name: University of Melbourne description: University of Melbourne public developer/API footprint review for APIs.json cataloging. url: https://raw.githubusercontent.com/api-evangelist/university-of-melbourne/refs/heads/main/review.yml created: '2026-06-03' modified: '2026-08-19' reviews: - date: '2026-08-19' rating: 3 summary: 'Re-profiled under the API Evangelist university pipeline, which settles operator attribution before saving any contract. Four institution-operated surfaces verified live: the Spatial Urban Data Observatory GeoNode API (https://sudo.eresearch.unimelb.edu.au/api/v2, 200, 7,417 datasets, unauthenticated), the Minerva Access DSpace 7.6 REST API (200 application/hal+json, 223 communities), the Minerva Access OAI-PMH 2.0 endpoint (200 text/xml, 14 metadata formats including two the Library built itself, `umbl` and a `trove` crosswalk for the National Library of Australia), and the University''s own Shibboleth SAML 2.0 identity provider (https://idp.unimelb.edu.au/idp/shibboleth, 200 application/xml, registered in the Australian Access Federation). Four tenancies recorded as relationships with NO vendor contract saved: Melbourne Data on Figshare (confirmed via DataCite client UNIMELB.REPO1), the open spatial portal on Esri ArcGIS Hub, web SSO on Okta, and the internal API programme on Boomi. Two defects recorded rather than smoothed over: sudo.eresearch.unimelb.edu.au presents a TLS certificate for staging.unimelb-sudo.cloud.edu.au and matches no other name, and /api/v2/categories timed out at 60s while sibling collections answered. findanexpert.unimelb.edu.au/api returns HTTP 200 with a Vue SPA shell and is explicitly recorded as a soft-404, not an API. The University publishes no OpenAPI, no developer portal, no changelog, no status page and no rate-limit signal for anything it operates; api., developer. and data.unimelb.edu.au do not resolve. The whole *.unimelb.edu.au marketing and student web estate returned HTTP 403 from Cloudflare bot management to every client tried and is recorded live-but-unreadable, never dead. Nothing was fabricated; the three OpenAPIs in openapi/ are ours and are marked method: derived.' - date: '2026-06-03' rating: 2 summary: 'Verified live: the Minerva Access institutional repository (DSpace 7.6) exposes a working public OAI-PMH 2.0 interface and a self-describing DSpace REST/HAL API, and the ArcGIS Hub open spatial-data portal is reachable with standard ArcGIS query/download APIs. The university also runs an internal Boomi API management developer portal for staff/students, but it is gated and not publicly documented, so no endpoints were confirmed. Central SSO (Okta, OAuth2/OIDC) exists but offers no public API program. An official GitHub org (github.com/unimelb) exists with mostly archived repos. No fabricated endpoints — only URLs probed live are recorded below. The institution''s homepage returns 403 to automated clients (bot protection) though it serves normally in a browser.' endpoints: - url: https://minerva-access.unimelb.edu.au/server/oai/request?verb=Identify status: 200 note: Live OAI-PMH; repositoryName "The University of Melbourne Library Digital Repository". - url: https://minerva-access.unimelb.edu.au/server/api status: 200 note: DSpace 7.6 REST API root, HAL+JSON self-describing links. - url: https://minerva-access.unimelb.edu.au/ status: 200 note: Minerva Access repository UI / human landing page. - url: https://spatialdata-uom.opendata.arcgis.com/ status: 200 note: Open spatial-data portal (ArcGIS Hub) for campus GIS layers. - url: https://github.com/unimelb status: 200 note: Official GitHub org, 18 repos, mostly archived. - url: https://www.unimelb.edu.au/ status: 403 note: Official website; 403 to automated client (bot protection), serves in browser. - url: https://boomi.com/blog/university-of-melbourne-innovates-with-api-driven-strategy/ status: 200 note: Vendor case study describing the gated internal Boomi API portal.