA issues no public API keys — no self-service key
      surface was found. Do not record an apiKey scheme for the public surface.
  - name: SLIP Subscription Services (ArcGIS REST)
    base: https://services.slip.wa.gov.au/arcgis/rest/services
    auth: gated
    evidence:
      url: https://services.slip.wa.gov.au/arcgis/rest/services
      status: 401
      probed: '2026-07-26'
    note: HTTP 401 anonymously — even /arcgis/rest/info is 401. Access follows a signed SLIP
      subscription / publication / broker / distributor / value-added-reseller licence.
  - name: MyLandgate / Land Enquiry Services
    base: https://sign-on.app.landgate.wa.gov.au
    auth: oauth2 + openIdConnect
    evidence:
      url: https://sign-on.app.landgate.wa.gov.au/.well-known/openid-configuration
      status: 200
      probed: '2026-07-26'
schemes:
  - name: MyLandgateOIDC
    type: openIdConnect
    openIdConnectUrl: https://sign-on.app.landgate.wa.gov.au/.well-known/openid-configuration
    issuer: https://sign-on.app.landgate.wa.gov.au
    product: PingFederate
    sources:
      - well-known/landgate-openid-configuration.json
      - openapi/landgate-mylandgate-openid-configuration.json
  - name: MyLandgateOAuth2
    type: oauth2
    sources: [well-known/landgate-oauth-authorization-server.json]
    metadata: RFC 8414 OAuth 2.0 Authorization Server Metadata
    flows:
      - flow: authorizationCode
        authorizationUrl: https://sign-on.app.landgate.wa.gov.au/as/authorization.oauth2
        tokenUrl: https://sign-on.app.landgate.wa.gov.au/as/token.oauth2
        scopes: [openid, profile, email, address, phone, ATO]
      - flow: implicit
        authorizationUrl: https://sign-on.app.landgate.wa.gov.au/as/authorization.oauth2
      - flow: clientCredentials
        tokenUrl: https://sign-on.app.landgate.wa.gov.au/as/token.oauth2
      - flow: deviceCode
        deviceAuthorizationUrl: https://sign-on.app.landgate.wa.gov.au/as/device_authz.oauth2
    endpoints:
      token: https://sign-on.app.landgate.wa.gov.au/as/token.oauth2
      revocation: https://sign-on.app.landgate.wa.gov.au/as/revoke_token.oauth2
      introspection: https://sign-on.app.landgate.wa.gov.au/as/introspect.oauth2
      userinfo: https://sign-on.app.landgate.wa.gov.au/idp/userinfo.openid
      jwks: https://sign-on.app.landgate.wa.gov.au/pf/JWKS
      registration: https://sign-on.app.landgate.wa.gov.au/as/clients.oauth2
      end_session: https://sign-on.app.landgate.wa.gov.au/idp/init_logout.openid
    token_endpoint_auth_methods: [client_secret_basic, client_secret_post, client_secret_jwt,
      private_key_jwt, tls_client_auth, none]
    note: |
      A registration_endpoint is advertised but this is the standard PingFederate dynamic
      client registration URL — no public developer flow, documentation or onboarding page was
      found for it. Treat the identity surface as staff/subscriber sign-on, not a developer API.
onboarding:
  self_service: false
  api_key_issuance: none found
  gate: signed licence (SLIP subscription / publication / broker / distributor / VAR) plus a
    MyLandgate account for bulk downloads
  contact: https://www.landgate.wa.gov.au/help-centre/