Sungkyunkwan University · Authentication Profile

Skku Authentication

Authentication

Sungkyunkwan University secures its APIs with saml2 across 1 declared security scheme, as derived from its OpenAPI definitions.

UniversityHigher EducationEducationResearchSouth KoreaSeoulIdentity FederationSAMLeduGAINResearch RepositoryOAI-PMHOpen Access
Methods: saml2 Schemes: 1 OAuth flows: API key in:

Security Schemes

kafeSamlIdP saml2

Source

Authentication Profile

skku-authentication.yml Raw ↑
generated: '2026-09-01'
method: probed
source: >-
  examples/skku-idp-saml-entity-descriptor-example.xml, retrieved 2026-09-01 from the eduGAIN
  metadata database; plus live probes of pure.skku.edu, icampus.skku.edu, sugang.skku.edu and
  kingo.skku.edu.
note: >-
  Sungkyunkwan University publishes no developer-facing authorization surface. There is no client
  registration path, no token endpoint, no consent screen and no API key issuance an outside
  developer could integrate against. What it does operate is an END-USER identity federation, and
  that is a different thing — it is recorded here because it is the strongest machine-readable
  surface the institution runs, not because it is consumable by a third-party integrator.
summary:
  types:
  - saml2
  developer_usable: false
  public_client_registration: false
  token_endpoint: false
schemes:
- name: kafeSamlIdP
  type: saml2
  x-operator: institution
  entity_id: https://kafe.skku.edu/idp/simplesamlphp
  scope: skku.edu
  protocol: urn:oasis:names:tc:SAML:2.0:protocol
  name_id_formats:
  - urn:oasis:names:tc:SAML:2.0:nameid-format:transient
  bindings:
  - urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect
  - urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
  endpoints:
    single_sign_on: https://kafe.skku.edu/simplesaml/saml2/idp/SSOService.php
    single_logout: https://kafe.skku.edu/simplesaml/saml2/idp/SingleLogoutService.php
  registration:
    authority: http://kafe.kreonet.net
    federation: KAFE (Korea Access Federation), interfederated through eduGAIN
    registered: '2022-09-26'
    first_seen_in_edugain: '2022-11-16'
    policy: https://www.kafe.or.kr/kafe-mrps-v1.1.pdf
    jurisdiction: KR
  assurance:
  - https://refeds.org/sirtfi
  entity_categories_supported:
  - http://refeds.org/category/research-and-scholarship
  description: >-
    SKKU's institutional SAML 2.0 identity provider, running SimpleSAMLphp on SKKU's own
    kafe.skku.edu host. It supports the REFEDS Research and Scholarship entity category and asserts
    the REFEDS Sirtfi security incident response assurance profile. Signing and encryption use a
    self-issued X.509 certificate (CN=kafe.skku.edu, O=SKKU, OU=Information Service Affairs Team,
    valid 2022-09-23 to 2032-09-22).
  liveness:
  - url: https://kafe.skku.edu/simplesaml/saml2/idp/SSOService.php
    status: 400
    note: >-
      Probed 2026-09-01. SimpleSAMLphp answers "No SAML request provided — You accessed the Single
      Sign On Service interface, but did not provide a SAML Authentication Request", with a session
      tracking number. A 400 here is the correct response to a request carrying no SAMLRequest, so
      the advertised endpoint is confirmed live and functioning rather than dead.
  sources:
  - examples/skku-idp-saml-entity-descriptor-example.xml
  x-note: >-
    The IdP's own metadata paths are not directly retrievable — https://kafe.skku.edu/ returns 200
    but /idp/simplesamlphp and /simplesaml/saml2/idp/metadata.php return a Korean WAF interstitial
    ("정보보호를 위해 부적절한 접근이 차단 되었습니다", HTTP 404). The metadata is published through the
    federation aggregate instead, which is the normal and correct distribution channel for it.
gated_surfaces:
- name: Kingo Portal (single sign-on)
  url: https://www.skku.edu/eng/CampusLife/ITServices/KingoPortal1_1.do
  x-operator: institution
  note: >-
    The campus SSO environment fronting Gmail/Google Workspace, GLS, iCampus, electronic approval and
    notice boards. Enrolment-gated; no public authentication API, no developer registration, no
    published rate limits.
- name: Pure Web Service
  url: https://pure.skku.edu/ws/api
  x-operator: tenant
  note: >-
    https://pure.skku.edu/ws/api/524/ returns HTTP 401 "Request not authorized. Please provide a
    valid API key for access." The documentation page at /ws/api canonicalises to
    https://api.elsevierpure.com/ws/api/documentation/index.html — this is Elsevier's contract on
    SKKU's tenancy, and no key issuance path for third parties was found.
- name: iCampus
  url: https://icampus.skku.edu/
  x-operator: institution
  note: >-
    Learning system on SKKU's own domain, a Laravel application. /api/v1/courses returns 419
    "Page Expired" (CSRF), every other API path returns the app's Korean 404. No public API.
- name: Course registration (수강신청)
  url: https://sugang.skku.edu/
  x-operator: institution
  note: HTTP 200, Korean-only, session-gated. No machine-readable course catalog is published.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/skku-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.