--- name: Autonomous University of Madrid description: Autonomous University of Madrid public developer/API footprint review for APIs.json cataloging. url: https://raw.githubusercontent.com/api-evangelist/uam/refs/heads/main/review.yml created: '2026-06-03' modified: '2026-09-01' reviews: - date: '2026-09-01' rating: 3 summary: >- Re-profiled under the university pipeline, with operator settled before any surface was saved. The 2026-06-03 profile was correct as far as it went but incomplete: it recorded two surfaces and missed four more. Operator was settled by address space rather than hostname, and the answer is unusually clean for this cohort — repositorio.uam.es, revistas.uam.es, moodle.uam.es, posgrado.uam.es, sede.uam.es and id.uam.es all resolve inside RIPE inetnum 150.244.0.0 – 150.244.255.255, netname UAM, org ORG-UADM1-RIPE, with no CNAME to any vendor platform. UAM licenses DSpace, OJS and Moodle and runs them itself. New institution-operated finds this pass: an OAI-PMH 2.0 endpoint over the Open Journal Systems journals portal at revistas.uam.es; a Shibboleth service provider on the repository host self-publishing SAML metadata and a discovery feed naming IDP_UAM; two Moodle instances publishing live LTI 1.3 JWKS; and an OpenSearch 1.1 descriptor on the repository. New relationships: UAM's SAML identity provider registered in SIR/eduGAIN through RedIRIS (Sirtfi-assured, scope uam.es), Crossref membership 6788 under prefix 10.15366 with 10,886 DOIs, ROR 01cby8j38, Handle prefix 10486, and two Springshare tenancies (biblioguias → region-eu.libguides.com, biblioagenda → region-eu.libcal.com) recorded as tenant rather than saved as contracts. No vendor product specification was stored. Two access conditions worth recording: revistas.uam.es fronts browser User-Agents with an Anubis proof-of-work challenge that returns 200 on every path, and portalcientifico.uam.es — linked from UAM's own library page — resolves outside UAM address space to 45.151.245.19 and never completes a TLS handshake, so it could not be classified. Still absent and stated rather than padded: no developer portal, no OpenAPI, no API terms, no key issuance, no open-data portal, no DataCite membership, no institutional GitHub organization. endpoints: - url: https://repositorio.uam.es/server/api status: 200 note: DSpace 7.6.5 HAL REST root, anonymous read, dspaceName "Biblos-e Archivo". - url: https://repositorio.uam.es/server/oai/request?verb=Identify status: 200 note: OAI-PMH 2.0 Identify, repositoryIdentifier repositorio.uam.es. - url: https://repositorio.uam.es/server/opensearch/service status: 200 note: OpenSearch 1.1 description document for Biblos-e Archivo. - url: https://repositorio.uam.es/Shibboleth.sso/Metadata status: 200 note: Self-published SAML SP metadata, entityID https://repositorio.uam.es/shibboleth. - url: https://repositorio.uam.es/Shibboleth.sso/DiscoFeed status: 200 note: Discovery feed listing IDP_UAM. - url: https://repositorio.uam.es/server/api/authn/status status: 200 note: 'WWW-Authenticate advertises shibboleth, ip and password realms for the REST API.' - url: https://revistas.uam.es/index.php/index/oai?verb=Identify status: 200 note: >- OJS 3.3.0.6 OAI-PMH 2.0, "Portal de revistas electrónicas de la UAM". Requires a plain User-Agent; browser User-Agents get an Anubis challenge that 200s on every path. - url: https://moodle.uam.es/mod/lti/certs.php status: 200 note: LTI 1.3 platform JWKS, RS256, kid 3ef1afab74110b0d11ed. - url: https://moodle.uam.es/mod/lti/token.php status: 400 note: 'LTI Advantage token service; POST without a signed assertion returns {"error":"invalid_request"}.' - url: https://moodle.uam.es/webservice/rest/server.php status: 200 note: Moodle web services enabled, returns invalidtoken exception; tokens issued by UAM only. - url: https://posgrado.uam.es/mod/lti/certs.php status: 200 note: Second UAM Moodle instance, its own LTI 1.3 JWKS. - url: https://technical.edugain.org/api.php?action=show_entity&entityid=https%3A%2F%2Fwww.rediris.es%2Fsir%2Fuamidp&format=json status: 200 note: >- SAML EntityDescriptor for UAM's IdP in SIR/eduGAIN, scope uam.es, Sirtfi, R&S category. - url: https://api.crossref.org/members/6788 status: 200 note: 'Servicio de Publicaciones de la UAM, prefix 10.15366, 10,886 DOIs.' - url: https://ror.org/01cby8j38 status: 200 note: ROR identifier for Universidad Autónoma de Madrid. - url: https://hdl.handle.net/api/handles/10486/1 status: 200 note: Handle prefix 10486 resolves to repositorio.uam.es. - url: https://biblioguias.uam.es/ status: 200 note: Springshare LibGuides tenancy (CNAME region-eu.libguides.com). - url: https://biblioagenda.uam.es/ status: 200 note: Springshare LibCal tenancy (CNAME region-eu.libcal.com). - url: https://www.uam.es/uam/datos-abiertos status: 404 note: No open-data portal; datosabiertos.uam.es and transparencia.uam.es do not resolve. - url: https://api.datacite.org/clients?query=uam status: 200 note: Zero matching repositories — UAM is not a DataCite member. - url: https://portalcientifico.uam.es/es/ status: 0 note: >- Research portal linked from UAM's own library page; resolves to 45.151.245.19 outside UAM address space and never completes a TLS handshake (curl 28 at 45s). Not classified. - date: '2026-06-03' rating: 2 summary: >- UAM has no centralized developer portal, but it operates a genuine, live, machine-readable API surface through Biblos-e Archivo, its DSpace 7.6.5 institutional repository. Both the DSpace REST API root (reporting dspaceVersion "DSpace 7.6.5") and the OAI-PMH 2.0 endpoint (reporting repositoryName "Biblos-e Archivo. Repositorio Institucional de la UAM", protocolVersion 2.0) were verified live via content fetch. Direct curl probes returned HTTP 403 due to bot/WAF filtering, but the endpoints resolve and return valid payloads. Identity is handled by the gated ID-UAM federated service (not a documented public API). No official institutional GitHub organization was found (only research-group and student-club accounts). Nothing was fabricated; only confirmed surfaces are cataloged. endpoints: - url: https://repositorio.uam.es/server/api status: 200 note: DSpace 7.6.5 REST API root, HAL links confirmed via fetch (curl 403 via WAF). - url: https://repositorio.uam.es/server/oai/request?verb=Identify status: 200 note: OAI-PMH 2.0 Identify confirmed via fetch (curl 403 via WAF). - url: https://repositorio.uam.es/ status: 200 note: Biblos-e Archivo repository home, live (curl 403 via WAF). - url: https://www.uam.es/ status: 302 note: Official university website, redirects to localized landing. - url: https://id.uam.es/ status: 200 note: ID-UAM federated identity service; gated SSO, not a public API. - url: https://biblioguias.uam.es/repositorio status: 200 note: Library guide documenting Biblos-e Archivo repository.