openapi: 3.2.0 info: title: Qatar University Single Sign-On (OpenID Connect / OAuth… version: '1.0' summary: Qatar University's own institution-operated OpenID Connect provider at sso.qu.edu.qa. description: 'Qatar University operates its own identity provider at `sso.qu.edu.qa` on a WSO2 Identity Server, and it is the strongest machine-readable contract in this profile.' contact: name: Qatar University url: https://www.qu.edu.qa/ x-provenance: generated: '2026-09-01' method: derived source: Transcribed from the live OpenID Connect discovery document at https://sso.qu.edu.qa/oauth2/token/.well-known/openid-configuration (200, application/json, captured to examples/qatar-qu-sso-openid-configuration.json), plus live probes on 2026-09-01 of https://sso.qu.edu.qa/oauth2/jwks (200, RS256 signing key), https://sso.qu.edu.qa/oauth2/userinfo (400, {"error":"invalid_request", "error_description":"Bearer token missing"}), https://sso.qu.edu.qa/oauth2/token (405 on GET) and https://sso.qu.edu.qa/identity/metadata/saml2 (200, application/xml, entityID sso.qu.edu.qa). No endpoint was called with a credential of any kind. x-operator: institution servers: - url: https://sso.qu.edu.qa description: Qatar University Single Sign-On (WSO2 Identity Server) security: [] tags: - name: Client Registration description: OpenID Connect Dynamic Client Registration. paths: /api/identity/oauth2/dcr/v1.1/register: post: tags: - Client Registration operationId: registerClient summary: OpenID Connect Dynamic Client Registration description: Advertised in the discovery document as `registration_endpoint`. Registration is institutional; no public self-service onboarding path was found, and this operation was not exercised. responses: '201': description: Client registered. '401': description: Registration requires authorization. components: securitySchemes: bearerToken: type: http scheme: bearer bearerFormat: JWT description: Access token issued by this provider, presented on the UserInfo endpoint. clientSecretBasic: type: http scheme: basic description: OAuth 2.0 client credentials in the Authorization header (client_secret_basic). clientSecretPost: type: apiKey in: header name: Authorization description: '`client_secret_post` — client_id and client_secret carried in the form body. Modelled here as a named scheme because OpenAPI has no first-class representation for it.'