University of Lausanne · Authentication Profile

University Of Lausanne Authentication

Authentication

University of Lausanne declares 0 security scheme(s) across its OpenAPI definitions.

EducationHigher EducationUniversitySwitzerlandOpen ScienceResearch DataInstitutional RepositoryResearch RepositoryIdentity FederationOAI-PMHCourse CatalogResearch Computing
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-09-01'
method: probed
source: >-
  Live probes on 2026-09-01 of api.unil.ch, spica.unil.ch, my.unil.ch and the
  SWITCHaai federation metadata. Written by API Evangelist, not published by the
  University of Lausanne.
note: >-
  UNIL publishes no developer portal, no API key programme and no client
  registration of any kind. Every anonymously callable surface below is open
  read; everything else is behind institutional SSO that only a UNIL account
  holder or a SWITCHaai/eduGAIN home organisation can traverse. There is no
  third-party developer path onto any UNIL API.
surfaces:
- name: SPICA Atlas API
  host: spica.unil.ch
  scheme: none
  detail: >-
    Anonymous open read. /projects.json and /projects/query.json both returned
    200 with no credential on 2026-09-01. No key, no quota header, no
    registration.
- name: IRIS DSpace REST API
  host: api.unil.ch
  scheme: mixed
  detail: >-
    Anonymous open read for /core/communities, /core/collections and
    /discover/search/objects (all 200 on 2026-09-01). /core/items and
    /core/bitstreams return 401 to an anonymous client. Authenticated access
    uses the DSpace 7 /api/authn contract (JWT bearer issued after login,
    CSRF token via DSPACE-XSRF-TOKEN), reachable in the root document's HAL
    _links as `authn` and `authorizations`, but IRIS is behind UNIL SSO and
    there is no self-service account.
- name: IRIS OAI-PMH
  host: api.unil.ch
  scheme: none
  detail: >-
    Anonymous open harvest on both contexts, /oai/request and
    /oai/openairecris. No credential, no registration, no rate-limit header
    observed.
- name: UNIL Shibboleth Identity Provider
  host: aai.unil.ch (entityID namespace; no public A record) / unil.login.eduid.ch
  scheme: saml2-shibboleth
  detail: >-
    entityID https://aai.unil.ch/idp/shibboleth, an IDPSSODescriptor with
    OrganizationName unil.ch and shibmd:Scope unil.ch, registered in SWITCHaai
    and exported to eduGAIN. This is the credential authority for everything
    behind my.unil.ch and for the 145 unil.ch entities registered in the same
    federation. Its SSO endpoints run on SWITCH's edu-ID platform at
    unil.login.eduid.ch, so UNIL owns the entity, the scope and the identities
    while SWITCH hosts the endpoint. The SAML metadata is anonymously readable
    only from SWITCH's published aggregates
    (metadata.aai.switch.ch/metadata.switchaai+idp.xml); SWITCH exposes no
    per-entity MDQ service — /entities/<entityID> answers 400 and
    /mdq/entities/<entityID> 302s to an HTML help page. Authentication itself
    is available only to federation members.
- name: my.unil.ch
  host: my.unil.ch
  scheme: institutional-sso
  detail: >-
    The gateway in front of UNIL's student-information, timetable and
    administrative services. Returned 200 (a login surface) on 2026-09-01.
    Nothing behind it is documented as an API and nothing is reachable without
    a UNIL identity.
- name: ADFS / STS
  host: sts.unil.ch
  scheme: ws-federation
  detail: >-
    A second UNIL federation entity, http://sts.unil.ch/adfs/services/trust,
    registered in SWITCHaai alongside the Shibboleth IdP.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/university-of-lausanne-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.