name: University of Michigan-Ann Arbor description: University of Michigan-Ann Arbor public developer/API footprint review for APIs.json cataloging. url: https://raw.githubusercontent.com/api-evangelist/university-of-michigan-ann-arbor/refs/heads/main/review.yml created: '2026-06-03' modified: '2026-08-19' reviews: - date: '2026-06-03' rating: 3 summary: 'U-M has a substantial but mostly gated API program. The ITS API Directory runs on Apigee X and requires a U-M uniqname, Duo two-factor, and campus-network/VPN access, so its endpoints could not be probed anonymously. The strongest verifiable public surface is library infrastructure: the Deep Blue Documents DSpace OAI-PMH endpoint resolved live (HTTP 200) with a valid Identify response, and Deep Blue Data documents a public REST API. GitHub orgs @umich and @mlibrary were confirmed via the GitHub API. Several umich.edu pages return 403 to automated agents (Akamai bot protection) but are real, publicly documented pages. No endpoints were fabricated; ratings reflect that most enterprise APIs are member-only.' endpoints: - url: https://backend.production.deepblue-documents.lib.umich.edu/server/oai/request?verb=Identify status: 200 note: Live DSpace OAI-PMH endpoint, valid Identify XML returned (repositoryName Deep Blue). - url: https://www.lib.umich.edu status: 200 note: U-M Library public website, live. - url: https://github.com/umich status: 200 note: Official University of Michigan GitHub org, verified via GitHub API. - url: https://github.com/mlibrary status: 200 note: U-M Library GitHub org, 398 public repos via GitHub API. - url: https://deepblue.lib.umich.edu/data/rest-api status: 403 note: Deep Blue Data REST API docs; 403 to bots (Akamai) but publicly documented and search-confirmed. - url: https://its.umich.edu/data/data-database/api-directory status: 403 note: ITS API Directory portal (Apigee X, gated). 403 to bots; real page, gated to U-M members. - url: https://documentation.its.umich.edu/api-directory status: 403 note: ITS API Directory documentation; 403 to bots, real public docs site. - url: https://umich.edu status: 403 note: Official university website; 403 to automated agents, live in browser. - url: https://www.linkedin.com/school/university-of-michigan/ status: 999 note: LinkedIn school page; 999 is LinkedIn's standard anti-bot response, page exists. - date: '2026-08-19' rating: 4 summary: 'Re-profiled under the university pipeline, which settles operator attribution before saving anything. No vendor contract was ever attributed to U-M in this repo — the pre-existing three surfaces all audited as institution-owned — so this pass was additive rather than corrective. The Deep Blue Documents OAI-PMH endpoint was probed exhaustively: all six protocol verbs returned 200, ListMetadataFormats advertises twelve prefixes, ListSets reports 726 sets, and four error codes were reproduced deliberately. Every one of those responses is captured verbatim in examples/ and described in a probed OpenAPI. A second, previously uncatalogued institution-operated surface was found: U-M''s own Shibboleth SAML 2.0 identity provider, registered in InCommon and confirmed through InCommon''s own metadata query service. Two more were added — the Magic Bus BusTime transit API and Materials Commons (PRISMS Center). One vendor tenancy is now recorded rather than absorbed: Canvas at umich.instructure.com, whose contract stays with Instructure. A suspected Figshare tenancy was rejected on a negative control: a nonsense subdomain returns the identical AWS WAF 202, so the response proves nothing. Most of the umich.edu estate answers automated clients with a Cloudflare managed challenge; those pointers are live but unreadable by us, which is why Deep Blue Data has no OpenAPI here. Nothing was fabricated to fill a slot.' endpoints: - url: https://backend.production.deepblue-documents.lib.umich.edu/server/oai/request?verb=Identify status: 200 note: repositoryName "Deep Blue", adminEmail deepblue@umich.edu, earliestDatestamp 2005-08-29T23:07:21Z, deletedRecord transient. - url: https://backend.production.deepblue-documents.lib.umich.edu/server/oai/request?verb=ListMetadataFormats status: 200 note: Twelve metadata prefixes advertised, including dim and xoai (confirms DSpace) and etdms (theses). - url: https://backend.production.deepblue-documents.lib.umich.edu/server/oai/request?verb=ListSets status: 200 note: completeListSize 726; com_2027.42_* communities and col_2027.42_* collections. - url: https://backend.production.deepblue-documents.lib.umich.edu/server/oai/request?verb=GetRecord&identifier=oai:deepblue.lib.umich.edu:2027.42/61022&metadataPrefix=oai_dc status: 200 note: Single-record retrieval verified against a real identifier taken from ListRecords. - url: https://backend.production.deepblue-documents.lib.umich.edu/server/oai/request?verb=Nope status: 200 note: error code="badVerb". Note the 200 — protocol errors never reach the status line. - url: https://shibboleth.umich.edu/idp/shibboleth status: 200 note: SAML 2.0 IdP metadata, 10,923 bytes, shibmd:Scope for umich.edu and the Dearborn/Flint campuses. Saved verbatim in authentication/. - url: https://mdq.incommon.org/entities/https%3A%2F%2Fshibboleth.umich.edu%2Fidp%2Fshibboleth status: 200 note: InCommon MDQ returns the U-M entity with registrationAuthority https://incommon.org. Independent confirmation of federation membership. - url: https://api.datacite.org/providers/umich status: 200 note: U-M Library is a DataCite direct member (symbol UMICH, ROR 00jmfr291) with five registered repositories. - url: https://mbus.ltp.umich.edu/bustime/api/v3/getroutes status: 200 note: 'Live and key-gated: "No API access key supplied". Institution-hosted Clever Devices BusTime.' - url: https://umich.instructure.com/api/v1/accounts status: 401 note: Real U-M Canvas tenancy — Canvas error envelope. Recorded as x-operator tenant; contract not saved here. - url: https://zzznotarealtenant.instructure.com/api/v1/accounts status: 404 note: Negative control. Proves the U-M Canvas 401 is meaningful and not a wildcard. - url: https://zzznotarealtenant.figshare.com/ status: 202 note: 'Negative control that KILLED a suspected tenancy: umich.figshare.com returns the identical AWS WAF 202/0-byte response. Not evidence of a U-M Figshare account; no tenancy recorded.' - url: https://github.com/umich-iam status: 200 note: U-M ITS Identity and Access Management, 21 repos of public SAML/OIDC integration examples. Genuine institution-authored developer material. - url: https://atlas.ai.umich.edu/ status: 200 note: Atlas course-exploration tool, Center for Academic Innovation with the Registrar and ITS. No public API — /api/ returns 404. Recorded as a CourseCatalog pointer only. - url: https://materialscommons.org/ status: 200 note: PRISMS Center at U-M, DOE award DE-SC0008637. Python SDK docs only, no HTTP contract; nothing derived from the SDK. - url: https://deepblue.lib.umich.edu/data/rest-api status: 403 note: Cloudflare managed challenge. Documented public REST API we could not read — deliberately left without an OpenAPI rather than guessed. - url: https://its.umich.edu/data/data-database/api-directory status: 403 note: Cloudflare challenge on top of a genuinely gated service (uniqname + Duo + VPN). No endpoint in the directory is described. - url: https://api.umich.edu/ status: 0 note: Connection timed out. No public API gateway on the obvious hostname.