Landgate · Authentication Profile
Landgate Authentication
Authentication
Landgate secures its APIs with none, oauth2, and openIdConnect across 2 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the authorizationCode, implicit, clientCredentials, refreshToken, deviceCode, tokenExchange, jwtBearer, saml2Bearer, ciba, and password flow(s).
Real-EstateAustraliaLand RegistryTitleValuationProperty DataOpen DataGeospatialGovernmentConveyancingPropTech
Methods: none, oauth2, openIdConnect
Schemes: 2
OAuth flows: authorizationCode, implicit, clientCredentials, refreshToken, deviceCode, tokenExchange, jwtBearer, saml2Bearer, ciba, password
API key in:
Security Schemes
MyLandgateOIDC openIdConnect
MyLandgateOAuth2 oauth2
· flows: authorizationCode, implicit, clientCredentials, deviceCode
Source
Authentication Profile
generated: '2026-07-26'
method: searched
source: live probes of the SLIP public services, the Data WA CKAN catalogue and the
MyLandgate PingFederate discovery documents
docs: https://www.landgate.wa.gov.au/location-data-and-services/discovering-landgate-data/licensing/
note: |
Landgate's authentication story is split three ways and the split is the whole finding.
The public tier takes NO credential at all; the subscription tier takes a credential that
cannot be self-issued (it is granted after a licence is signed); and the identity provider
that fronts the gated tier is a real, standards-compliant OAuth 2.0 / OIDC authorization
server that publishes no public client registration path.
summary:
types: [none, oauth2, openIdConnect]
api_key_in: []
oauth2_flows: [authorizationCode, implicit, clientCredentials, refreshToken, deviceCode,
tokenExchange, jwtBearer, saml2Bearer, ciba, password]
self_service_signup: false
public_client_registration: false
surfaces:
- name: SLIP Public Services (ArcGIS REST)
base: https://public-services.slip.wa.gov.au/public/rest
auth: none
evidence:
url: https://public-services.slip.wa.gov.au/public/rest/info?f=json
status: 200
probed: '2026-07-26'
body: '{"authInfo":{"isTokenBasedSecurity":false}}'
note: Confirmed anonymous — a live feature query returned real LGA boundary features
with no credential.
- name: SLIP Public OGC Services (WMS / WFS)
base: https://public-services.slip.wa.gov.au/public/services
auth: none
evidence:
url: https://public-services.slip.wa.gov.au/public/services/SLIP_Public_Services/Boundaries/MapServer/WMSServer?request=GetCapabilities&service=WMS
status: 200
probed: '2026-07-26'
- name: Data WA CKAN Action API
base: https://catalogue.data.wa.gov.au/api/3/action
auth: none (read)
evidence:
url: https://catalogue.data.wa.gov.au/api/3/action/status_show
status: 200
probed: '2026-07-26'
note: |
Read actions are anonymous. CKAN write actions require an API key sent in the
`Authorization` header, but Data WA issues no public API keys — no self-service key
surface was found. Do not record an apiKey scheme for the public surface.
- name: SLIP Subscription Services (ArcGIS REST)
base: https://services.slip.wa.gov.au/arcgis/rest/services
auth: gated
evidence:
url: https://services.slip.wa.gov.au/arcgis/rest/services
status: 401
probed: '2026-07-26'
note: HTTP 401 anonymously — even /arcgis/rest/info is 401. Access follows a signed SLIP
subscription / publication / broker / distributor / value-added-reseller licence.
- name: MyLandgate / Land Enquiry Services
base: https://sign-on.app.landgate.wa.gov.au
auth: oauth2 + openIdConnect
evidence:
url: https://sign-on.app.landgate.wa.gov.au/.well-known/openid-configuration
status: 200
probed: '2026-07-26'
schemes:
- name: MyLandgateOIDC
type: openIdConnect
openIdConnectUrl: https://sign-on.app.landgate.wa.gov.au/.well-known/openid-configuration
issuer: https://sign-on.app.landgate.wa.gov.au
product: PingFederate
sources:
- well-known/landgate-openid-configuration.json
- openapi/landgate-mylandgate-openid-configuration.json
- name: MyLandgateOAuth2
type: oauth2
sources: [well-known/landgate-oauth-authorization-server.json]
metadata: RFC 8414 OAuth 2.0 Authorization Server Metadata
flows:
- flow: authorizationCode
authorizationUrl: https://sign-on.app.landgate.wa.gov.au/as/authorization.oauth2
tokenUrl: https://sign-on.app.landgate.wa.gov.au/as/token.oauth2
scopes: [openid, profile, email, address, phone, ATO]
- flow: implicit
authorizationUrl: https://sign-on.app.landgate.wa.gov.au/as/authorization.oauth2
- flow: clientCredentials
tokenUrl: https://sign-on.app.landgate.wa.gov.au/as/token.oauth2
- flow: deviceCode
deviceAuthorizationUrl: https://sign-on.app.landgate.wa.gov.au/as/device_authz.oauth2
endpoints:
token: https://sign-on.app.landgate.wa.gov.au/as/token.oauth2
revocation: https://sign-on.app.landgate.wa.gov.au/as/revoke_token.oauth2
introspection: https://sign-on.app.landgate.wa.gov.au/as/introspect.oauth2
userinfo: https://sign-on.app.landgate.wa.gov.au/idp/userinfo.openid
jwks: https://sign-on.app.landgate.wa.gov.au/pf/JWKS
registration: https://sign-on.app.landgate.wa.gov.au/as/clients.oauth2
end_session: https://sign-on.app.landgate.wa.gov.au/idp/init_logout.openid
token_endpoint_auth_methods: [client_secret_basic, client_secret_post, client_secret_jwt,
private_key_jwt, tls_client_auth, none]
note: |
A registration_endpoint is advertised but this is the standard PingFederate dynamic
client registration URL — no public developer flow, documentation or onboarding page was
found for it. Treat the identity surface as staff/subscriber sign-on, not a developer API.
onboarding:
self_service: false
api_key_issuance: none found
gate: signed licence (SLIP subscription / publication / broker / distributor / VAR) plus a
MyLandgate account for bulk downloads
contact: https://www.landgate.wa.gov.au/help-centre/