Delft University of Technology · Authentication Profile

Tu Delft Authentication

Authentication

Delft University of Technology declares 0 security scheme(s) across its OpenAPI definitions.

UniversityHigher EducationEducationTechnical UniversityResearch DataOpen AccessIdentity FederationResearch RepositoryResearch Computing4TU.FederationNetherlandsEurope
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-08-19'
method: probed
source: >-
  Live probes on 2026-08-19 of https://data.4tu.nl/v2/account/articles (HTTP 403
  InvalidSessionToken), https://login.tudelft.nl/ (HTTP 200),
  https://login.tudelft.nl/sso/saml2/idp/metadata.php (HTTP 200,
  application/samlmetadata+xml), https://metadata.surfconext.nl/idps-metadata.xml (HTTP 200),
  https://pure.tudelft.nl/ws/oai?verb=Identify (HTTP 401), plus
  https://raw.githubusercontent.com/4TUResearchData/djehuty/main/docs/api.md and
  https://www.tudelft.nl/en/it-manuals/netid (HTTP 200).
note: >-
  TU Delft has two entirely separate authentication stories and they should not be conflated.
  Human access to institutional services runs through NetID over SAML 2.0, federated nationally
  through SURFconext and onward to eduGAIN. Machine access to the one public API the institution
  operates (4TU.ResearchData) uses a personal bearer token issued from a dashboard, with no
  OAuth 2.0, no OIDC discovery document and no published scope vocabulary. The legacy
  api.tudelft.nl OAuth 2.0 authorization service at oauth.tudelft.nl no longer answers on
  either port 80 or 443 from the public internet.
mechanisms:
  - id: api-token
    name: djehuty personal API token
    applies_to: 4TU.ResearchData API (data.4tu.nl)
    x-operator: institution
    type: bearer
    scheme: token
    header: 'Authorization: token YOUR_TOKEN_HERE'
    issuance: Self-service from the depositor dashboard after NetID/ORCID/SRAM login.
    public_read: true
    evidence: >-
      GET /v2/account/articles without a token returns HTTP 403
      {"message":"Invalid or unknown session token","code":"InvalidSessionToken"}.
      All /v2 and /v3 read endpoints listed in openapi/ answered HTTP 200 with no credentials.
    oauth2: false
    oidc: false
    scopes_published: false
  - id: saml-idp
    name: TU Delft SAML 2.0 Identity Provider (NetID)
    applies_to: Institutional web services, SURFconext service providers, eduGAIN
    x-operator: institution
    type: saml2
    entity_id: https://login.tudelft.nl/sso/saml2/idp/metadata.php
    metadata_url: https://login.tudelft.nl/sso/saml2/idp/metadata.php
    software: SimpleSAMLphp
    federation: SURFconext (SURF, Netherlands) -> eduGAIN
    federation_metadata: https://metadata.surfconext.nl/idps-metadata.xml
    display_names: ['Technische Universiteit Delft', 'Delft University of Technology']
    evidence: >-
      The entity is present in the live SURFconext IdP aggregate with a SingleSignOnService
      HTTP-Redirect binding at
      https://engine.surfconext.nl/authentication/idp/single-sign-on/key:20230503/a2f60e8691e4518b7cb67605ecd88a8d,
      and the institution's own metadata document is served directly from login.tudelft.nl.
    local_copy: authentication/tu-delft-saml-idp-metadata.xml
  - id: sram
    name: SURF Research Access Management (SRAM) collaboration
    applies_to: 4TU.ResearchData depositor onboarding
    x-operator: tenant
    type: saml2-broker
    evidence: >-
      djehuty's configuration documentation describes joining an SRAM collaboration to grant
      access to a djehuty instance (organization-api-token + collaboration-id). SRAM is
      operated by SURF, not by TU Delft.
  - id: orcid
    name: ORCID as identity provider
    applies_to: 4TU.ResearchData depositor login and author records
    x-operator: vendor
    type: oauth2
    evidence: >-
      djehuty documents ORCID both as a primary login identity provider and as a way to couple
      an author record to an ORCID iD. ORCID is operated by ORCID, Inc.
  - id: pure-ws
    name: Elsevier Pure Web Service
    applies_to: pure.tudelft.nl / research.tudelft.nl
    x-operator: tenant
    type: api-key
    evidence: >-
      https://pure.tudelft.nl/ws/oai?verb=Identify returns HTTP 401 — the interface exists and
      is gated, not absent. The API documentation served under pure.tudelft.nl/ws/api/ carries
      rel=canonical to https://api.elsevierpure.com/ws/api/index.html, which is the ownership
      signal: the contract is Elsevier's, the tenancy is TU Delft's.
  - id: legacy-oauth
    name: api.tudelft.nl OAuth 2.0 authorization service (retired)
    applies_to: The former TU Delft institutional API platform
    x-operator: institution
    type: oauth2
    status: unreachable
    evidence: >-
      api.tudelft.nl resolves to 131.180.187.26 and oauth.tudelft.nl to 131.180.187.27, both
      inside TU Delft's DUNET netblock, but TCP connections to ports 80 and 443 time out from
      the public internet. apidoc.tudelft.nl has no DNS record at all. The OAuth 2.0
      developer's guide previously published at api.tudelft.nl/cms/developers-guide/oauth2/
      is not retrievable.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tu-delft-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.