Queen's University at Kingston · Authentication Profile

Queens University At Kingston Authentication

Authentication

Queen’s University at Kingston secures its APIs with saml2 across 3 declared security schemes, as derived from its OpenAPI definitions.

UniversityHigher EducationEducationCanadaOntarioU15Public Research UniversityResearch DataInstitutional RepositoryIdentity FederationOAI-PMHLibrary
Methods: saml2 Schemes: 3 OAuth flows: API key in:

Security Schemes

Shibboleth / SAML 2.0 Single Sign-On saml2
DSpace REST API authentication (QSpace on Scholaris) multiple
Dataverse API token (Queen's collection on Borealis) apiKey

Source

Authentication Profile

queens-university-at-kingston-authentication.yml Raw ↑
generated: '2026-08-30'
method: probed
source: >-
  https://login.queensu.ca/idp/shibboleth (SAML 2.0 IdP metadata) and
  https://queensu.scholaris.ca/server/api/authn/status (WWW-Authenticate challenge), probed 2026-08-30
provider: Queen's University at Kingston
providerId: queens-university-at-kingston
note: >-
  Queen's publishes no public API key, OAuth application registration, or developer credential flow of
  its own — there is no institution-operated public API to authenticate against. What it does operate,
  and publish machine-readably, is federated identity: a Shibboleth Identity Provider on its own domain
  serving SAML 2.0 metadata. That is the institution's real authentication surface and the one recorded
  here. The token flows of its repository tenants belong to the platforms that run them (DSpace on
  Scholaris, Dataverse on Borealis) and are not restated as Queen's own.
summary:
  types:
  - saml2
  api_key_in: []
  oauth2_flows: []
  self_service_signup: false
schemes:
- name: Shibboleth / SAML 2.0 Single Sign-On
  type: saml2
  x-operator: institution
  documented: true
  entity_id: https://login.queensu.ca/idp/shibboleth
  metadata_url: https://login.queensu.ca/idp/shibboleth
  scope: queensu.ca
  protocol_support: urn:oasis:names:tc:SAML:2.0:protocol
  detail: >-
    IdP metadata is served as application/xml at a stable, unauthenticated URL, carrying an
    IDPSSODescriptor, an X509 signing certificate, and a shibmd:Scope of queensu.ca. This is the
    credential surface every federated Queen's service — including its repository tenants — resolves to.
- name: DSpace REST API authentication (QSpace on Scholaris)
  type: multiple
  x-operator: tenant
  documented: true
  detail: >-
    The Queen's institutional repository REST API answers unauthenticated requests with
    `WWW-Authenticate: password realm="DSpace REST API", shibboleth realm="DSpace REST API",
    ip realm="DSpace REST API"` and a Shibboleth login location. Read access to public records needs no
    credential at all. The scheme is DSpace's, deployed by OCUL / Scholars Portal.
  evidence:
  - url: https://queensu.scholaris.ca/server/api/authn/status
    locator: WWW-Authenticate response header
- name: Dataverse API token (Queen's collection on Borealis)
  type: apiKey
  x-operator: tenant
  documented: true
  detail: >-
    Deposit and management operations against the Queen's University Dataverse Collection use a
    Dataverse API token passed in the X-Dataverse-key header. Tokens are issued by Borealis, not by
    Queen's; public search and metadata reads are keyless.
  docs: https://borealisdata.ca/guides/en/latest/api/native-api.html

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/queens-university-at-kingston-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.