--- name: Technical University of Berlin description: Technical University of Berlin public developer/API footprint review for APIs.json cataloging. url: https://raw.githubusercontent.com/api-evangelist/tu-berlin/refs/heads/main/review.yml created: '2026-06-03' modified: '2026-08-30' reviews: - date: '2026-08-30' rating: 3 summary: >- University-pipeline re-profile. Operator attribution was settled before anything was saved: seven surfaces are institution-operated (hosts under tu.berlin / tu-berlin.de) and one — library discovery on Ex Libris Primo — is a tenant relationship, recorded as such. No vendor contract is saved under this slug and no OpenAPI is derived: TU Berlin authors none, and the generic specifications of the products it deploys (DSpace, GitLab, Synapse, Moodle) belong to those vendors' own profiles. Three new institution-operated surfaces were found that the June 2026 review missed: a public Shibboleth SAML 2.0 IdP metadata document (entityID https://ephraim.tu-berlin.de/shibboleth, DFN-AAI, scope tu-berlin.de), a Matrix homeserver running Synapse 1.157.2 with the Client-Server API answering unauthenticated, and ISIS (Moodle) acting as an LTI 1.3 platform with a public RS256 JWKS. Two June facts were WRONG and are corrected: the GitLab API is not fully gated (GET /api/v4/projects returns 200 with X-Total 2851 unauthenticated; only /version, /metadata and /mcp are 401), and DepositOnce runs DSpace 9.4, not 8.1. Education-regime domain standards confirmed live: oai-pmh, saml, shibboleth, lti, datacite (DOI prefix 10.14279, DataCite client tib.tub). orcid, crossref, scim, oneroster, caliper, qti and ed-fi were probed and NOT found — recorded as absent rather than claimed. No llms.txt (404) and no security.txt (403). endpoints: - url: https://api-depositonce.tu-berlin.de/server/oai/request?verb=Identify status: 200 note: OAI-PMH 2.0 Identify, repositoryName DepositOnce, earliest datestamp 1999-01-18. - url: https://api-depositonce.tu-berlin.de/server/oai/request?verb=ListMetadataFormats status: 200 note: 15 metadata prefixes incl. oai_dc, qdc, mods, mets, rioxx, etdms, xoai. - url: https://api-depositonce.tu-berlin.de/server/api status: 200 note: DSpace REST/HAL root, dspaceVersion "DSpace 9.4-SNAPSHOT" (was 8.1 in June). - url: https://api-depositonce.tu-berlin.de/server/api/discover/search/objects?size=1 status: 200 note: Discovery search readable anonymously. - url: https://api-depositonce.tu-berlin.de/server/api/core/items?size=1 status: 401 note: Item listing requires authentication — anonymous read is partial, not total. - url: https://api-depositonce.tu-berlin.de/server/opensearch/service status: 200 note: OpenSearch 1.1 description with atom and rss result templates. - url: https://shibboleth.tu-berlin.de/idp/shibboleth status: 200 note: SAML 2.0 IdP metadata, 15,920 bytes, IDPSSODescriptor + AttributeAuthorityDescriptor. - url: https://git.tu-berlin.de/api/v4/projects?visibility=public status: 200 note: 2,851 public projects listed WITHOUT credentials (X-Total header). - url: https://git.tu-berlin.de/api/v4/version status: 401 note: Version endpoint still gated — the June "fully gated" reading came from here alone. - url: https://git.tu-berlin.de/.well-known/openid-configuration status: 200 note: GitLab instance is its own OIDC provider; PKCE S256, 26 scopes incl. mcp, ai_features. - url: https://matrix.tu-berlin.de/_matrix/client/versions status: 200 note: Matrix Client-Server API, r0.0.1 through v1.12. - url: https://matrix.tu-berlin.de/_matrix/federation/v1/version status: 200 note: Synapse 1.157.2. - url: https://isis.tu-berlin.de/mod/lti/certs.php status: 200 note: LTI 1.3 platform JWKS (RS256) served by the institutional Moodle. - url: https://isis.tu-berlin.de/webservice/rest/server.php status: 200 note: Moodle web services enabled but closed — XML moodle_exception, invalidtoken. - url: https://tubcloud.tu-berlin.de/status.php status: 200 note: Nextcloud 32.0.9 Enterprise; the WebDAV/OCS surface itself is account-gated. - url: https://api.datacite.org/prefixes/10.14279 status: 200 note: DepositOnce DOI prefix, DataCite client tib.tub — evidence for datacite conformance. - url: https://tu-berlin.hosted.exlibrisgroup.com/primo-explore/search?tab=tub_all&vid=TUB status: 200 note: Library discovery is an Ex Libris Primo TENANT, not TU Berlin engineering. - url: https://moseskonto.tu-berlin.de/moses/verzeichnis/index.html status: 200 note: Moses course catalog (VVZ) — public but HTML only, no JSON/CSV/API surface. - url: https://www.tu.berlin/robots.txt status: 200 note: Carries a Content-Signal directive — ai-train=no, search=yes, ai-input=no. - url: https://www.tu.berlin/llms.txt status: 404 note: No llms.txt. - url: https://www.tu.berlin/.well-known/security.txt status: 403 note: nginx 403 — no security.txt served. - date: '2026-06-03' rating: 2 summary: >- TU Berlin has no unified developer portal. The confirmed public, machine-readable API surface is the DepositOnce institutional repository (DSpace 8.1): its OAI-PMH endpoint returned a valid Identify response and its REST/HAL API root returned a HAL document reporting dspaceVersion "DSpace 8.1" — both live (HTTP 200). The self-hosted GitLab instance (git.tu-berlin.de) is reachable but its API is gated: /api/v4/version returned HTTP 401, requiring Shibboleth SSO. Authentication is Shibboleth/SAML via the DFN-AAI federation (no public OAuth/OIDC IdP confirmed). The library "APIs for Scientific Resources" page lists only external third-party APIs (OECD, World Bank, IEEE Xplore, OpenAlex, etc.), not TU Berlin's own. Public GitHub orgs TU-Berlin and TUUB exist. No endpoints were fabricated; every URL below was probed live. endpoints: - url: https://api-depositonce.tu-berlin.de/server/oai/request?verb=Identify status: 200 note: Valid OAI-PMH 2.0 Identify response, repository "DepositOnce", DSpace 8.1. - url: https://api-depositonce.tu-berlin.de/server/api status: 200 note: DSpace REST/HAL API root, dspaceVersion "DSpace 8.1", _links hypermedia. - url: https://depositonce.tu-berlin.de/ status: 200 note: DepositOnce repository home (DSpace UI). - url: https://git.tu-berlin.de/ status: 200 note: GitLab Enterprise Edition instance; login required. - url: https://git.tu-berlin.de/api/v4/version status: 401 note: GitLab REST API present but gated; requires authentication. - url: https://github.com/TU-Berlin status: 200 note: Public GitHub organization, ~29 repos (many migrated to GitLab). - url: https://www.tu.berlin/en status: 200 note: Official institutional website (English). - url: https://www.tu.berlin/en/ub/search-borrow/search-for-papers-standards/free-online-resources/apis-for-scientific-resources status: 200 note: Library guide listing external third-party APIs only, not TU Berlin's own.