University of Exeter · Authentication Profile

University Of Exeter Authentication

Authentication

University of Exeter secures its APIs with oauth2, openIdConnect, saml2, and token across 5 declared security schemes, as derived from its OpenAPI definitions.

UniversityHigher EducationEducationResearchUnited KingdomRussell GroupIdentity FederationResearch RepositoryLearning ManagementCampus Life
Methods: oauth2, openIdConnect, saml2, token Schemes: 5 OAuth flows: API key in:

Security Schemes

cognitoOAuth2 oauth2
· flows:
entraIdOidc openIdConnect
shibbolethSaml saml2
moodleWebServiceToken token
· in: query ()
ltiAdvantage openIdConnect

Source

Authentication Profile

university-of-exeter-authentication.yml Raw ↑
generated: '2026-09-01'
method: probed
source: >-
  Live probes of api.exeter.ac.uk, ele.exeter.ac.uk, elibrary.exeter.ac.uk and the Exeter
  Entra ID tenant on 2026-09-01, plus the public MyExeter application bundle at
  https://m.exeter.ac.uk/main.dart.js. Exeter publishes no OpenAPI, so no scheme here is
  derived from a contract.
note: >-
  Every authenticated surface Exeter operates is credentialed against institutional identity.
  There is no self-service registration, no API key issuance and no public client
  registration on any host - an unaffiliated developer cannot obtain a credential for any
  of these schemes.
summary:
  types:
  - oauth2
  - openIdConnect
  - saml2
  - token
  self_service: false
  public_registration: false
schemes:
- name: cognitoOAuth2
  type: oauth2
  flows:
  - authorizationCode
  authorizationUrl: https://exeter-auth-prod.auth.eu-west-2.amazoncognito.com/oauth2/authorize
  tokenUrl: https://exeter-auth-prod.auth.eu-west-2.amazoncognito.com/oauth2/token
  applies_to: https://api.exeter.ac.uk
  description: >-
    The MyExeter platform API is protected by an Exeter-owned AWS Cognito user pool in
    eu-west-2. Unauthenticated requests to existing routes return 401 {"message":"Unauthorized"};
    unrouted paths return the API Gateway default 403 {"message":"Missing Authentication Token"},
    which is how the route inventory was confirmed. Some routes additionally require a
    `tenant` request header - /application-settings returns 400 BAD_REQUEST "tenant is required"
    without it.
  sources:
  - https://m.exeter.ac.uk/main.dart.js
  - https://api.exeter.ac.uk/user/profile
- name: entraIdOidc
  type: openIdConnect
  openIdConnectUrl: https://login.microsoftonline.com/912a5d77-fb98-4eee-af32-1334d8f04a53/v2.0/.well-known/openid-configuration
  applies_to: Exeter staff and student single sign-on
  description: >-
    Exeter's Microsoft Entra ID tenant publishes OIDC discovery metadata (200,
    application/json) advertising token_endpoint, jwks_uri and
    token_endpoint_auth_methods_supported of client_secret_post, private_key_jwt,
    client_secret_basic and self_signed_tls_client_auth. Application registration in this
    tenant is closed to the public.
  sources:
  - https://login.microsoftonline.com/912a5d77-fb98-4eee-af32-1334d8f04a53/v2.0/.well-known/openid-configuration
- name: shibbolethSaml
  type: saml2
  entityId: https://elibrary.exeter.ac.uk/idp/shibboleth
  metadataUrl: https://elibrary.exeter.ac.uk/idp/shibboleth
  applies_to: Library electronic resources and federated service providers
  description: >-
    Exeter's own Shibboleth 2.0 identity provider. SSO is offered over HTTP-Redirect,
    HTTP-POST, HTTP-POST-SimpleSign and SOAP/ECP; SLO and ArtifactResolution are advertised.
    Access is granted to service providers registered in the UK Access Management Federation
    or reachable through eduGAIN, not to individual developers.
  federations:
  - http://mdq.ukfederation.org.uk/entities/https%3A%2F%2Felibrary.exeter.ac.uk%2Fidp%2Fshibboleth
  - https://mdq.incommon.org/entities/https%3A%2F%2Felibrary.exeter.ac.uk%2Fidp%2Fshibboleth
  sources:
  - https://elibrary.exeter.ac.uk/idp/shibboleth
- name: moodleWebServiceToken
  type: token
  in: query
  parameterName: wstoken
  applies_to: https://ele.exeter.ac.uk/webservice/rest/server.php
  description: >-
    Moodle web services are enabled on ELE and gated by a per-user web-service token. An
    unauthenticated request returns a well-formed Moodle exception
    (ERRORCODE invalidtoken, "Invalid token - token not found") rather than a 404, which is
    how the surface was confirmed. Tokens are issued to affiliated users through Moodle, not
    through any public registration.
  sources:
  - https://ele.exeter.ac.uk/webservice/rest/server.php
- name: ltiAdvantage
  type: openIdConnect
  jwksUrl: https://ele.exeter.ac.uk/mod/lti/certs.php
  authorizationUrl: https://ele.exeter.ac.uk/mod/lti/auth.php
  applies_to: LTI 1.3 tools launching into ELE
  description: >-
    ELE acts as an LTI 1.3 Advantage tool platform. It publishes an RSA JWKS at
    /mod/lti/certs.php, an OIDC authorization endpoint at /mod/lti/auth.php, and the
    Advantage services endpoint at /mod/lti/services.php. Tool deployments are registered by
    Exeter, not self-service.
  sources:
  - https://ele.exeter.ac.uk/mod/lti/certs.php
  - https://ele.exeter.ac.uk/mod/lti/services.php
unauthenticated:
- url: https://news.exeter.ac.uk/wp-json/
  description: >-
    The only Exeter-hosted API that serves data without a credential. The WordPress REST API
    reports an empty `authentication` object and serves /wp/v2/posts openly (X-WP-Total 2,596).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/university-of-exeter-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.