--- name: University of California, Berkeley description: University of California, Berkeley public developer/API footprint review for APIs.json cataloging. url: https://raw.githubusercontent.com/api-evangelist/ucb/refs/heads/main/review.yml created: '2026-06-03' modified: '2026-08-19' reviews: - date: '2026-08-19' rating: 4 pipeline: university summary: >- Re-profiled under the API Evangelist university pipeline, which settles the operator axis before saving anything. The June 2026 profile was directionally right about Berkeley's API program but attributed two vendor-run repository surfaces to the institution without qualification. Corrected: every apis[] entry now carries an x-operator. Five surfaces are institution-operated and three are tenant relationships. Three institution-operated machine-readable surfaces were newly found and verified by protocol response rather than link presence -- the CalNet Shibboleth/SAML 2.0 IdP metadata at shib.berkeley.edu (entityID urn:mace:incommon:berkeley.edu, also served signed by InCommon MDQ), the Library's GeoBlacklight JSON catalog at geodata.lib.berkeley.edu returning 5,156 anonymous records, and the MyBRC Savio cluster access-management API answering a well-formed JSON 401. The API Central catalog was re-read anonymously with a browser User-Agent and returns 200, not the 403 recorded in June: roughly 28 campus APIs are publicly listed with data classifications and named Data Owners, while every contract stays CalNet-gated. eScholarship was reclassified from a Berkeley surface to a California Digital Library tenant relationship (its OAI-PMH exposes a single "everything" set; there is no Berkeley-scoped set). Digital Collections OAI-PMH was newly found on Berkeley's own hostname but CNAMEs to TIND, so it is recorded as tenant. The library Alma/Primo entry was reclassified as an Ex Libris tenant after the Alma OAI provider rejected the Berkeley view code 01UCS_BER as an invalid institution code. Zero OpenAPI documents are held and none were generated. Berkeleytime was probed, is live, and was deliberately not credited: student-run, non-institution domain, no evidence of University operation. endpoints: - url: https://developers.api.berkeley.edu/apis status: 200 note: >- Public, uncredentialed catalog of ~28 campus APIs. Corrects the June 403 finding, which was a bot-challenge artifact, not a gate. - url: https://developers.api.berkeley.edu/terms_of_service status: 200 note: Real API program terms of service naming the EIS team and the access-plan model. - url: https://gateway.api.berkeley.edu/ status: 200 note: Institution-operated gateway on Berkeley's own CloudFront distribution. - url: https://shib.berkeley.edu/idp/shibboleth status: 200 note: >- SAML 2.0 IdP metadata, application/xml, cert subject O=UC Berkeley OU=IST-Calnet. Institution-operated. NEW FIND. - url: https://mdq.incommon.org/entities/urn%3Amace%3Aincommon%3Aberkeley.edu status: 200 note: Signed InCommon entity for Berkeley; confirms active federation membership. - url: https://geodata.lib.berkeley.edu/catalog.json?q=water status: 200 note: >- JSON:API-shaped Blacklight response, 5,156 records, no credentials. Host resolves inside Berkeley's own network. Institution-operated. NEW FIND. - url: https://mybrc.brc.berkeley.edu/api/ status: 401 note: >- {"detail":"Authentication credentials were not provided."} -- live gated research computing API on Berkeley address space. Institution-operated. NEW FIND. - url: https://digicoll.lib.berkeley.edu/oai2d?verb=Identify status: 200 note: >- OAI-PMH 2.0 confirmed by verb, admin digicoll@berkeley.edu, but CNAMEs to berkeley.lb.service.tind.io. TENANT. - url: https://escholarship.org/oai?verb=Identify status: 200 note: >- California Digital Library service for all of UC; single "everything" set, no Berkeley-scoped set. TENANT, reclassified from the June profile. - url: https://na01.alma.exlibrisgroup.com/view/oai/01UCS_BER/request?verb=Identify status: 200 note: >- Returns "Institution code 01UCS_BER is invalid" -- Berkeley is a Primo VE view inside a UC network zone, not the operator of an Alma instance. TENANT. - url: https://classes.berkeley.edu/ status: 200 note: Server-rendered Drupal class schedule; no backing public API found. - url: https://www.berkeley.edu/.well-known/security.txt status: 404 note: No machine-discoverable security contact. - url: https://www.berkeley.edu/llms.txt status: 404 note: No agent-facing manifest. - url: https://berkeleytime.com/ status: 403 note: >- Cloudflare challenge; live. Student-built course API on a non-institution domain under ASUC. NOT credited to the University. - date: '2026-06-03' rating: 4 summary: >- UC Berkeley operates a mature, formally governed campus API program via Integration Services: an API Central developer portal with interactive OpenAPI docs and a shared API Gateway centralizing auth and rate limiting. Verified the gateway and integration-services management pages resolve (HTTP 200); the developer portal and main www return 403 to automated crawlers but are confirmed real and CalNet-gated per official docs. Most campus APIs (e.g. SIS class schedule) are gated behind CalNet identity and Data Owner approval, so individual endpoints could not be fabricated. The UC-wide eScholarship OAI-PMH interface (HTTP 200) and the library's public Alma/Primo GitHub utilities provide confirmed public-read footprint. No endpoints were invented; gated items are noted honestly. endpoints: - url: https://developers.api.berkeley.edu/ status: 403 note: API Central developer portal; real per docs, 403 to crawler, CalNet-gated. - url: https://gateway.api.berkeley.edu/ status: 200 note: Shared API Gateway entry point, resolves live. - url: https://integration-services.berkeley.edu/api-management status: 200 note: API management program documentation, resolves live. - url: https://www.escholarship.org/oai status: 200 note: UC-wide eScholarship OAI-PMH interface, public read, resolves live. - url: https://github.com/BerkeleyLibrary status: 200 note: Library GitHub org with public Alma/Primo utilities. - url: https://github.com/ucberkeley status: 200 note: Official UC Berkeley GitHub organization, resolves live. - url: https://systemstatus.berkeley.edu/ status: 200 note: Campus IT system status page, resolves live. - url: https://api-central.berkeley.edu/ status: 0 note: Legacy/deprecated portal hostname; does not resolve (replaced by developers.api.berkeley.edu). - url: https://www.berkeley.edu/ status: 403 note: Official website; real, 403 to automated crawler.