TU Wien · Authentication Profile
Tu Wien Authentication
Authentication
TU Wien declares 7 security scheme(s) across its OpenAPI definitions.
UniversityHigher EducationEducationTechnical UniversityAustriaEuropeResearch DataResearch RepositoryOpen AccessOAI-PMHIdentity FederationResearch ComputingInvenioRDMDataCiteORCIDSAMLRIS Synergy
Methods:
Schemes: 7
OAuth flows:
API key in:
Security Schemes
scheme: none for read, bearer for write
scheme: none
scheme: none
scheme: none declared — request refused by a crawler filter before authentication is reached
scheme: TU Wien single sign-on
scheme: OAuth 2.0 / OpenID Connect bearer token (Keycloak)
scheme: SAML 2.0 Web Browser SSO
Source
Authentication Profile
---
generated: '2026-08-30'
method: derived
probe: true
probe_note: >-
Written by API Evangelist from live HTTP probes run on 2026-08-30. `derived` is the authorship
vocabulary term; every status code recorded below was actually returned to us. TU Wien did not
publish this file.
source: live probes 2026-08-30 plus the FUNDify contract in openapi/_original/
summary: >-
TU Wien has no single API gateway and no unified developer credential. Each institution-operated
surface carries its own scheme, and three of the five machine surfaces are anonymous-readable.
schemes:
- surface: tu-wien:researchdata-api
x-operator: institution
scheme: none for read, bearer for write
detail: >-
InvenioRDM. GET /api/records, /api/communities, /api/vocabularies/*, /api/affiliations and
/api/funders answer anonymously. /api/names returns 403 anonymously. Write operations
(drafts, file upload, curation requests) require a personal access token issued from the user
account and sent as `Authorization: Bearer <token>`.
evidence:
- url: https://researchdata.tuwien.ac.at/api/records?size=1
status: 200
- url: https://researchdata.tuwien.ac.at/api/names?size=1
status: 403
- url: https://researchdata.tuwien.ac.at/tuw/about/api
status: 200
- surface: tu-wien:researchdata-oai
x-operator: institution
scheme: none
evidence:
- url: https://researchdata.tuwien.ac.at/oai2d?verb=Identify
status: 200
- surface: tu-wien:repositum-oai
x-operator: institution
scheme: none
evidence:
- url: https://repositum.tuwien.at/oai/openaire?verb=Identify
status: 200
- surface: tu-wien:repositum-rest
x-operator: institution
scheme: none declared — request refused by a crawler filter before authentication is reached
evidence:
- url: https://repositum.tuwien.at/server/api/core/items?size=1
status: 416
- url: https://repositum.tuwien.at/server/api
status: 503
- surface: tu-wien:tiss-api
x-operator: institution
scheme: TU Wien single sign-on
detail: >-
https://tiss.tuwien.ac.at/api/dokumentation redirects to a TU Wien Login page. The API edge is
reachable anonymously and returns a structured XML error document under the namespace
https://tiss.tuwien.ac.at/api/schema/error/v10, but resource paths are not publicly enumerable
and the documentation that would name them is behind the institutional IdP.
evidence:
- url: https://tiss.tuwien.ac.at/api/dokumentation
status: 200
detail: 'page title "TU Wien Login" (unauthenticated); "Cookie fehlt" without a session cookie'
- url: https://tiss.tuwien.ac.at/api/course/v22/all
status: 404
detail: RESTEasy XML error document — proves a live REST backend behind /api/course/
- surface: tu-wien:fundify-funding
x-operator: institution
scheme: OAuth 2.0 / OpenID Connect bearer token (Keycloak)
detail: >-
Anonymous calls to the funding routes return 401 with an empty body. The source repository
configures a Keycloak client against https://id.arisnet.ac.at/realms/fundify; the RIS Synergy
network broker realm that TU Wien itself operates publishes a public discovery document.
evidence:
- url: https://fundify.arisnet.ac.at/api/ris-synergy/funding/v1/fundings
status: 401
- url: https://ris-synergy.csd.tuwien.ac.at/auth/realms/ris-synergy/.well-known/openid-configuration
status: 200
- surface: tu-wien:saml-idp
x-operator: institution
scheme: SAML 2.0 Web Browser SSO
detail: >-
entityID https://idp.zid.tuwien.ac.at/saml2, SimpleSAMLphp, registered in the ACOnet /
eduID.at federation and interfederated into eduGAIN. This is the credential behind almost
every gated TU Wien surface above.
evidence:
- url: https://eduid.at/md/aconet-registered.xml
status: 200
not_found:
- api key issuance page
- developer portal registration
- OAuth client self-registration on any TU Wien host
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/tu-wien-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.