name: Stanford University
description: Stanford University public developer/API footprint review for APIs.json cataloging.
url: https://raw.githubusercontent.com/api-evangelist/stanford/refs/heads/main/review.yml
created: '2026-06-03'
modified: '2026-08-19'
reviews:
- date: '2026-08-19'
rating: 4
summary: 'University-pipeline re-profile. Operator attribution settled first: all 15 surfaces resolve
to hosts under stanford.edu — 15 institution, 0 tenant, 0 vendor, 0 placeholder. Stanford carries
no Figshare/Pure/Ex Libris/Dataverse attribution and none had to be removed. Five first-party OpenAPI
contracts recovered from the sul-dlss GitHub org (SDR, DOR Services, Preservation Catalog, Technical
Metadata, SURI — 76 operations, 46 schemas, Apache 2.0); judged institution-operated by their own
servers[] and info.title, not by fetch URL. Their production hosts are internal: sdr-api-prod resolves
but refuses public connections, and three others are NXDOMAIN — so the contracts are public and the
deployments are not, and the unreachable baseURLs were dropped rather than emitted as dead pointers.
Four surfaces confirmed open with no credential (PURL, IIIF, Library Hours, ExploreCourses) plus a
working oEmbed service. Two new finds not in the June profile: signed Shibboleth SAML 2.0 IdP metadata
at idp.stanford.edu/metadata.xml (satisfies both saml and shibboleth in the education regime) and
the AI API Gateway, a metered institution-operated LLM gateway billed to a Stanford PTA. The June
description''s ''AI API Gateway'' claim was unverifiable from the developers page but proved correct
at uit.stanford.edu/service/ai-api-gateway. Honest absences recorded: no OAI-PMH provider (six verb=Identify
probes, all 404), no open-data portal, no OAuth scopes, no info.contact or termsOfService in any contract,
no examples on any of the 76 operations.'
endpoints:
- url: https://idp.stanford.edu/metadata.xml
status: 200
note: Signed SAML 2.0 EntityDescriptor, entityID https://idp.stanford.edu/, shibmd:Scope stanford.edu,
validUntil 2027-08-16.
- url: https://library-hours.stanford.edu/libraries.json
status: 200
note: JSON:API document; 24 library locations. The real Library Hours endpoint.
- url: https://purl.stanford.edu/bb157hs6068.xml
status: 200
note: cocina-models/0.127.0 publicObject — Stanford's own metadata model.
- url: https://purl.stanford.edu/bb157hs6068.mods
status: 200
note: MODS 3.7 projection of the same druid.
- url: https://purl.stanford.edu/bb157hs6068/iiif/manifest
status: 200
note: IIIF Presentation 2.1 manifest, application/ld+json.
- url: https://embed.stanford.edu/embed?url=https://purl.stanford.edu/bb157hs6068
status: 200
note: oEmbed 1.0 rich response, provider_name 'SUL Embed Service'. The root path returns an empty
200.
- url: https://explorecourses.stanford.edu/search?view=xml-20140630&q=CS106A&academicYear=20242025
status: 200
note: Live course XML. Body carries true and 20200810.
- url: https://raw.githubusercontent.com/sul-dlss/dor-services-app/main/openapi.yml
status: 200
note: OpenAPI 3.1.2, servers dor-services-{env}.stanford.edu — institution-operated.
- url: https://raw.githubusercontent.com/sul-dlss/sdr-api/main/openapi.yml
status: 200
note: OpenAPI 3.0.0, servers sdr-api-{env}.stanford.edu.
- url: https://uit.stanford.edu/service/ai-api-gateway
status: 200
note: AI API Gateway — API keys, PTA billing, approved for High Risk data and PHI.
- url: https://uit.stanford.edu/security/responsibleai
status: 200
note: Responsible AI at Stanford — AIPolicy pointer.
- url: https://library-status.stanford.edu/
status: 200
note: Stanford Libraries system status.
- url: https://purl.stanford.edu/oai?verb=Identify
status: 404
note: No OAI-PMH provider. One of six negative probes across purl, sdr, library and searchworks hosts.
- url: https://searchworks.stanford.edu/?q=maps&search_field=search
status: 200
note: F5/Shape JavaScript bot challenge body, not the application. Live for humans, unreadable to
an automated client.
- url: https://sdr-api-prod.stanford.edu/
status: 0
note: Resolves in public DNS (171.67.21.17) but does not answer a public TCP connection — internal
network.
- url: https://www.stanford.edu/.well-known/security.txt
status: 410
note: Explicit 410 Gone; no RFC 9116 security.txt.
- url: https://www.stanford.edu/llms.txt
status: 404
note: No llms.txt.
- date: '2026-06-03'
rating: 4
summary: 'Stanford has a strong, multi-unit developer footprint. Two live public developer hubs were
verified: University IT (uit.stanford.edu/developers) and Stanford Libraries (api.library.stanford.edu).
The Libraries publish open, documented APIs — IIIF, PURL, Embed, Digital Stacks, and Library Hours
— backing the Stanford Digital Repository (all doc paths use hyphens, e.g. /docs/digital-stacks/api/;
underscore variants 404). The Registrar''s ExploreCourses exposes a confirmed-live XML query interface
(?view=xml-20140630), documented by community SDKs rather than a formal reference. The CAP/Stanford
Profiles API and its console are live but credentialed via HelpSU. The MaIS Registry APIs (Account,
Person, Student, CourseClass, Privilege, Workgroup) are publicly documented but gated behind an x509
client certificate with no public base URLs. GitHub presence verified at sul-dlss and SU-SWS.'
endpoints:
- url: https://uit.stanford.edu/developers/apis
status: 200
note: UIT developer hub; MaIS Registry APIs (x509-cert gated).
- url: https://api.library.stanford.edu/docs/iiif/api/
status: 200
note: Stanford Libraries IIIF API docs.
- url: https://api.library.stanford.edu/docs/purl/api/
status: 200
note: PURL API docs.
- url: https://api.library.stanford.edu/docs/library-hours/api/
status: 200
note: Library Hours API docs.
- url: https://explorecourses.stanford.edu/search?view=xml-20140630
status: 200
note: ExploreCourses XML query — confirmed live; community-documented.
- url: https://cap.stanford.edu/cap-api/console
status: 200
note: CAP/Profiles API console; access credentialed via HelpSU.
- url: https://github.com/sul-dlss
status: 200
note: Stanford University Digital Library (DLSS) GitHub org.
- url: https://github.com/SUDigitalRepository
status: 404
note: Does not exist; correct org is github.com/sul-dlss.