University of Ottawa · Authentication Profile

University Of Ottawa Authentication

Authentication

University of Ottawa declares 0 security scheme(s) across its OpenAPI definitions.

UniversityHigher EducationEducationCanadaOntarioBilingualPublic Research UniversityU15Institutional RepositoryResearch DataLibraryCourse CatalogIdentity FederationShibbolethSAMLDSpaceOAI-PMHJSON APIOpen AccessDataCiteCrossrefROR
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

Raw ↑
generated: '2026-09-01'
method: probed
source: https://ruor.uottawa.ca/server/api/authn/status
x-operator: institution
note: >-
  How authentication actually behaves on the University of Ottawa's institution-operated
  surfaces, established by live anonymous requests on 2026-09-01. uOttawa publishes no
  developer documentation for any of these, so every statement below is a probe result.
surfaces:
  - id: ruor-dspace-rest
    name: uO Research DSpace REST API
    base_url: https://ruor.uottawa.ca/server/api
    operator: institution
    public_read: partial
    scheme: none_required_for_public_reads
    evidence: >-
      GET /authn/status returns HTTP 200 with {"okay": true, "authenticated": false,
      "authenticationMethod": null}, confirming anonymous calls are accepted. GET
      /core/communities and /core/collections return 200 anonymously; GET /core/items and
      GET /core/bitstreams/{uuid} return 401, so item and bitstream enumeration is closed to
      anonymous callers and public discovery must go through /discover/search/objects.
    write_access: >-
      Not attempted. DSpace 8 supports session-based login at /api/authn/login plus an
      X-XSRF-TOKEN CSRF flow; no credentials were used and no write path was probed.
  - id: ruor-oai-pmh
    name: uO Research OAI-PMH
    base_url: https://ruor.uottawa.ca/server/oai/request
    operator: institution
    public_read: true
    scheme: none
    evidence: >-
      Identify, ListMetadataFormats, ListSets and ListRecords all returned HTTP 200 with no
      credentials, key, or referrer requirement.
  - id: www-jsonapi
    name: uottawa.ca Content JSON:API
    base_url: https://www.uottawa.ca/en/jsonapi
    operator: institution
    public_read: true
    scheme: none
    evidence: >-
      The resource index, node/article, node/alert and taxonomy_term/tags all returned HTTP
      200 anonymously. Drupal's JSON:API module is running read-only for anonymous users;
      no write was attempted.
  - id: caf-idp
    name: uOttawa Shibboleth Identity Provider
    base_url: https://fca-caf.uottawa.ca/idp
    operator: institution
    public_read: true
    scheme: saml2
    evidence: >-
      The SAML 2.0 metadata document at /idp/shibboleth is served anonymously (HTTP 200). The
      IdP itself authenticates uottawa.ca principals for federated services; this profile
      records only the public metadata endpoint.
negative_probes:
  - url: https://www.uottawa.ca/.well-known/openid-configuration
    status: 404
    note: No OIDC discovery document on the primary web property.
  - url: https://www.uottawa.ca/.well-known/security.txt
    status: 404
    note: No RFC 9116 security contact.
  - url: https://api.uottawa.ca/
    status: 0
    note: Host does not resolve. No central API gateway.
  - url: https://developer.uottawa.ca/
    status: 0
    note: Host does not resolve. No developer portal, so no key-issuing or onboarding flow exists.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/university-of-ottawa-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.