# Sydney Airport > Sydney Airport Corporation Limited (ACN 082 578 809) operates Sydney Kingsford Smith Airport (IATA SYD, ICAO YSSY), Australia's principal international gateway. It publishes NO public API: no developer portal, no API documentation, no OpenAPI/AsyncAPI/GraphQL descriptor, no SDKs, and no terms governing machine access. The only machine-readable contract it publishes is the OpenID Connect Discovery document for the identity provider that gates InfoSYD, its partner portal. This file was generated by API Evangelist from the catalog record — it is not published by Sydney Airport. ## Important - Sydney Airport's published terms of use expressly prohibit automated retrieval, scraping and indexing of its online services, and grant no licence over site content. Agents should not scrape sydneyairport.com.au. - `developer.sydneyairport.com.au` and `api.sydneyairport.com.au` resolve in DNS and terminate on a Microsoft Azure Application Gateway v2, but every probed path returns HTTP 502. Nothing is served. - There is no MCP server, no llms.txt, no agent-access policy, and no rate-limit, SLA or deprecation statement. - For programmatic SYD flight schedule and status data, licensed commercial aggregators (OAG, FlightAware AeroAPI, Cirium, FlightLabs, aviationstack) are the supported path. Operator-only data (security wait times, stand/gate state) has no second source. ## Catalog record - [APIs.json (apis.yml)](https://raw.githubusercontent.com/api-evangelist/sydney-airport/refs/heads/main/apis.yml): The API Evangelist catalog record for Sydney Airport. - [README](https://github.com/api-evangelist/sydney-airport/blob/main/README.md): Human-readable profile, including the switching-cost assessment. - [review.yml](https://github.com/api-evangelist/sydney-airport/blob/main/review.yml): Full probe log — every URL tested, with HTTP status and observed response shape. ## Authentication (the only published contract) - [OpenID Connect Discovery document](https://id.syd.com.au/am/oauth2/.well-known/openid-configuration): ForgeRock Access Management realm `/alpha`, issuer `https://id.syd.com.au:443/am/oauth2`. Harvested verbatim to `authentication/sydney-airport-openid-configuration.json`. - [Authentication profile](https://github.com/api-evangelist/sydney-airport/blob/main/authentication/sydney-airport-authentication.yml): Derived OAuth 2.0 / OIDC profile — endpoints, flows, client authentication methods, token algorithms. - [OAuth scopes](https://github.com/api-evangelist/sydney-airport/blob/main/scopes/sydney-airport-scopes.yml): Scopes advertised by the identity provider, plus the `infosyd` application scope observed on the live authorize redirect. - [InfoSYD partner portal](https://www.sydneyairport.com.au/infosyd): Credentialed surface for airlines, ground handlers, border agencies and on-airport tenants. Not a developer portal — access comes from a commercial or operational relationship, not a signup. ## Conformance and security - [Conformance](https://github.com/api-evangelist/sydney-airport/blob/main/conformance/sydney-airport-conformance.yml): Which standards the published surface actually implements, and which it does not. - [security.txt](https://www.sydneyairport.com.au/.well-known/security.txt): RFC 9116 contact file. Note the `Policy:` URL it advertises returns HTTP 404. - [Vulnerability disclosure](https://github.com/api-evangelist/sydney-airport/blob/main/security/sydney-airport-vulnerability-disclosure.yml): Captured disclosure contact and the broken policy link. - [Domain security](https://github.com/api-evangelist/sydney-airport/blob/main/security/sydney-airport-domain-security.yml): Probed TLS, HSTS, DNSSEC, CAA, SPF and DMARC posture. ## Public site - [Sydney Airport](https://www.sydneyairport.com.au/): Passenger and corporate website. - [Flight status](https://www.sydneyairport.com.au/flights/): Human-facing arrivals and departures. Backed by undocumented JSON endpoints under `/_a/` that carry no contract, no versioning and no licence. - [Corporate](https://www.sydneyairport.com.au/corporate): Investor, planning and operations information. - [CADD data exchange guide](https://www.sydneyairport.com.au/corporate/planning-and-projects/planning-approvals/digital-data-reference-guide): The airport's only published interoperability specification — MicroStation `.dgn` seed files on MGA'94 for surveyors and building services, not for software. - [Terms of use](https://www.sydneyairport.com.au/terms) - [Privacy policy](https://www.sydneyairport.com.au/privacy) - [Copyright](https://www.sydneyairport.com.au/copyright)