---
name: University of Otago
description: University of Otago public developer/API footprint review for APIs.json cataloging.
url: https://raw.githubusercontent.com/api-evangelist/university-of-otago/refs/heads/main/review.yml
created: '2026-06-03'
modified: '2026-08-30'
reviews:
- date: '2026-08-30'
rating: 2
summary: >-
Re-reviewed under the university pipeline's operator axis. University of Otago has no
developer portal, no API reference and no open-data portal. Exactly ONE machine-readable
surface is both on Otago's domain and operated by Otago: the self-hosted WordPress REST API
behind artificialintelligence.otago.ac.nz, which returns a 144-route discovery document and
published content with no credential. The June 2026 review recorded OUR Archive as an Otago
surface on the strength of its hostname; DNS shows ourarchive.otago.ac.nz CNAMEs to
ap02.esploro.exlibrisgroup.com, so it is an Ex Libris Esploro TENANCY and is relabelled
accordingly, and its OAI-PMH endpoint now returns 403 (previously 200) while still carrying
OAI error_code 21. Three surfaces were added that the June review missed: a Blackboard Learn
tenancy, the Tuakiri SAML identity (where Otago owns the entityID and REANNZ operates the
IdP), and Otago's DataCite and Crossref registrations. Two soft-200s were caught and are
recorded as non-finds. Nothing was fabricated; every row below was probed directly.
endpoints:
- url: https://artificialintelligence.otago.ac.nz/wp-json/
status: 200
note: >-
THE ONE INSTITUTION-OPERATED SURFACE. Live WordPress REST API on Otago's own domain,
200,783 bytes, 144 routes across 6 namespaces, "authentication":[] — keyless read.
- url: https://artificialintelligence.otago.ac.nz/wp-json/wp/v2/pages
status: 200
note: Returns page objects anonymously, confirming the API serves data and not just an index.
- url: https://artificialintelligence.otago.ac.nz/
status: 200
note: Otago's AI guidance site; also the AIPolicy pointer. Live to scripted requests.
- url: https://blackboard.otago.ac.nz/learn/api/public/v1/system/version
status: 200
note: >-
Blackboard Learn tenancy (CNAME otago.blackboard.com). Keyless version endpoint returns
release 4000.21.0, build rel.28+435d029. New find; missed by the June review.
- url: https://blackboard.otago.ac.nz/learn/api/public/v1/courses
status: 401
note: >-
{"status":401,"message":"API request is not authenticated."} — a 401 not a 404, which is
the evidence the REST API exists and is gated. Same on /dataSources and /v3/courses.
- url: https://blackboard.otago.ac.nz/.well-known/openid-configuration
status: 200
note: >-
SOFT-200. Body is Blackboard's login.jsp HTML page, not an OIDC discovery document.
NO LTI conformance is claimed from it.
- url: https://directory.tuakiri.ac.nz/metadata/tuakiri-metadata-signed.xml
status: 200
note: >-
Signed Tuakiri NZ Access Federation aggregate, 725,866 bytes, 82 entities. Contains a
full SAML 2.0 IDPSSODescriptor for entityID https://idp.otago.ac.nz/idp/shibboleth,
DisplayName "The University of Otago".
- url: https://hosted-login.tuakiri.ac.nz/hosting/otago.ac.nz/idp/profile/SAML2/Redirect/SSO
status: 500
note: >-
All six of Otago's advertised SSO/SLO bindings resolve here — REANNZ's Tuakiri Hosted
Login. 500 is the expected reply to a GET carrying no AuthnRequest, not a fault.
- url: https://api.datacite.org/providers/otagouni
status: 200
note: >-
DataCite provider "University of Otago", consortium_organization, rorId
https://ror.org/01jmxt844. Repository otagouni.snbodh (OUR Archive) holds 334 DOIs.
- url: https://api.crossref.org/members/4843
status: 200
note: >-
Crossref member "University of Otago Library", DOI prefix 10.11157, 2,537 DOIs
(412 current, 2,125 backfile).
- url: https://ourarchive.otago.ac.nz/
status: 200
note: >-
OUR Archive. CNAME -> ap02.esploro.exlibrisgroup.com — an Ex Libris Esploro TENANCY,
not Otago-operated infrastructure. This is the correction made in this review.
- url: https://ourarchive.otago.ac.nz/view/oai/64OTAGO_INST/request?verb=Identify
status: 403
note: >-
OAI-PMH deployed but unauthorised: returns OAI error_code 21 on Identify,
ListMetadataFormats, ListSets and ListRecords. Was 200 at the June review; now 403.
- url: https://ourarchive.otago.ac.nz/view/google/siteindex.xml
status: 200
note: Live sitemap index, lastmod 2026-08-30. The repository's open machine-readable surface.
- url: https://ourarchive.otago.ac.nz/esploro/openapi
status: 200
note: >-
SOFT-200. Returns the Esploro Angular SPA shell (
Research Portal), served
for any unmatched path under /esploro/. Not an OpenAPI. No OpenAPI exists for Otago.
- url: https://ourarchive.otago.ac.nz/oai?verb=Identify
status: 404
note: Legacy DSpace OAI path, dead since the migration to Esploro.
- url: https://api.otago.ac.nz/
status: 503
note: >-
Otago-owned hostname behind Cloudflare; origin is an OpenShift router returning the
default "Application is not available" page on all 8 paths probed (/, /openapi.json,
/swagger, /docs, /api, /v1, /health, /.well-known/openapi). No application. Not catalogued.
- url: https://otago.figshare.com/
status: 202
note: >-
Empty body. Figshare answers 202 for both live tenancies and its wildcard, so this cannot
confirm a tenancy. NOT asserted, and no Figshare contract is stored in this repo.
- url: https://otago.instructure.com/
status: 404
note: Resolves to cluster1.instructure.com but 404s. Otago's LMS is Blackboard, not Canvas.
- url: https://www.otago.ac.nz/
status: 403
note: >-
Cloudflare 403 to all scripted requests across the whole origin, including /robots.txt,
/sitemap.xml and /llms.txt. Live in a browser — bot-blocked, not dead. This prevented the
sitemap crawl used to measure absence on other institutions in this cohort.
- url: https://ask.otago.ac.nz/knowledgebase/article/KA-10005970/en-us
status: 200
note: AskOtago "Responsible use of Generative AI" article. AIPolicy pointer.
- url: https://ask.otago.ac.nz/knowledgebase/article/KA-10002700/en-us
status: 200
note: AskOtago article documenting Tuakiri federated identity. Authentication pointer.
- url: https://otago.libguides.com/Generative_AI/policies
status: 200
note: Otago Library Generative AI policy guide (Springshare LibGuides tenancy). AIPolicy pointer.
- url: https://docs.tuakiri.ac.nz/
status: 200
note: Tuakiri federation technical documentation.
- url: https://library.otago.ac.nz/
status: 0
note: Resolves to 139.80.135.136 but does not complete a connection publicly. Not catalogued.
- url: https://hpc.otago.ac.nz/
status: 0
note: >-
Resolves via peweb.otago.ac.nz to 139.80.8.113 but does not answer on 443 publicly. A real
internal research-computing service, not a public surface. Not catalogued.
- url: https://login.otago.ac.nz/
status: 0
note: Resolves to 139.80.64.89 (its-cs-im.registry.otago.ac.nz); no public connection. Not catalogued.
- url: https://github.com/UniversityofOtago
status: 200
note: >-
Org exists (id 28741595) with ZERO public repositories and is not verifiably official.
Still not catalogued, same conclusion as the June review.
- url: https://www.linkedin.com/school/university-of-otago/
status: 999
note: Official LinkedIn school page; 999 is LinkedIn's standard anti-bot response.
- date: '2026-06-03'
rating: 2
summary: >-
SUPERSEDED by the 2026-08-30 review, which corrected the operator attribution of OUR Archive
from institution to tenant and added three surfaces this review missed. Retained for history.
University of Otago has no dedicated public developer portal and no documented public API
program. The most concrete machine interface verified live is the OUR Archive Esploro
OAI-PMH endpoint, which resolves and returns valid OAI XML but currently responds with
error_code 21 (unauthorized / public harvesting not enabled). Identity is handled via the
Tuakiri NZ Access Federation (SAML 2.0 / Shibboleth), which is federation infrastructure
rather than a self-service API. The main website returns 403 to automated bots but is a
valid live site. A GitHub org named "UniversityofOtago" exists but has zero public repos and
is not verifiably official, so it is not catalogued. No endpoints were fabricated;
everything was probed directly.
endpoints:
- url: https://www.otago.ac.nz/
status: 403
note: Official website; live in browsers but returns 403 to scripted requests (bot filtering).
- url: https://ourarchive.otago.ac.nz/
status: 200
note: OUR Archive research repository home (Ex Libris / Clarivate Esploro).
- url: https://ourarchive.otago.ac.nz/view/oai/64OTAGO_INST/request?verb=Identify
status: 200
note: >-
Esploro OAI-PMH endpoint resolves but returns OAI error_code 21. NOTE — re-probed
2026-08-30 and now returns 403, not 200.
- url: https://ourarchive.otago.ac.nz/esploro/?institution=64OTAGO_INST
status: 200
note: OUR Archive Esploro research portal (human UI).
- url: https://ask.otago.ac.nz/
status: 200
note: AskOtago service portal; documents Tuakiri federated identity for staff/students.
- url: https://www.linkedin.com/school/university-of-otago/
status: 999
note: Official LinkedIn school page; 999 is LinkedIn's standard anti-bot response.
- url: https://github.com/UniversityofOtago
status: 200
note: GitHub org with this name exists but has no public repos; not catalogued.
- url: https://ourarchive.otago.ac.nz/oai?verb=Identify
status: 404
note: Legacy DSpace OAI path no longer valid after migration to Esploro.