Technical University of Darmstadt · Authentication Profile

Technical University Of Darmstadt Authentication

Authentication

Technical University of Darmstadt declares 0 security scheme(s) across its OpenAPI definitions.

EducationHigher EducationUniversityTechnical UniversityGermanyResearch DataOpen AccessScholarly PublishingLibraryOAI-PMHDSpaceIdentity FederationShibbolethResearch Computing
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

technical-university-of-darmstadt-authentication.yml Raw ↑
---
# How authentication works across TU Darmstadt's programmable surfaces.
# Derived from the institution's own live SAML metadata and from live probes of each
# surface; nothing here is inferred from documentation alone.
slug: technical-university-of-darmstadt
generated: '2026-09-01'
method: probed
source: >-
  https://idp.hrz.tu-darmstadt.de/idp/shibboleth (fetched 2026-09-01, HTTP 200,
  15,371 bytes of SAML 2.0 metadata) plus unauthenticated probes of each listed surface.
primary:
  type: saml2-shibboleth
  operator: institution
  entity_id: https://idp.hrz.tu-darmstadt.de/idp/shibboleth
  metadata_url: https://idp.hrz.tu-darmstadt.de/idp/shibboleth
  scope: tu-darmstadt.de
  federation: DFN-AAI (Deutsches Forschungsnetz), reachable via eduGAIN
  federation_mdq: https://mdq.aai.dfn.de/entities/
  operated_by: Hochschulrechenzentrum (HRZ), TU Darmstadt
  contacts:
    technical: idmadmin@hrz.tu-darmstadt.de
    support: service@hrz.tu-darmstadt.de
  endpoints:
    - binding: urn:mace:shibboleth:1.0:profiles:AuthnRequest
      location: https://login.tu-darmstadt.de/idp/profile/Shibboleth/SSO
    - binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
      location: https://login.tu-darmstadt.de/idp/profile/SAML2/POST/SSO
    - binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign
      location: https://login.tu-darmstadt.de/idp/profile/SAML2/POST-SimpleSign/SSO
    - binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect
      location: https://login.tu-darmstadt.de/idp/profile/SAML2/Redirect/SSO
    - binding: urn:oasis:names:tc:SAML:2.0:bindings:SOAP
      location: https://login.tu-darmstadt.de/idp/profile/SAML2/SOAP/ECP
      note: ECP profile — the one binding here usable by a non-browser client.
  notes: >-
    This is browser-mediated web SSO for humans. It is not an API authorization
    server: there is no OAuth 2.0 or OpenID Connect token endpoint published on the
    institution's public surface, and no RFC 9728 protected-resource metadata was
    found. An agent cannot obtain a bearer token here.
surfaces:
  - surface: TUdatalib DSpace REST API
    base_url: https://tudatalib.ulb.tu-darmstadt.de/server/api
    anonymous_read: true
    scheme: >-
      Anonymous GET works for the API root and public discovery. Write and restricted
      reads use DSpace's own /server/api/authn endpoints, which chain to the
      Shibboleth IdP above.
    method: probed
  - surface: TUdatalib OAI-PMH
    base_url: https://tudatalib.ulb.tu-darmstadt.de/server/oai/request
    anonymous_read: true
    scheme: None. OAI-PMH is unauthenticated by protocol.
    method: probed
  - surface: DBRepo API v1
    base_url: https://dbrepo.ulb.tu-darmstadt.de/api/v1
    anonymous_read: true
    scheme: >-
      Public database listings and the license vocabulary return 200 anonymously.
      DBRepo's write and private paths use a Keycloak-issued bearer token; no
      registration path was found on the public surface.
    method: probed
  - surface: TUjournals (Janeway) REST API
    base_url: https://tujournals.ulb.tu-darmstadt.de/api
    anonymous_read: true
    scheme: >-
      Fully anonymous read across /api/journals/, /api/articles/ and /api/issues/.
      Note the operator is a vendor (Janeway shared hosting), not the institution.
    method: probed
not_found:
  - oauth2
  - openid-connect
  - api-keys
  - rfc9728-protected-resource-metadata
  - developer-registration-portal

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/technical-university-of-darmstadt-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.