University of Exeter · Authentication Profile
University Of Exeter Authentication
Authentication
University of Exeter secures its APIs with oauth2, openIdConnect, saml2, and token across 5 declared security schemes, as derived from its OpenAPI definitions.
UniversityHigher EducationEducationResearchUnited KingdomRussell GroupIdentity FederationResearch RepositoryLearning ManagementCampus Life
Methods: oauth2, openIdConnect, saml2, token
Schemes: 5
OAuth flows:
API key in:
Security Schemes
cognitoOAuth2 oauth2
· flows:
entraIdOidc openIdConnect
shibbolethSaml saml2
moodleWebServiceToken token
· in: query ()
ltiAdvantage openIdConnect
Source
Authentication Profile
generated: '2026-09-01'
method: probed
source: >-
Live probes of api.exeter.ac.uk, ele.exeter.ac.uk, elibrary.exeter.ac.uk and the Exeter
Entra ID tenant on 2026-09-01, plus the public MyExeter application bundle at
https://m.exeter.ac.uk/main.dart.js. Exeter publishes no OpenAPI, so no scheme here is
derived from a contract.
note: >-
Every authenticated surface Exeter operates is credentialed against institutional identity.
There is no self-service registration, no API key issuance and no public client
registration on any host - an unaffiliated developer cannot obtain a credential for any
of these schemes.
summary:
types:
- oauth2
- openIdConnect
- saml2
- token
self_service: false
public_registration: false
schemes:
- name: cognitoOAuth2
type: oauth2
flows:
- authorizationCode
authorizationUrl: https://exeter-auth-prod.auth.eu-west-2.amazoncognito.com/oauth2/authorize
tokenUrl: https://exeter-auth-prod.auth.eu-west-2.amazoncognito.com/oauth2/token
applies_to: https://api.exeter.ac.uk
description: >-
The MyExeter platform API is protected by an Exeter-owned AWS Cognito user pool in
eu-west-2. Unauthenticated requests to existing routes return 401 {"message":"Unauthorized"};
unrouted paths return the API Gateway default 403 {"message":"Missing Authentication Token"},
which is how the route inventory was confirmed. Some routes additionally require a
`tenant` request header - /application-settings returns 400 BAD_REQUEST "tenant is required"
without it.
sources:
- https://m.exeter.ac.uk/main.dart.js
- https://api.exeter.ac.uk/user/profile
- name: entraIdOidc
type: openIdConnect
openIdConnectUrl: https://login.microsoftonline.com/912a5d77-fb98-4eee-af32-1334d8f04a53/v2.0/.well-known/openid-configuration
applies_to: Exeter staff and student single sign-on
description: >-
Exeter's Microsoft Entra ID tenant publishes OIDC discovery metadata (200,
application/json) advertising token_endpoint, jwks_uri and
token_endpoint_auth_methods_supported of client_secret_post, private_key_jwt,
client_secret_basic and self_signed_tls_client_auth. Application registration in this
tenant is closed to the public.
sources:
- https://login.microsoftonline.com/912a5d77-fb98-4eee-af32-1334d8f04a53/v2.0/.well-known/openid-configuration
- name: shibbolethSaml
type: saml2
entityId: https://elibrary.exeter.ac.uk/idp/shibboleth
metadataUrl: https://elibrary.exeter.ac.uk/idp/shibboleth
applies_to: Library electronic resources and federated service providers
description: >-
Exeter's own Shibboleth 2.0 identity provider. SSO is offered over HTTP-Redirect,
HTTP-POST, HTTP-POST-SimpleSign and SOAP/ECP; SLO and ArtifactResolution are advertised.
Access is granted to service providers registered in the UK Access Management Federation
or reachable through eduGAIN, not to individual developers.
federations:
- http://mdq.ukfederation.org.uk/entities/https%3A%2F%2Felibrary.exeter.ac.uk%2Fidp%2Fshibboleth
- https://mdq.incommon.org/entities/https%3A%2F%2Felibrary.exeter.ac.uk%2Fidp%2Fshibboleth
sources:
- https://elibrary.exeter.ac.uk/idp/shibboleth
- name: moodleWebServiceToken
type: token
in: query
parameterName: wstoken
applies_to: https://ele.exeter.ac.uk/webservice/rest/server.php
description: >-
Moodle web services are enabled on ELE and gated by a per-user web-service token. An
unauthenticated request returns a well-formed Moodle exception
(ERRORCODE invalidtoken, "Invalid token - token not found") rather than a 404, which is
how the surface was confirmed. Tokens are issued to affiliated users through Moodle, not
through any public registration.
sources:
- https://ele.exeter.ac.uk/webservice/rest/server.php
- name: ltiAdvantage
type: openIdConnect
jwksUrl: https://ele.exeter.ac.uk/mod/lti/certs.php
authorizationUrl: https://ele.exeter.ac.uk/mod/lti/auth.php
applies_to: LTI 1.3 tools launching into ELE
description: >-
ELE acts as an LTI 1.3 Advantage tool platform. It publishes an RSA JWKS at
/mod/lti/certs.php, an OIDC authorization endpoint at /mod/lti/auth.php, and the
Advantage services endpoint at /mod/lti/services.php. Tool deployments are registered by
Exeter, not self-service.
sources:
- https://ele.exeter.ac.uk/mod/lti/certs.php
- https://ele.exeter.ac.uk/mod/lti/services.php
unauthenticated:
- url: https://news.exeter.ac.uk/wp-json/
description: >-
The only Exeter-hosted API that serves data without a credential. The WordPress REST API
reports an empty `authentication` object and serves /wp/v2/posts openly (X-WP-Total 2,596).
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/university-of-exeter-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.