University of Bristol · Authentication Profile
University Of Bristol Authentication
Authentication
University of Bristol secures its APIs with none, apiKey, and saml across 0 declared security schemes, as derived from its OpenAPI definitions.
UniversityHigher EducationEducationUnited KingdomRussell GroupResearch DataResearch RepositoryMetadata HarvestingOAI-PMHIdentity FederationOpen Data
Methods: none, apiKey, saml
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
generated: '2026-08-30'
method: probed
source: live unauthenticated probes of University of Bristol hosts on 2026-08-30
note: >-
REPLACES the 2026-07-11 version of this file, which was derived from
openapi/university-of-bristol-pure-research-api.yaml — a hand-authored subset of Elsevier's Pure
product contract that has been removed from this repository as vendor-operated. Authentication is
now recorded per surface, with the operator of each surface named.
summary:
types:
- none
- apiKey
- saml
institution_operated_keyless_surfaces: 2
surfaces:
- id: research-portal-oai-pmh
x-operator: institution
endpoint: https://research-information.bris.ac.uk/ws/oai
scheme: none
detail: >-
No API key, token, cookie or affiliation is required. Every OAI-PMH verb tested on 2026-08-30
executed anonymously; five returned well-formed OAI-PMH 2.0 XML and Identify returned HTTP 500.
evidence:
- url: https://research-information.bris.ac.uk/ws/oai?verb=ListRecords&metadataPrefix=oai_dc
status: 200
detail: 100 records returned with no credential presented.
- id: idp-shibboleth-metadata
x-operator: institution
endpoint: https://idp.bris.ac.uk/idp/shibboleth
scheme: none
detail: >-
SAML 2.0 IdP metadata is served anonymously. The identity service itself is of course
credential-gated; the METADATA describing it is public, which is what makes it a
machine-readable surface.
evidence:
- url: https://idp.bris.ac.uk/idp/shibboleth
status: 200
detail: 5,990 bytes of application/xml SAML 2.0 metadata, no credential presented.
- id: idp-shibboleth-sso
x-operator: institution
endpoint: https://idp.bris.ac.uk/idp/profile/SAML2/Redirect/SSO
scheme: saml
detail: >-
SAML 2.0 web browser SSO. Bindings observed in the live metadata: Shibboleth/SSO,
SAML2/POST/SSO, SAML2/POST-SimpleSign/SSO, SAML2/Redirect/SSO. Trust is established through
the UK Access Management Federation, not through a self-serve credential; scope bris.ac.uk;
REFEDS Research & Scholarship entity category asserted.
- id: data-bris-research-data-repository
x-operator: institution
endpoint: https://data.bris.ac.uk/datasets/
scheme: none
detail: >-
Open dataset payload index served without credentials. Individual datasets may carry their own
access conditions; the index itself answered anonymously (200, 315,475 bytes).
tenant_surfaces:
- id: pure-web-services
x-operator: tenant
endpoint: https://research-information.bris.ac.uk/ws/api
scheme: apiKey
detail: >-
Elsevier Pure Web Services running under the institution's host. api-key gated; no key is
issued self-serve. Verified 2026-08-30: GET /ws/api/524/research-outputs returned 401 with no
key. The OpenAPI describing it is Elsevier's product contract
(info.title "Pure API", info.contact.email pure-support@elsevier.com, 826 paths) and is
deliberately NOT stored in this repository.
evidence:
- url: https://research-information.bris.ac.uk/ws/api/524/research-outputs
status: 401
- url: https://research-information.bris.ac.uk/ws/api/openapi.json
status: 200
detail: The vendor's own contract, publicly readable, 1,740,065 bytes.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/university-of-bristol-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.