name: Indian Institute of Technology Bombay description: Indian Institute of Technology Bombay public developer/API footprint review for APIs.json cataloging. url: https://raw.githubusercontent.com/api-evangelist/iit-bombay/refs/heads/main/review.yml created: '2026-06-03' modified: '2026-08-30' reviews: - date: '2026-06-03' rating: 2 summary: 'IIT Bombay has no central, unified developer portal. The public API footprint is community- and library-driven: the Students'' Gymkhana OAuth 2.0 Profiles API (documented, but gated to IIT Bombay server infrastructure), the Institute Technical Council ITC SSO service (documented session-based auth), and a live DSpace OAI-PMH 2.0 endpoint over the Central Library institutional repository. All three documentation pages and the OAI-PMH Identify verb resolved with HTTP 200 and the OAI response was verified as valid OAI-PMH 2.0. No fabricated endpoints; all base URLs were probed live. LinkedIn returned HTTP 999 (standard bot block) but the school page exists.' endpoints: - url: https://gymkhana.iitb.ac.in/profiles/doc/ status: 200 note: Gymkhana Profiles OAuth 2.0 API docs (authorize/token/revoke/user endpoints). - url: https://sso.tech-iitb.org/docs/ status: 200 note: ITC Single Sign-On integration docs (ssocall + getuserdata flow). - url: https://dspace.library.iitb.ac.in/ status: 200 note: DSpace institutional repository home (Central Library). - url: https://dspace.library.iitb.ac.in/oai/request?verb=Identify status: 200 note: Live OAI-PMH 2.0 endpoint; Identify verb returns valid OAI-PMH response. - url: https://www.iitb.ac.in/ status: 200 note: Official institutional website. - url: https://github.com/DevCom-IITB status: 200 note: DevCom student developer community GitHub org (InstiApp and related projects). - url: https://github.com/iitb-gymkhana status: 200 note: Gymkhana IIT Bombay GitHub org. - url: https://www.linkedin.com/school/indian-institute-of-technology-bombay/ status: 999 note: LinkedIn school page; 999 is LinkedIn's standard bot-block, page exists. - date: '2026-08-30' rating: 3 pipeline: pipeline-university.md summary: 'University-pipeline re-profile with the operator axis settled first. The June 2026 review missed the largest thing IIT Bombay actually publishes: a first-party, institution-hosted, OpenAPI-described API. InstiApp is served from gymkhana.iitb.ac.in (the institution''s own registrable domain), its autogenerated Swagger 2.0 document at /instiapp/api/docs/?format=openapi returns 200 with 112 paths, 164 operations and 37 definitions, info.contact.email is devcom@iitb.ac.in, and the source is public under AGPL-3.0. A large read surface answers with no credential. Also newly found: the Computer Centre''s central OpenID Connect provider at sso.iitb.ac.in publishes a live discovery document and JWKS — the identity-federation surface class this pipeline treats as a real find. Two corrections against the June review. First, its claim that the DSpace OAI-PMH Identify verb returns a valid OAI-PMH 2.0 response is no longer reproducible: /oai/request answers 403 at the Apache layer with a browser User-Agent, and /xmlui/OAI/request answers 200 with Content-Length 0, a soft-200. The claim is withdrawn and oai-pmh conformance is recorded as unverified, not false, because the DSpace application itself is demonstrably alive. Second, the ITC SSO surface is relabelled x-operator: tenant — it is run by an IIT Bombay student council but tech-iitb.org was registered in 2024 through Hostinger and is not an institution-owned domain. No vendor contract was found attributed to this institution and none was added; the pre-run audit reported no hostless, shared-contract or misbased findings.' endpoints: - url: https://gymkhana.iitb.ac.in/instiapp/api/docs/?format=openapi status: 200 note: First-party autogenerated OpenAPI (Swagger 2.0), 85,661 bytes, host gymkhana.iitb.ac.in. THE find. - url: https://gymkhana.iitb.ac.in/instiapp/api/events status: 200 note: Keyless read — institute events. - url: https://gymkhana.iitb.ac.in/instiapp/api/bodies status: 200 note: Keyless read — 154 student bodies. - url: https://gymkhana.iitb.ac.in/instiapp/api/mess status: 200 note: Keyless read — 22 hostel mess menus. - url: https://gymkhana.iitb.ac.in/instiapp/api/locations status: 200 note: Keyless read — 427 campus map locations. - url: https://gymkhana.iitb.ac.in/instiapp/api/user-me status: 401 note: User-scoped paths correctly gated. - url: https://sso.iitb.ac.in/.well-known/openid-configuration status: 200 note: Institution-operated OIDC discovery — issuer https://sso.iitb.ac.in. Not previously catalogued. - url: https://sso.iitb.ac.in/.well-known/jwks.json status: 200 note: JWKS, one RSA key. - url: https://sso.iitb.ac.in/token status: 400 note: '"method must be POST" — live token endpoint.' - url: https://gymkhana.iitb.ac.in/profiles/oauth/token/ status: 405 note: POST-only OAuth token endpoint, live. - url: https://gymkhana.iitb.ac.in/profiles/user/api/user/ status: 401 note: Live protected OAuth resource. - url: https://dspace.library.iitb.ac.in/oai/request?verb=Identify status: 403 note: 'CORRECTION: 403 at the Apache layer, ErrorDocument 500s behind it. June 2026 claim of a valid Identify response withdrawn.' - url: https://dspace.library.iitb.ac.in/jspui/oai/request?verb=Identify status: 404 note: Genuine DSpace error page — the application is alive, the /oai path is denied. - url: https://dspace.library.iitb.ac.in/xmlui/OAI/request?verb=Identify status: 200 note: Content-Length 0 — soft-200, dead. Would falsely read as live on status alone. - url: https://asc.iitb.ac.in/ status: 200 note: Academic Section — SSO + hCaptcha gate, no API. - url: https://opac.library.iitb.ac.in/ status: 502 note: Library OPAC host answers 502 — dead. - url: https://data.iitb.ac.in/ status: 0 note: No open-data portal — DNS does not resolve. - url: https://hpc.iitb.ac.in/ status: 0 note: No research-computing surface — DNS does not resolve. - url: https://www.iitb.ac.in/llms.txt status: 404 note: No agent-facing surface.