--- name: University of Sydney description: University of Sydney public developer/API footprint review for APIs.json cataloging. url: https://raw.githubusercontent.com/api-evangelist/university-of-sydney/refs/heads/main/review.yml created: '2026-06-03' modified: '2026-08-19' reviews: - date: '2026-08-19' rating: 2 summary: >- Re-profiled under the API Evangelist university pipeline with operator attribution settled before any artifact was saved. Findings: the only openly machine-readable artifact served under a University of Sydney hostname is Shibboleth SAML 2.0 identity-provider metadata at federation.sydney.edu.au (200, application/xml, registered in the Australian Access Federation and republished into eduGAIN) — and that is a TENANT surface, because the host CNAMEs to d007b274....idp-cname.aaf.edu.au and answers from CloudFront + an AWS ALB running Jetty 12.1.0 under an Amazon-issued certificate: AAF's hosted Rapid IdP. The entity, scope and SAML signing key are the university's; the software is not. It is also a DataCite repository client (ARDCX.USYD, Sydney eScholarship, 2,146 DOIs) and a Crossref member (12184, The University of Sydney Library, prefix 10.30722, 654 DOIs), which settles the institutional repository as institution-operated rather than a vendor's. Its documented OAI-PMH endpoint is behind Cloudflare bot management and returned 403 to every automated client tried, so OAI-PMH conformance is recorded as claimed and unverified rather than credited. api.sydney.edu.au resolves to a MuleSoft Anypoint production load balancer (usyd-lb-p.lb.anypointdns.net) but filters TCP 443 — a real API program that is not a public one. Library discovery, LMS and sign-in are tenants on Ex Libris, Instructure and Okta; those contracts are not the university's and none were saved here. sydney.figshare.com was checked and REJECTED — it is a Figshare wildcard host, not a University of Sydney repository; the Sydney-region Figshare customer is UTS. llms.txt and .well-known/security.txt on sydney.edu.au are soft-404s (200 redirecting to /errors/404.html) and are not credited. No OpenAPI, no developer portal, no credential self-service. This is a correct thin profile. endpoints: - url: https://federation.sydney.edu.au/idp/shibboleth status: 200 note: >- Shibboleth/SAML 2.0 IdP metadata, application/xml, 4506 bytes; scope sydney.edu.au; idp-signing.crt CN=federation.sydney.edu.au self-issued 2018. Served via CloudFront + AWS ALB + Jetty 12.1.0 with an Amazon-issued cert, behind a CNAME to idp-cname.aaf.edu.au — AAF Rapid IdP hosting, so operator is tenant. - url: https://md.aaf.edu.au/aaf-metadata.xml status: 200 note: AAF aggregate carries the Sydney IdP with OrganizationDisplayName "The University of Sydney". - url: https://mds.edugain.org/edugain-v2.xml status: 200 note: eduGAIN aggregate contains federation.sydney.edu.au. - url: https://api.datacite.org/clients/ardcx.usyd status: 200 note: DataCite repository client ARDCX.USYD, Sydney eScholarship, 2146 DOIs. - url: https://api.crossref.org/members/12184 status: 200 note: Crossref member The University of Sydney Library, prefix 10.30722, 654 DOIs. - url: https://ses.library.usyd.edu.au/oai/request?verb=Identify status: 403 note: Cloudflare bot management; blocked to default UA, browser UA and XML Accept alike. - url: https://ses.library.usyd.edu.au/robots.txt status: 200 note: Same host serves robots.txt — live and bot-blocked, not dead. - url: https://cusp.sydney.edu.au/ status: 200 note: CUSP course and unit-of-study portal; institution-operated, HTML only. - url: https://myuni.sydney.edu.au/ status: 200 note: myUni student portal on CloudFront; backing JSON endpoints are session-gated. - url: https://api.sydney.edu.au/ status: 0 note: MuleSoft Anypoint prod LB in DNS; TCP 443 filtered, HTTP and HTTPS both time out. - url: https://canvas.sydney.edu.au/ status: 200 note: CNAMEs to sydney-vanity.instructure.com; redirects into the Okta tenant. Tenant, not institution. - url: https://sydney.primo.exlibrisgroup.com/ status: 200 note: Ex Libris Primo VE tenant (61USYD_INST:sydney). Vendor contract, university data. - url: https://sydney.figshare.com/ status: 202 note: AWS WAF challenge on a Figshare wildcard host. REJECTED — not the university's repository. - url: https://www.sydney.edu.au/llms.txt status: 200 note: Soft-404 (redirects to /errors/404.html). Not credited. - url: https://www.sydney.edu.au/.well-known/security.txt status: 200 note: Soft-404 (redirects to /errors/404.html). Not credited. - url: https://www.sydney.edu.au/s/search.json?collection=Usyd&query=library status: 502 note: Funnelback JSON output not exposed. - url: https://data.sydney.edu.au/ status: 0 note: NXDOMAIN — no institutional open data portal. - url: https://developer.sydney.edu.au/ status: 0 note: NXDOMAIN — no developer portal. - url: https://cogniti.ai/ status: 200 note: >- Cogniti, an AI teaching-agent platform stating it is "built by a team from the University of Sydney and our development partners from other institutions". Domain is privacy-shielded and not registered to the university; recorded as AITooling, not as an institution API. - url: https://www.sydney.edu.au/students/academic-integrity/artificial-intelligence.html status: 200 note: Institutional AI-in-assessment guidance. Recorded as AIPolicy. - date: '2026-06-03' rating: 2 summary: >- No central public developer portal or openly documented API program was found for the University of Sydney. Verified live: the official website, the Primo discovery layer, the myUni student portal, and the ServiceNow service portal all returned HTTP 200. The library runs on Ex Libris Alma and Primo, whose APIs require an institution-issued key. The Sydney eScholarship Repository OAI-PMH endpoint is documented but returned HTTP 403 to automated requests (bot-blocked, not necessarily dead). The myUni student APIs are authenticated and gated. The Sydney Informatics Hub GitHub org is real (research/training code, not API products); the usyd GitHub org exists but is private. No endpoints were fabricated; all rows below were probed directly. endpoints: - url: https://www.sydney.edu.au/ status: 200 note: Official university website (live). - url: https://www.library.sydney.edu.au/ status: 200 note: University Library site (live). - url: https://sydney.primo.exlibrisgroup.com/ status: 200 note: Ex Libris Primo discovery layer (live); Alma/Primo APIs are key-gated. - url: https://ses.library.usyd.edu.au/oai/request?verb=Identify status: 403 note: Sydney eScholarship OAI-PMH endpoint; documented but bot-blocked to automated fetch. - url: https://myuni.sydney.edu.au/ status: 200 note: myUni student portal (live); backing APIs require authenticated session. - url: https://sydneyuni.service-now.com/sm status: 200 note: ServiceNow service/knowledge portal (live). - url: https://github.com/Sydney-Informatics-Hub status: 200 note: Sydney Informatics Hub GitHub org (research/training code, not API products). - url: https://github.com/usyd status: 200 note: usyd GitHub org exists but has no public members/repos. - url: https://au.linkedin.com/school/university-of-sydney/ status: 999 note: Official LinkedIn school page; 999 is LinkedIn bot-block, page is live in browser.