--- name: Carnegie Mellon University description: Carnegie Mellon University public developer/API footprint review for APIs.json cataloging. Re-profiled 2026-08-19 under the API Evangelist university pipeline, which settles operator attribution (institution / tenant / vendor) before any contract is saved. url: https://raw.githubusercontent.com/api-evangelist/carnegie-mellon-university/refs/heads/main/review.yml created: '2026-06-03' modified: '2026-08-19' reviews: - date: '2026-08-19' rating: 3 summary: 'Re-profile under the university pipeline. The 2026-06 profile scored CMU 41.1 with agent readiness 38.9 on eleven tag-split copies of ONE figshare contract for KiltHub — the same document, and the same 38.9 fingerprint, shared by the eight top-scoring universities in the catalog. Those ten OpenAPIs and twenty derived collection files (every request URL api.figshare.com) were removed, along with the figshare-derived scopes, vocabulary, rules and JSON-LD context that inherited the vendor''s operator. What replaced them is smaller and genuinely CMU''s. Two of the three institution-operated APIs were not in the profile at all: the CERT/CC Vulnerability Notes API, operated by the CERT Division of the Software Engineering Institute — an FFRDC operated by Carnegie Mellon — which the cohort audit could not see because it lives on cert.org rather than cmu.edu; and the CMU Library Publishing Service, a REST API plus a conformant OAI-PMH 2.0 provider self-hosted at 128.2.24.32 inside CMU''s own /16, whose Identify response names the repository as Carnegie Mellon University Library Publishing Service. Neither publishes an OpenAPI, so both specs in this repo are marked derived and attributed to API Evangelist. Domain-standard conformance under the education regime: oai-pmh, shibboleth, saml and datacite all institution-operated; lti present but tenant (canvas.cmu.edu CNAMEs to Instructure); crossref confirmed absent — CMU is not a Crossref member. Real absences confirmed by probe, not assumed: no developer portal, no OpenAPI anywhere, no status page, no deprecation policy, no llms.txt, no security.txt, and CMU''s own dining application is a soft-200 Blazor catch-all that returns the SPA shell for a deliberate nonsense path. Expect the composite to FALL. That is the correction working.' endpoints: - url: https://api.delphi.cmu.edu/epidata/version status: 200 note: Delphi Epidata service version 4.1.44 — institution - url: https://api.delphi.cmu.edu/epidata/fluview/?regions=nat&epiweeks=202001 status: 200 note: Real ILINet records — institution - url: https://api.delphi.cmu.edu/epidata/fluview/ status: 200 note: Parameter error served with HTTP 200, result -1 — the failure mode to know about - url: https://kb.cert.org/vuls/api/421644/ status: 200 note: CERT/CC Vulnerability Note, 55-field JSON payload — institution (CMU SEI) - url: https://kb.cert.org/vuls/api/421644/vendors/ status: 200 note: 123 vendor coordination records — institution - url: https://kb.cert.org/vuls/atomfeed/ status: 200 note: Atom feed author uri https://www.sei.cmu.edu — the operator evidence for cert.org - url: https://www.cert.org/ status: 200 note: 301s to https://www.sei.cmu.edu/divisions/cert/ — cert.org is CMU - url: https://lps.library.cmu.edu/api/journals/ status: 200 note: 5 journals, publisher "Carnegie Mellon University Library Publishing Service" — institution - url: https://ncmr.lps.library.cmu.edu/api/oai/?verb=Identify status: 200 note: OAI-PMH 2.0 on CMU hardware (128.2.24.32); adminEmail librarypublishing@andrew.cmu.edu - url: https://ncmr.lps.library.cmu.edu/api/articles/ status: 200 note: 379 articles — institution - url: https://login.cmu.edu/idp/shibboleth status: 200 note: SAML 2.0 metadata, InCommon R&S entity category — institution - url: https://mdq.incommon.org/entities/https%3A%2F%2Flogin.cmu.edu%2Fidp%2Fshibboleth status: 200 note: Signed InCommon/eduGAIN entity descriptor - url: https://api.datacite.org/repositories/cmu.lps status: 200 note: CMU Library Publishing Service, 545 DOIs, prefixes 10.34891/10.34842 resolving to CMU hosts - url: https://kilthub.cmu.edu/ status: 202 note: CNAME FIGSHARE.COM — tenant, bot challenge, graded live - url: https://api.figshare.com/v2/oai?verb=Identify status: 200 note: repositoryName "figshare" on the VENDOR host — this is not a CMU OAI-PMH endpoint - url: https://canvas.cmu.edu/api/lti/security/jwks status: 200 note: LTI 1.3 JWKS; canvas.cmu.edu CNAME CMU-VANITY.INSTRUCTURE.COM — tenant - url: https://api.cmueats.com/v2/locations status: 200 note: ScottyLabs student org, non-CMU domain — tenant, endorsement unverified - url: https://apps.studentaffairs.cmu.edu/dining/conceptinfo/zzz-nonsense-xyz status: 200 note: 'NEGATIVE PROBE: soft-200 Blazor catch-all returns SPA shell. No CMU dining API exists.' - url: https://api.delphi.cmu.edu/epidata/openapi.json status: 404 note: No OpenAPI published; .yaml, /openapi and /swagger.json also 404 - url: https://api.heinz.cmu.edu/courses_api/course_list/ status: 200 note: Now text/html. Retired without a deprecation notice or Sunset header. - url: https://www.cmu.edu/llms.txt status: 404 note: No llms.txt - url: https://www.cmu.edu/.well-known/security.txt status: 404 note: No security.txt - url: https://api.crossref.org/members?query=carnegie+mellon status: 200 note: total-results 0 — CMU is not a Crossref member - date: '2026-06-03' rating: 3 summary: 'CMU has no single central developer portal, but a genuinely strong public research-API footprint. Verified live: the Delphi Epidata API returns real JSON (covidcast_meta and fluview both 200) with full docs and an active GitHub org (cmu-delphi); the KiltHub OAI-PMH endpoint on figshare returns valid OAI-PMH XML with real CMU records in set portal_231; and the Shibboleth Web Login identity provider metadata resolves. The Heinz College courses_api now 302-redirects to a student web page and is no longer a usable public API, so it was excluded. The Schedule of Classes is a servlet web app, not a documented API, so it was not cataloged as an API. No fabricated endpoints; only verified URLs and properties are included.' endpoints: - url: https://api.delphi.cmu.edu/epidata/covidcast_meta/ status: 200 note: Delphi Epidata API returns live JSON metadata - url: https://api.delphi.cmu.edu/epidata/fluview/?regions=nat&epiweeks=202001 status: 200 note: Delphi fluview endpoint returns data - url: https://cmu-delphi.github.io/delphi-epidata/ status: 200 note: Delphi Epidata API documentation portal - url: https://github.com/cmu-delphi status: 200 note: Delphi group GitHub org (clients and source) - url: https://api.figshare.com/v2/oai?verb=ListRecords&metadataPrefix=oai_dc&set=portal_231 status: 200 note: KiltHub OAI-PMH CMU set returns real records - url: https://kilthub.cmu.edu/ status: 202 note: KiltHub institutional repository (figshare-hosted) - url: https://login.cmu.edu/idp/shibboleth status: 200 note: Shibboleth identity provider metadata endpoint - url: https://api.heinz.cmu.edu/courses_api/course_list/ status: 302 note: Former Heinz courses API now redirects to student web page; excluded - url: https://enr-apps.as.cmu.edu/open/SOC/SOCServlet status: 200 note: Schedule of Classes servlet UI, not a documented API - url: https://github.com/cmu-lib status: 200 note: CMU University Libraries GitHub org - url: https://www.cmu.edu/ status: 200 note: Official university website