Sungkyunkwan University · Authentication Profile
Skku Authentication
Authentication
Sungkyunkwan University secures its APIs with saml2 across 1 declared security scheme, as derived from its OpenAPI definitions.
UniversityHigher EducationEducationResearchSouth KoreaSeoulIdentity FederationSAMLeduGAINResearch RepositoryOAI-PMHOpen Access
Methods: saml2
Schemes: 1
OAuth flows:
API key in:
Security Schemes
kafeSamlIdP saml2
Source
Authentication Profile
generated: '2026-09-01'
method: probed
source: >-
examples/skku-idp-saml-entity-descriptor-example.xml, retrieved 2026-09-01 from the eduGAIN
metadata database; plus live probes of pure.skku.edu, icampus.skku.edu, sugang.skku.edu and
kingo.skku.edu.
note: >-
Sungkyunkwan University publishes no developer-facing authorization surface. There is no client
registration path, no token endpoint, no consent screen and no API key issuance an outside
developer could integrate against. What it does operate is an END-USER identity federation, and
that is a different thing — it is recorded here because it is the strongest machine-readable
surface the institution runs, not because it is consumable by a third-party integrator.
summary:
types:
- saml2
developer_usable: false
public_client_registration: false
token_endpoint: false
schemes:
- name: kafeSamlIdP
type: saml2
x-operator: institution
entity_id: https://kafe.skku.edu/idp/simplesamlphp
scope: skku.edu
protocol: urn:oasis:names:tc:SAML:2.0:protocol
name_id_formats:
- urn:oasis:names:tc:SAML:2.0:nameid-format:transient
bindings:
- urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect
- urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
endpoints:
single_sign_on: https://kafe.skku.edu/simplesaml/saml2/idp/SSOService.php
single_logout: https://kafe.skku.edu/simplesaml/saml2/idp/SingleLogoutService.php
registration:
authority: http://kafe.kreonet.net
federation: KAFE (Korea Access Federation), interfederated through eduGAIN
registered: '2022-09-26'
first_seen_in_edugain: '2022-11-16'
policy: https://www.kafe.or.kr/kafe-mrps-v1.1.pdf
jurisdiction: KR
assurance:
- https://refeds.org/sirtfi
entity_categories_supported:
- http://refeds.org/category/research-and-scholarship
description: >-
SKKU's institutional SAML 2.0 identity provider, running SimpleSAMLphp on SKKU's own
kafe.skku.edu host. It supports the REFEDS Research and Scholarship entity category and asserts
the REFEDS Sirtfi security incident response assurance profile. Signing and encryption use a
self-issued X.509 certificate (CN=kafe.skku.edu, O=SKKU, OU=Information Service Affairs Team,
valid 2022-09-23 to 2032-09-22).
liveness:
- url: https://kafe.skku.edu/simplesaml/saml2/idp/SSOService.php
status: 400
note: >-
Probed 2026-09-01. SimpleSAMLphp answers "No SAML request provided — You accessed the Single
Sign On Service interface, but did not provide a SAML Authentication Request", with a session
tracking number. A 400 here is the correct response to a request carrying no SAMLRequest, so
the advertised endpoint is confirmed live and functioning rather than dead.
sources:
- examples/skku-idp-saml-entity-descriptor-example.xml
x-note: >-
The IdP's own metadata paths are not directly retrievable — https://kafe.skku.edu/ returns 200
but /idp/simplesamlphp and /simplesaml/saml2/idp/metadata.php return a Korean WAF interstitial
("정보보호를 위해 부적절한 접근이 차단 되었습니다", HTTP 404). The metadata is published through the
federation aggregate instead, which is the normal and correct distribution channel for it.
gated_surfaces:
- name: Kingo Portal (single sign-on)
url: https://www.skku.edu/eng/CampusLife/ITServices/KingoPortal1_1.do
x-operator: institution
note: >-
The campus SSO environment fronting Gmail/Google Workspace, GLS, iCampus, electronic approval and
notice boards. Enrolment-gated; no public authentication API, no developer registration, no
published rate limits.
- name: Pure Web Service
url: https://pure.skku.edu/ws/api
x-operator: tenant
note: >-
https://pure.skku.edu/ws/api/524/ returns HTTP 401 "Request not authorized. Please provide a
valid API key for access." The documentation page at /ws/api canonicalises to
https://api.elsevierpure.com/ws/api/documentation/index.html — this is Elsevier's contract on
SKKU's tenancy, and no key issuance path for third parties was found.
- name: iCampus
url: https://icampus.skku.edu/
x-operator: institution
note: >-
Learning system on SKKU's own domain, a Laravel application. /api/v1/courses returns 419
"Page Expired" (CSRF), every other API path returns the app's Korean 404. No public API.
- name: Course registration (수강신청)
url: https://sugang.skku.edu/
x-operator: institution
note: HTTP 200, Korean-only, session-gated. No machine-readable course catalog is published.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/skku-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.