Tokyo Institute of Technology · Authentication Profile

Tokyo Institute Of Technology Authentication

Authentication

Tokyo Institute of Technology secures its APIs with saml2 across 2 declared security schemes, as derived from its OpenAPI definitions.

EducationHigher EducationUniversityInstitute of TechnologyJapanResearchResearch DataOpen AccessInstitutional RepositoryOAI-PMHIdentity FederationShibbolethSAMLResearch ComputingCourse CatalogLibrary
Methods: saml2 Schemes: 2 OAuth flows: API key in:

Security Schemes

GakuNin Shibboleth IdP (Science & Engineering field) saml2
EX-TIC GakuNin entity for Institute of Science Tokyo saml2

Source

Authentication Profile

Raw ↑
generated: '2026-08-30'
method: derived
evidence_method: probed
evidence_note: >-
  Derived by API Evangelist from the live GakuNin federation metadata aggregate plus direct
  probes of the advertised endpoints on 2026-08-30. The institution publishes no authentication
  document of its own.
source: https://metadata.gakunin.nii.ac.jp/gakunin-metadata.xml
docs: https://www.gakunin.jp/en
note: >-
  This institution publishes no OAuth 2.0 or OpenID Connect developer API. Its authentication
  posture is entirely federated SAML: a Shibboleth Identity Provider registered in GakuNin,
  Japan's national academic access management federation. That is a real, machine-readable,
  institution-operated interface — it is simply not a developer API, and must not be counted as
  one. The one public harvesting endpoint the institution runs (T2R2 OAI-PMH) requires no
  authentication at all.
summary:
  types:
  - saml2
  api_key_in: []
  oauth2_flows: []
  public_unauthenticated_surfaces:
  - https://t2r2.star.titech.ac.jp/oaipmh/OAIHandler
  note: >-
    No signup, no API key, no bearer token and no rate-limit headers were observed on the
    OAI-PMH endpoint. No /.well-known/openid-configuration and no /.well-known/oauth-authorization-server
    was found on any institution host.
schemes:
- name: GakuNin Shibboleth IdP (Science & Engineering field)
  type: saml2
  operator: institution
  entity_id: https://idp-gakunin.nap.gsic.titech.ac.jp/idp/shibboleth
  organization: Institute of Science Tokyo / 東京科学大学
  display_name: Institute of Science Tokyo (Science & Engineering Field)
  organization_url: https://portal.titech.ac.jp/
  federation: GakuNin (Academic Access Management Federation in Japan), operated by NII
  metadata_source: https://metadata.gakunin.nii.ac.jp/gakunin-metadata.xml
  endpoints:
  - binding: urn:mace:shibboleth:1.0:profiles:AuthnRequest
    location: https://idp-gakunin.nap.gsic.titech.ac.jp/idp/profile/Shibboleth/SSO
  - binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
    location: https://idp-gakunin.nap.gsic.titech.ac.jp/idp/profile/SAML2/POST/SSO
  - binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect
    location: https://idp-gakunin.nap.gsic.titech.ac.jp/idp/profile/SAML2/Redirect/SSO
  - binding: urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding
    location: https://idp-gakunin.nap.gsic.titech.ac.jp:8443/idp/profile/SAML1/SOAP/AttributeQuery
  - binding: urn:oasis:names:tc:SAML:2.0:bindings:SOAP
    location: https://idp-gakunin.nap.gsic.titech.ac.jp:8443/idp/profile/SAML2/SOAP/AttributeQuery
  observed: >-
    GET https://idp-gakunin.nap.gsic.titech.ac.jp/idp/shibboleth redirects (HTTP 200) to the
    institution's own login portal at portal.nap.gsic.titech.ac.jp with resource id
    idp-gakunin-2015 and an authentication-factor list including CERTIFICATE, GRID, TOKENRO and
    OTP. Probed 2026-08-30.
  audience: Members of the institution and of GakuNin-federated services. Not issuable to third-party developers.
- name: EX-TIC GakuNin entity for Institute of Science Tokyo
  type: saml2
  operator: tenant
  entity_id: https://isct.ex-tic.com/auth/gakunin/saml2/assertions
  organization: Institute of Science Tokyo / 東京科学大学
  organization_url: https://www.tmd.ac.jp
  federation: GakuNin
  metadata_source: https://metadata.gakunin.nii.ac.jp/gakunin-metadata.xml
  endpoints:
  - binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
    location: https://isct.ex-tic.com/auth/gakunin/saml2/assertions
  - binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect
    location: https://isct.ex-tic.com/auth/gakunin/saml2/assertions
  observed: >-
    A bare GET returns HTTP 400 — correct for a SAML assertion endpoint that expects a POST, and
    not evidence of a dead host. Probed 2026-08-30.
  operator_note: >-
    The host is an institution-specific subdomain on ex-tic.com, a commercial platform. The
    institution's identity is real and federated here; the engineering is the vendor's. Recorded
    as a tenant relationship, which is a genuine institutional fact, rather than credited to the
    institution or deleted.
absent:
- id: oauth2
  evidence: No authorization or token endpoint published on any institution host.
- id: oidc
  evidence: /.well-known/openid-configuration not served on isct.ac.jp or titech.ac.jp hosts probed.
- id: api-key
  evidence: No key issuance surface, no developer portal, no signup flow found.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tokyo-institute-of-technology-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.