openapi: 3.2.0 info: title: Qatar University Single Sign-On ( / OAuth 2.0) OpenID… version: '1.0' summary: Qatar University's own institution-operated OpenID Connect provider at sso.qu.edu.qa. description: 'Qatar University operates its own identity provider at `sso.qu.edu.qa` on a WSO2 Identity Server, and it is the strongest machine-readable contract in this profile.' contact: name: Qatar University url: https://www.qu.edu.qa/ x-provenance: generated: '2026-09-01' method: derived source: Transcribed from the live OpenID Connect discovery document at https://sso.qu.edu.qa/oauth2/token/.well-known/openid-configuration (200, application/json, captured to examples/qatar-qu-sso-openid-configuration.json), plus live probes on 2026-09-01 of https://sso.qu.edu.qa/oauth2/jwks (200, RS256 signing key), https://sso.qu.edu.qa/oauth2/userinfo (400, {"error":"invalid_request", "error_description":"Bearer token missing"}), https://sso.qu.edu.qa/oauth2/token (405 on GET) and https://sso.qu.edu.qa/identity/metadata/saml2 (200, application/xml, entityID sso.qu.edu.qa). No endpoint was called with a credential of any kind. x-operator: institution servers: - url: https://sso.qu.edu.qa description: Qatar University Single Sign-On (WSO2 Identity Server) security: [] tags: - name: OpenID Connect description: Authorization, user info and session management. paths: /oauth2/authorize: get: tags: - OpenID Connect operationId: authorize summary: OAuth 2.0 / OpenID Connect authorization endpoint description: Browser-facing authorization endpoint. Supported response types are `code`, `id_token`, `token`, `id_token token` and `device`; response modes are `query`, `fragment` and `form_post`; PKCE is supported with `S256` and `plain`. parameters: - name: response_type in: query required: true schema: type: string enum: - code - id_token - token - id_token token - device - name: client_id in: query required: true schema: type: string - name: redirect_uri in: query required: true schema: type: string format: uri - name: scope in: query required: false schema: type: string examples: - openid profile email - name: state in: query required: false schema: type: string - name: code_challenge in: query required: false schema: type: string - name: code_challenge_method in: query required: false schema: type: string enum: - S256 - plain responses: '302': description: Redirect back to the client's `redirect_uri` with a code, token or error. /oauth2/userinfo: get: tags: - OpenID Connect operationId: getUserInfo summary: OpenID Connect UserInfo endpoint description: Returns claims about the authenticated end user. Responses may be signed with RS256. security: - bearerToken: [] responses: '200': description: UserInfo claims. content: application/json: schema: type: object '400': description: 'Missing or malformed bearer token. Observed 2026-09-01 without a credential: `{"error_description":"Bearer token missing","error":"invalid_request"}`. Note this is a 400, not the RFC 6750 401 with a `WWW-Authenticate` header.' content: application/json: schema: $ref: '#/components/schemas/OAuthError' examples: observed: value: error: invalid_request error_description: Bearer token missing /oidc/logout: get: tags: - OpenID Connect operationId: endSession summary: RP-initiated logout description: End-session endpoint. Back-channel logout is supported and session-aware. responses: '302': description: Redirect after session termination. /oidc/checksession: get: tags: - OpenID Connect operationId: checkSession summary: OpenID Connect session-management check_session_iframe responses: '200': description: Session management iframe. content: text/html: schema: type: string components: schemas: OAuthError: type: object description: RFC 6749 section 5.2 error object. properties: error: type: string error_description: type: string required: - error securitySchemes: bearerToken: type: http scheme: bearer bearerFormat: JWT description: Access token issued by this provider, presented on the UserInfo endpoint. clientSecretBasic: type: http scheme: basic description: OAuth 2.0 client credentials in the Authorization header (client_secret_basic). clientSecretPost: type: apiKey in: header name: Authorization description: '`client_secret_post` — client_id and client_secret carried in the form body. Modelled here as a named scheme because OpenAPI has no first-class representation for it.'