openapi: 3.2.0 info: title: Qatar University Single Sign-On (OpenID Connect / OAuth… version: '1.0' summary: Qatar University's own institution-operated OpenID Connect provider at sso.qu.edu.qa. description: 'Qatar University operates its own identity provider at `sso.qu.edu.qa` on a WSO2 Identity Server, and it is the strongest machine-readable contract in this profile.' contact: name: Qatar University url: https://www.qu.edu.qa/ x-provenance: generated: '2026-09-01' method: derived source: Transcribed from the live OpenID Connect discovery document at https://sso.qu.edu.qa/oauth2/token/.well-known/openid-configuration (200, application/json, captured to examples/qatar-qu-sso-openid-configuration.json), plus live probes on 2026-09-01 of https://sso.qu.edu.qa/oauth2/jwks (200, RS256 signing key), https://sso.qu.edu.qa/oauth2/userinfo (400, {"error":"invalid_request", "error_description":"Bearer token missing"}), https://sso.qu.edu.qa/oauth2/token (405 on GET) and https://sso.qu.edu.qa/identity/metadata/saml2 (200, application/xml, entityID sso.qu.edu.qa). No endpoint was called with a credential of any kind. x-operator: institution servers: - url: https://sso.qu.edu.qa description: Qatar University Single Sign-On (WSO2 Identity Server) security: [] tags: - name: Discovery description: Provider metadata and signing keys. paths: /oauth2/token/.well-known/openid-configuration: get: tags: - Discovery operationId: getOpenIdConfiguration summary: Get the OpenID Connect discovery document description: Returns the provider configuration. Note the non-standard location — the well-known path is nested under `/oauth2/token/` rather than served from the host root, so a client following RFC 8414 by appending `/.well-known/openid-configuration` to the issuer will not find it. responses: '200': description: OpenID Provider Metadata. content: application/json: schema: $ref: '#/components/schemas/OpenIdConfiguration' examples: observed: summary: Observed 2026-09-01 externalValue: ../../examples/qatar-qu-sso-openid-configuration.json /oauth2/jwks: get: tags: - Discovery operationId: getJwks summary: Get the JSON Web Key Set description: Returns the RSA public key set used to verify ID token and userinfo signatures (RS256). responses: '200': description: JWKS document. content: application/json: schema: $ref: '#/components/schemas/Jwks' components: schemas: OpenIdConfiguration: type: object description: OpenID Provider Metadata as served by this deployment. properties: issuer: type: string format: uri description: Observed value https://sso.qu.edu.qa:9443/oauth2endpoints/token — the WSO2 management port, inconsistent with the :443 endpoints in the same document. authorization_endpoint: type: string format: uri token_endpoint: type: string format: uri userinfo_endpoint: type: string format: uri jwks_uri: type: string format: uri registration_endpoint: type: string format: uri introspection_endpoint: type: string format: uri revocation_endpoint: type: string format: uri end_session_endpoint: type: string format: uri check_session_iframe: type: string format: uri scopes_supported: type: array items: type: string response_types_supported: type: array items: type: string grant_types_supported: type: array items: type: string claims_supported: type: array items: type: string subject_types_supported: type: array items: type: string enum: - pairwise - public id_token_signing_alg_values_supported: type: array items: type: string code_challenge_methods_supported: type: array items: type: string required: - issuer - authorization_endpoint - token_endpoint - jwks_uri Jwks: type: object properties: keys: type: array items: type: object properties: kty: type: string use: type: string kid: type: string alg: type: string n: type: string e: type: string required: - keys securitySchemes: bearerToken: type: http scheme: bearer bearerFormat: JWT description: Access token issued by this provider, presented on the UserInfo endpoint. clientSecretBasic: type: http scheme: basic description: OAuth 2.0 client credentials in the Authorization header (client_secret_basic). clientSecretPost: type: apiKey in: header name: Authorization description: '`client_secret_post` — client_id and client_secret carried in the form body. Modelled here as a named scheme because OpenAPI has no first-class representation for it.'