Lse Authentication
How authentication actually works across LSE's programmable surfaces, split by who operates each one. LSE operates its own SAML2 identity provider and its own LTI 1.3 platform; everything else affiliated with the institution authenticates against a vendor's platform under an LSE tenancy.
London School of Economics and Political Science declares 0 security scheme(s) across its OpenAPI definitions.
Security Schemes
Source
Authentication Profile
---
name: London School of Economics and Political Science — authentication surfaces
description: >-
How authentication actually works across LSE's programmable surfaces, split by who
operates each one. LSE operates its own SAML2 identity provider and its own LTI 1.3
platform; everything else affiliated with the institution authenticates against a
vendor's platform under an LSE tenancy.
generated: '2026-08-19'
method: probed
source: live HTTP probes and UK Access Management Federation metadata, 2026-08-19
authentication:
- name: LSE Shibboleth Identity Provider (SAML2)
x-operator: institution
type: SAML2 / Shibboleth
entity_id: https://lse.ac.uk/idp
metadata_url: https://gate.library.lse.ac.uk/idp/shibboleth
metadata_status: 200
metadata_content_type: application/xml;charset=UTF-8
federation: UK Access Management Federation (UKAMF)
federation_metadata: http://metadata.ukfederation.org.uk/ukfederation-metadata.xml
display_name: LSE - London School of Economics and Political Science
scope: lse.ac.uk
protocols:
- urn:oasis:names:tc:SAML:2.0:protocol
bindings:
- urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect
- urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
- urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign
endpoints:
- url: https://gate.library.lse.ac.uk/idp/profile/SAML2/Redirect/SSO
- url: https://gate.library.lse.ac.uk/idp/profile/SAML2/POST/SSO
- url: https://gate.library.lse.ac.uk:8443/idp/profile/SAML2/SOAP/ArtifactResolution
defects:
- issue: >-
The POST-SimpleSign SSO Location published in LSE's federation metadata is
https://gate.library.lse.ac.uk.lse.ac.uk/idp/profile/SAML2/POST-SimpleSign/SSO
— a doubled domain. The host does not resolve (NXDOMAIN, verified
2026-08-19). A relying party that selects the SimpleSign binding from LSE's
published metadata cannot reach it.
severity: medium
verified: '2026-08-19'
note: >-
A second LSE entity is registered in UKAMF at
https://idp.lse.ac.uk/idp/shibboleth with the display name
"LSE - London School of Economics and Political Science - Test IdP - DO NOT USE".
It does not resolve. It is a non-production entity and is deliberately NOT
recorded as a surface in apis.yml.
- name: LSE Moodle SAML2 Service Provider
x-operator: institution
type: SAML2 SP
entity_id: https://moodle.lse.ac.uk/auth/saml2/sp/metadata.php
metadata_url: https://moodle.lse.ac.uk/auth/saml2/sp/metadata.php
metadata_status: 200
authn_requests_signed: true
want_assertions_signed: false
technical_contact: lti.support@lse.ac.uk
note: >-
The VLE is a service provider against the LSE IdP. WantAssertionsSigned is
false, which is common for Moodle's saml2 plugin but is a weaker posture than
requiring signed assertions.
- name: LSE Moodle LTI 1.3 platform (OAuth 2.0 / OIDC)
x-operator: institution
type: OAuth 2.0 client credentials with JWT bearer client assertion (RFC 7523)
issuer: https://moodle.lse.ac.uk
jwks_uri: https://moodle.lse.ac.uk/mod/lti/certs.php
jwks_status: 200
token_endpoint: https://moodle.lse.ac.uk/mod/lti/token.php
authorization_endpoint: https://moodle.lse.ac.uk/mod/lti/auth.php
keys_observed: 1 RSA RS256 signing key (kid fc7fb5f6ed67a729c4d6)
note: >-
Registration is closed — a tool must be registered by LSE before it can obtain
a token. There is no public self-service registration and no published
.well-known discovery document for this issuer.
- name: LSE Moodle Web Services
x-operator: institution
type: Bearer token (Moodle wstoken)
token_endpoint: https://moodle.lse.ac.uk/login/token.php
service_endpoint: https://moodle.lse.ac.uk/webservice/rest/server.php
status: live, credentialed
note: >-
Enabled and reachable, but issuing a token requires LSE credentials and an
enabled external service. Not a public API.
- name: Vendor-platform authentication under LSE tenancy
x-operator: tenant
covers:
- Ex Libris Alma/Primo VE (librarysearch.lse.ac.uk, vid=44LSE_INST)
- EPrints Services (researchonline.lse.ac.uk)
- Quartex (digital.library.lse.ac.uk)
- Epexio (archives.lse.ac.uk)
note: >-
Authentication for these is defined by the vendor, configured by LSE. Credit
for the auth contract belongs to the vendor's own catalog entry, not to LSE.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/security/lse-authentication"
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.