How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Shibboleth Identity Provider (Tuakiri / eduGAIN)

The university's own SAML 2.0 Identity Provider. entityID https://idp.vuw.ac.nz/idp/shibboleth, shibmd:Scope vuw.ac.nz, metadata served unauthenticated over HTTPS GET and republished in the signed Tuakiri (New Zealand Access Federation) aggregate, where it has been registered since 2012-06-26 and from where it reaches eduGAIN. Carries the REFEDS Research & Scholarship entity category and a REFEDS Sirtfi assurance certification. Advertises SAML2 HTTP-POST, HTTP-Redirect and SOAP/ECP single sign-on, HTTP-POST and HTTP-Redirect single logout, persistent and transient NameID formats, and an eduPerson/SCHAC/auEduPerson attribute release including mail, schacHomeOrganization, schacHomeOrganizationType and auEduPersonSharedToken. This is institution-operated by definition and is the university's strongest machine-readable asset.

Shibboleth Identity Provider (Tuakiri / eduGAIN) is one of 10 APIs that Victoria University of Wellington publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Identity Federation, SAML, Shibboleth, Tuakiri, and eduGAIN. The published artifact set on APIs.io includes an OpenAPI specification and API documentation.

This API exposes 2 operations across 2 paths, and defines 3 schemas. It is described by OpenAPI 3.2.0, at version 2026-08-30.

Requests are made against a single base URL, https://idp.vuw.ac.nz.

2 operations 2 paths 3 schemas 2 GET

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
2026-08-30
Base URL
https://idp.vuw.ac.nz/idp/shibboleth
Resource Areas
1

Paths & Operations 2

Across 2 paths, the API surfaces 2 operations — 2 GET. Each is listed below with its method, path, parameters, and response codes.

IdentityFederation 2

SAML 2.0 identity federation surfaces operated by the institution.

GET
/idp/shibboleth
Retrieve the institution's SAML 2.0 IdP metadata
getIdpSamlMetadata → 200
GET
/idp/profile/SAML2/Redirect/SSO
SAML 2.0 HTTP-Redirect single sign-on endpoint
samlRedirectSso 4 params → 200400

Schemas 3

The contract defines 3 schemas that model the data the API accepts and returns. The most detailed are IDPSSODescriptor (5 properties), Endpoint (2 properties), EntityDescriptor (2 properties). Each schema is shown below with its type and property counts.

EntityDescriptor
object
SAML 2.0 metadata EntityDescriptor, defined by OASIS saml-metadata-2.0-os, not by this document. Modelled here only far enough to make the endpoint's payload l…
2 properties
IDPSSODescriptor
object
5 properties
Endpoint
object
2 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

victoria-university-of-wellington-identity-federation-openapi.yml Raw ↑

Other APIs Victoria University of Wellington publishes across the network.

Website Global Object
Institutional Repository (self-hosted DSpace)
Open Access Repository (Figshare tenancy)
Te Waharoa Library Discovery (Ex Libris Primo / Alma tenancy)
Nuku Learning Management (Instructure Canvas tenancy)
Research Information System (Symplectic Elements tenancy)
Enterprise Single Sign-On (WSO2 Identity Server)
Student Records (Ellucian Banner Self-Service tenancy)
Microsoft Entra ID Tenant (production browser sign-on)
Where this information came from

This is an independent, third-party profile of Shibboleth Identity Provider (Tuakiri / eduGAIN), published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.