University of Glasgow · Authentication Profile
University Of Glasgow Authentication
Authentication
University of Glasgow declares 0 security scheme(s) across its OpenAPI definitions.
UniversityHigher EducationEducationUnited KingdomScotlandRussell GroupResearch DataRepositoryOAI-PMHOpen AccessIdentity FederationDigital Library
Methods:
Schemes: 0
OAuth flows:
API key in:
Security Schemes
Source
Authentication Profile
name: University of Glasgow — authentication posture
aid: university-of-glasgow
generated: '2026-08-30'
method: derived
x-evidence-method: probed
source: live probes of University of Glasgow operated hosts, 2026-08-30
summary: >-
Every machine-readable surface the University of Glasgow operates and exposes to the public is
open and unauthenticated: three OAI-PMH endpoints and the read side of the Enlighten EPrints REST
interface all answer anonymously. Everything the institution gates, it gates through one
mechanism — the GUID single sign-on estate behind its Shibboleth SAML 2.0 identity provider. That
identity provider is by some distance the institution's largest and best-maintained machine-readable
artifact, and it is a login federation rather than a programmable API, which is the honest shape of
most of this cohort.
apis:
- aid: university-of-glasgow:enlighten-oai
x-operator: institution
scheme: none
detail: >-
OAI-PMH is an open harvesting protocol. verb=Identify, verb=ListMetadataFormats and
verb=ListRecords all returned 200 with real data and no credential on 2026-08-30.
verified: '2026-08-30'
- aid: university-of-glasgow:researchdata-oai
x-operator: institution
scheme: none
detail: >-
Anonymous verb=ListRecords returned a 266 KB page of live dataset records carrying DOIs under
prefix 10.5525 on 2026-08-30.
verified: '2026-08-30'
- aid: university-of-glasgow:theses-oai
x-operator: institution
scheme: none
detail: Anonymous verb=Identify returned repositoryName "Enlighten Theses" on 2026-08-30.
verified: '2026-08-30'
- aid: university-of-glasgow:enlighten-rest
x-operator: institution
scheme: http-basic
public_read: true
detail: >-
Read access to the dataset indexes, eprint records and subject taxonomy is anonymous — /rest/,
/rest/eprint/, /rest/eprint/1.xml, /rest/eprint/1/title.txt and /rest/subject/ all returned 200
without credentials on 2026-08-30. The user dataset is the exception: /rest/user/ lists
identifiers only and /rest/user/1.xml returned 401, so no personal data is reachable anonymously.
EPrints HTTP Basic credentials are required for user records and for any write. There is no
OAuth, no API key, no token endpoint and no scope model.
verified: '2026-08-30'
- aid: university-of-glasgow:moodle-lti
x-operator: institution
x-vendor: moodle
scheme: oauth2-jwt
detail: >-
The virtual learning environment's LTI 1.3 platform surface is machine-readable but not open:
/mod/lti/certs.php serves the public JWKS anonymously (200), while /mod/lti/token.php returns
400 to an unsigned request and the Moodle Web Services REST endpoint at
/webservice/rest/server.php returns a Moodle invalidtoken exception. Access is by
registered-tool client credentials issued by the institution, not by public self-service. The
scheme is Moodle's, not Glasgow's engineering.
verified: '2026-08-30'
- aid: university-of-glasgow:sierra-library-api
x-operator: institution
x-vendor: innovative-interfaces
scheme: oauth2-client-credentials
detail: >-
The library management system at eleanor.lib.gla.ac.uk exposes the Innovative Interfaces Sierra
API. /iii/sierra-api/v6/info/token returned 401 on 2026-08-30 — live and credentialed, not
absent. Keys are issued by the library to named partners; there is no public registration path.
verified: '2026-08-30'
- aid: university-of-glasgow:worldcat-discovery
x-operator: tenant
x-vendor: oclc
scheme: vendor
detail: >-
gla.on.worldcat.org is Glasgow's OCLC WorldCat Discovery tenancy. Any programmatic access runs
on OCLC's own WorldCat Search API keys and OAuth, documented and operated by OCLC. Not scored
here.
verified: '2026-08-30'
- aid: university-of-glasgow:libguides
x-operator: tenant
x-vendor: springshare
scheme: vendor
detail: >-
gla.libguides.com is Glasgow's Springshare LibGuides tenancy. The LibGuides API is Springshare's
product, keyed per site by Springshare. Not scored here.
verified: '2026-08-30'
identity_federation:
x-operator: institution
protocol: SAML 2.0 / Shibboleth
entity_id: https://idp.gla.ac.uk/shibboleth
scope: gla.ac.uk
metadata:
self_published: https://idp.gla.ac.uk/idp/shibboleth
federation_mdq: http://mdq.ukfederation.org.uk/entities/https%3A%2F%2Fidp.gla.ac.uk%2Fshibboleth
federations:
- UK Access Management Federation
- eduGAIN
bindings:
- urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
- urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign
- urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect
- urn:mace:shibboleth:1.0:profiles:AuthnRequest
entities_registered: 2
service_providers_registered: 0
detail: >-
Glasgow registers a production IdP and a test IdP (https://idptest.gla.ac.uk/idp/shibboleth) in
the UK federation aggregate and no Service Provider entities. Both metadata copies — the IdP's
own and the federation's signed MDQ copy — were fetched and read on 2026-08-30.
verified: '2026-08-30'
notes:
- >-
No developer key, no OAuth client registration, no API key issuance page and no self-service
onboarding of any kind exists on gla.ac.uk. Everything credentialed here is credentialed through
institutional identity or a library/VLE administrator.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/university-of-glasgow-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.