--- name: University of Twente description: University of Twente programmable-footprint review for APIs.json cataloging, run under the API Evangelist university pipeline with operator attribution settled per surface. url: https://raw.githubusercontent.com/api-evangelist/university-of-twente/refs/heads/main/review.yml created: '2026-06-03' modified: '2026-09-01' reviews: - date: '2026-09-01' rating: 6 summary: 'Re-profiled under the university pipeline, which settles WHO OPERATES each surface before saving any contract. The June 2026 review concluded the university''s footprint was limited to a documented-but-unreachable Pure OAI-PMH endpoint. That was wrong in both directions. The OAI-PMH claim does not survive re-probing — every base-URL variant errors and the library page cited for it no longer mentions OAI-PMH — and has been retired. But the university does operate a real API of its own that the earlier pass missed entirely: the University of Twente Energy API at energyapi.utwente.nl, publishing an OpenAPI 3.0.1 contract and a Swagger UI, requiring no authentication, and serving historical electricity, gas, heat, water and solar metering for 103 named campus resources with a CO2-equivalent mode. It was found from the university''s own open-data page and confirmed by the energydata.utwente.nl JavaScript bundle, which names the API host and its path template. Live calls returned real kWh and kg CO2e series. Two contract defects were measured: the spec declares RFC 7807 ProblemDetails on 400 but the service returns a bespoke envelope, and GET /api/Dashboard is documented as 200 but returned 400. Three further institution-or-federation surfaces were confirmed — a SAML 2.0 IdP on a Microsoft Entra tenant registered in SURFconext with Shibboleth scope utwente.nl, a Crossref membership held by the University Library under prefix 10.3990, and a machine-readable llms.txt at the web root (which is not valid JSON and whose bachelor and master arrays are elided). Five surfaces were recorded as tenant relationships and NOT credited as the university''s engineering: Elsevier Pure (research.utwente.nl and ris.utwente.nl both CNAME to utwente-pva.elsevierpure.com), Instructure Canvas (canvas.utwente.nl CNAMEs to utwente-vanity.instructure.com, LTI 1.3 JWKS public), CACI OSIRIS (utwente.osiris-student.nl), 4TU.ResearchData (named groups 28592 and 28634), and an SOP Mobility-Online Erasmus Without Paper node declaring 15 UT-scoped mobility APIs. No DataCite membership was claimed: the university has no DataCite client of its own and its data DOIs are minted under 4TU''s 10.4121 prefix. No endpoints were fabricated; no vendor contract was saved.' endpoints: - url: https://energyapi.utwente.nl/swagger/v1/swagger.json status: 200 note: University of Twente Energy API — OpenAPI 3.0.1, 3 paths, 9 schemas, 9,647 bytes. The institution's own contract. - url: https://energyapi.utwente.nl/ status: 200 note: Swagger UI served at the API host root. - url: https://energyapi.utwente.nl/api/Energy status: 200 note: Live unauthenticated call; returned 103 campus resources with their metered energy types. - url: https://energyapi.utwente.nl/api/Energy/universiteit-twente/electricity?resolution=month&from=2025-01-01%2000:00&to=2025-04-01%2000:00 status: 200 note: Live monthly kWh series for the campus aggregate. - url: https://energyapi.utwente.nl/api/Dashboard status: 400 note: 'DEFECT: documented as 200 with savings and solar data; returned 400 with an internal message naming the contractor mailbox.' - url: https://energydata.utwente.nl/ status: 200 note: Public Energy Data Platform SPA on UT network 130.89.3.171; its JS bundle names energyapi.utwente.nl. - url: https://www.utwente.nl/llms.txt status: 200 note: Machine-readable programme catalog, text/plain, 3,049 bytes. Not valid JSON — contains JavaScript comments; bachelor/master arrays elided. - url: https://www.utwente.nl/.well-known/security.txt status: 200 note: RFC 9116, contacts cert@utwente.nl and responsible-disclosure@utwente.nl, expires 2026-12-31. - url: https://metadata.surfconext.nl/idps-metadata.xml status: 200 note: SURFconext IdP aggregate carrying UT's EntityDescriptor with shibmd:Scope utwente.nl. - url: https://login.microsoftonline.com/723246a1-c3f5-43c5-acdc-43adb404ac4d/federationmetadata/2007-06/federationmetadata.xml status: 200 note: UT's own SAML 2.0 metadata, entityID https://sts.windows.net/723246a1-c3f5-43c5-acdc-43adb404ac4d/. - url: https://login.microsoftonline.com/723246a1-c3f5-43c5-acdc-43adb404ac4d/v2.0/.well-known/openid-configuration status: 200 note: OIDC discovery for the same tenant; tenant_region_scope EU. - url: https://api.crossref.org/members/2372 status: 200 note: University Library/University of Twente, prefix 10.3990, 599 member DOIs. Institution-operated identifier surface. - url: https://ror.org/006hf6230 status: 200 note: ROR record, domain utwente.nl, established 1961. - url: https://canvas.utwente.nl/api/lti/security/jwks status: 200 note: LTI 1.3 platform JWKS, 3 RS256 keys. Live conformance evidence on a UT hostname; the LMS itself is Instructure. - url: https://canvas.utwente.nl/api/v1/courses status: 401 note: Canvas REST API is token-gated; not a public surface. - url: https://mobility-online.utwente.nl/mobility/ewp/manifest?api=all status: 200 note: EWP discovery manifest, application/xml, 15 APIs, all endpoints scoped to HEI ID utwente.nl. Admin contact ewp@sop.co.at (SOP Mobility-Online) — tenant, not institution. - url: https://data.4tu.nl/v3/groups status: 200 note: 4TU group listing; UT holds group 28592 (utwente.nl) and 28634 (student.utwente.nl). Note the API group filter does not actually scope results. - url: https://data.4tu.nl/institutions/University_of_Twente status: 200 note: 4TU institution landing page. Repository hosted and governed by TU Delft. - url: https://utwente.osiris-student.nl/ status: 200 note: OSIRIS student system tenant (CACI), reached by redirect from osiris.utwente.nl. Login-gated; no public course API. - url: https://research.utwente.nl/ status: 200 note: 'Elsevier Pure portal. DNS: research.utwente.nl -> utwente-pva.elsevierpure.com. Tenant.' - url: https://research.utwente.nl/ws/oai?verb=Identify status: 500 note: 'CORRECTION: the OAI-PMH endpoint this repo carried since 2026-06-03 does not respond. Redirects to /error/ with a status-999 body.' - url: https://research.utwente.nl/ws/oai/?verb=Identify status: 404 note: Alternate OAI base path; not present. - url: https://research.utwente.nl/en/persons/ status: 403 note: Pure person pages bot-block non-browser clients. Live, not dead — no ORCID evidence could be read from them. - url: https://api.datacite.org/clients?query=twente status: 200 note: Returns total 0. The university is NOT a DataCite client; no membership claimed. - url: https://essay.utwente.nl/ status: 200 note: Student theses repository, self-hosted on UT IP 130.89.252.55, running Mendix. Single-page app with no public API found. - url: https://www.utwente.nl/en/ status: 200 note: Official institutional website (English), WebHare CMS on UT network. - url: https://github.com/utwente status: 200 note: Official GitHub organization, 8 public repos. - url: https://github.com/utwente-fmt status: 200 note: Formal Methods and Tools GitHub org, 68 public repos. - url: https://www.linkedin.com/school/university-of-twente/ status: 999 note: Official LinkedIn school page; 999 is LinkedIn anti-bot, page exists. - date: '2026-06-03' rating: 2 summary: The University of Twente has a limited publicly documented API footprint. The official website, the Pure research portal (research.utwente.nl), the official GitHub organization, and the 4TU.ResearchData institution page all resolve live (HTTP 200). UT Research Information (Pure) is documented as offering an OAI-PMH harvesting endpoint, but every OAI base-URL variant probed returned an error/500 or redirected to an error page, so no working public OAI-PMH endpoint was confirmed; it is cataloged on documented evidence only with no baseURL asserted. 4TU.ResearchData is co-founded by UT but hosted and governed by TU Delft, so it is referenced rather than claimed as a UT-operated API. No endpoints were fabricated. endpoints: - url: https://www.utwente.nl/en/ status: 200 note: Official institutional website (English). - url: https://research.utwente.nl/ status: 200 note: UT Research Information (Pure) public portal, live. - url: https://www.utwente.nl/en/service-portal/university-library/publication-archiving/ut-research-information-pure status: 200 note: Library documentation page describing Pure RIS and its OAI-PMH endpoint. - url: https://research.utwente.nl/ws/oai?verb=Identify status: 500 note: Pure OAI-PMH variant probed; redirected to error page, no valid OAI response. - url: https://research.utwente.nl/cgi/oai2?verb=Identify status: 500 note: Alternate OAI-PMH path probed; returned error, not openly accessible. - url: https://github.com/utwente status: 200 note: Official University of Twente GitHub organization (~8 repos). - url: https://github.com/utwente-fmt status: 200 note: UT Formal Methods and Tools GitHub org (source code). - url: https://data.4tu.nl/institutions/University_of_Twente status: 200 note: 4TU.ResearchData institution page; repository hosted/governed by TU Delft. - url: https://www.linkedin.com/school/university-of-twente/ status: 999 note: Official LinkedIn school page; 999 is LinkedIn anti-bot, page exists.