--- name: University of Sussex description: University of Sussex public developer/API footprint review for APIs.json cataloging. url: https://raw.githubusercontent.com/api-evangelist/university-of-sussex/refs/heads/main/review.yml created: '2026-06-03' modified: '2026-08-30' reviews: - date: '2026-06-03' rating: 2 summary: >- The University of Sussex has a thin public, documented API footprint. The institution's research outputs are hosted on Figshare, which is publicly browsable and backed by the standard public Figshare v2 REST API (host live, returns HTTP 400 on a deliberately malformed query, which confirms the API is responding). Identity is managed via Okta single sign-on (OAuth2/OIDC) but is gated to staff/students and not openly documented for third-party developers. The previously documented Sussex Research Online EPrints OAI-PMH endpoint is decommissioned: a request to its old base URL now returns HTTP 301 and redirects to a non-OAI HTML publications page pointing at Figshare. A GitHub organization exists but currently has zero public repositories. No course/timetable/SIS or open-data developer API was confirmed. All entries verified live; nothing fabricated. endpoints: - url: https://www.sussex.ac.uk/ status: 200 note: Official institution website resolves. - url: https://sussex.figshare.com/ status: 202 note: Figshare-hosted research repository portal (publicly browsable). - url: https://api.figshare.com/v2/articles status: 400 note: Public Figshare v2 REST API host is live; 400 returned on a deliberately malformed query parameter. - url: https://www.sussex.ac.uk/its/services/sso status: 200 note: Okta SSO (OAuth2/OIDC) service documentation; gated, not a public API. - url: https://sro.sussex.ac.uk/cgi/oai2?verb=Identify status: 301 note: Former EPrints OAI-PMH endpoint; now redirects to a non-OAI HTML publications page. Decommissioned. - url: https://github.com/universityofsussex status: 200 note: Official GitHub org exists but currently publishes zero public repositories. - url: https://www.linkedin.com/school/university-of-sussex/ status: 200 note: Official LinkedIn school page. - date: '2026-08-30' rating: 2 summary: >- Re-profiled under the API Evangelist university pipeline, which settles operator attribution before saving any contract. The June 2026 profile credited the University of Sussex with ten OpenAPI definitions and thirty-eight derived artifacts; every one of them was Figshare's generic v2 contract (info.title beginning "Figshare", info.contact support.figshare.com, empty servers block), the same document eleven other institutions in this catalog also shipped under their own names. All of it has been removed. What Sussex actually operates is one machine-readable contract: its own Shibboleth identity provider at idp.sussex.ac.uk, publishing signed SAML 2.0 metadata with entityID https://idp.sussex.ac.uk/shibboleth and shibmd:Scope sussex.ac.uk, on a host that CNAMEs to a Sussex-run Azure deployment rather than to a vendor. Four tenant relationships were recorded rather than deleted: Okta (okta.sussex.ac.uk, a full OIDC discovery document on a Sussex vanity domain CNAMEd to sussexac.customdomains.okta.com), Instructure Canvas (canvas.sussex.ac.uk, live 401 REST API and a live LTI 1.3 JWKS), Figshare (sussex.figshare.com, independently confirmed by the DataCite repository client FIGSHARE.SUSSEX), and Ex Libris Primo (institution view 44SUS_INST). Domain-standard conformance was probed, not asserted: shibboleth and saml confirmed as institution, lti and datacite confirmed as tenant, oai-pmh blocked by an AWS WAF challenge. No open-data portal, course/timetable API, or developer portal exists — data.sussex.ac.uk and api.sussex.ac.uk do not resolve and the GitHub org has zero public repositories. The score should fall as a result of this correction; that is the pipeline working. endpoints: - url: https://idp.sussex.ac.uk/idp/shibboleth status: 200 note: Institution-operated Shibboleth IdP; signed SAML 2.0 EntityDescriptor. The one institution-operated contract here. - url: https://okta.sussex.ac.uk/.well-known/openid-configuration status: 200 note: Sussex Okta tenant OIDC discovery document; issuer https://okta.sussex.ac.uk. Tenant, not institution. - url: https://canvas.sussex.ac.uk/api/v1/accounts status: 401 note: Canvas LMS REST API live on the Sussex hostname, unauthenticated. Instructure's contract; tenant. - url: https://canvas.sussex.ac.uk/api/lti/security/jwks status: 200 note: LTI 1.3 platform JWKS — the only confirmed Learning Tools Interoperability evidence for Sussex. - url: https://sussex.figshare.com/oai?verb=Identify status: 202 note: AWS WAF challenge (x-amzn-waf-action challenge, empty body). OAI-PMH neither confirmed nor refuted; blocked, not dead. - url: https://api.datacite.org/clients/figshare.sussex status: 200 note: DataCite repository client FIGSHARE.SUSSEX, domains sussex.figshare.com — third-party confirmation of the Figshare tenant. - url: https://sussex.primo.exlibrisgroup.com/discovery/search?vid=44SUS_INST:44SUS_VU1 status: 200 note: Ex Libris Primo VE institution view 44SUS_INST on the vendor's shared host. Tenant. - url: https://api.github.com/orgs/universityofsussex/repos status: 200 note: Returns an empty array. The GitHub organization exists and publishes nothing. - url: https://data.sussex.ac.uk/ status: 0 note: Does not resolve. No open-data portal. - url: https://api.sussex.ac.uk/ status: 0 note: Does not resolve. No central API host. - url: https://www.sussex.ac.uk/llms.txt status: 404 note: No llms.txt; the 404 is served as an HTML page.