--- name: University of Wisconsin-Madison description: University of Wisconsin-Madison public developer/API footprint review for APIs.json cataloging. url: https://raw.githubusercontent.com/api-evangelist/university-of-wisconsin-madison/refs/heads/main/review.yml created: '2026-06-03' modified: '2026-08-19' reviews: - date: '2026-08-19' rating: 4 summary: 'University pipeline re-profile with the operator axis applied. UW-Madison is the rare case in this cohort where the institution genuinely operates its own API program: I recovered eleven OpenAPI 3.0 contracts (245 operations, 113 component schemas) from the developer portal''s own catalog API at /portals/api/sites/{siteId}/liveportal/apis/{apiId}/download_spec, and every one declares servers under api.wisc.edu, mock.api.wisc.edu or doit.dev.api.wisc.edu with a wisc.edu contact — x-operator institution on all of them. No Figshare, Pure, Ex Libris, Dataverse or Symplectic contract is attributed here, so the misattribution this pipeline exists to prevent does not occur in this repo. Three surfaces were added that no prior pass had found: a fully public unauthenticated course-search API at public.enroll.wisc.edu, an institution-operated Shibboleth IdP at login.wisc.edu serving both SAML 2.0 metadata and OIDC discovery, and a live OAI-PMH 2.0 endpoint for MINDS@UW. One tenant relationship is recorded rather than credited: Canvas LMS at canvas.wisc.edu, gated behind UW''s own IdP — the data is UW''s, the contract is Instructure''s, and Instructure''s spec is deliberately not saved here. CORRECTION to the 2026-06-03 review: the DARS API entry has been REMOVED. That review recorded https://developer.wisc.edu/docs/dars/1/types/DarsBatchAuditRequest as HTTP 200, but developer.wisc.edu is an Angular SPA that returns a byte-identical 2,138-byte shell with status 200 for every URL including deliberately bogus ones; DARS appears in neither the portal sitemap nor its API catalog. The Curricular Data Model pointer was re-verified as real and retained, and the SourceCode/Authentication pointers were moved off the now-archived api-program repository to the live api-publisher-documentation repository.' endpoints: - url: https://developer.wisc.edu/portals/api/sites/doit-ipt-apigee-prod-ce29-productionorgportal/liveportal/apis status: 200 note: Portal API catalog — 11 published APIs, all anonymously readable specs. - url: https://developer.wisc.edu/sitemap.xml status: 200 note: Authoritative route list for the SPA; used to grade portal deep links. - url: https://developer.wisc.edu/docs/dars/1/types/DarsBatchAuditRequest status: 200 note: SOFT-404. Byte-identical 2,138-byte SPA shell to a bogus control URL. Entry removed. - url: https://developer.wisc.edu/docs/this-api-does-not-exist-zzz/1/overview status: 200 note: Bogus control URL — same 2,138-byte shell. Proves the portal cannot be graded by status code. - url: https://public.enroll.wisc.edu/api/search/v1/terms status: 200 note: Course search — open term codes, no auth. - url: https://public.enroll.wisc.edu/api/search/v1/aggregate status: 200 note: Course search facets — 190 subjects per term, 127,065 bytes. - url: https://public.enroll.wisc.edu/api/search/v1 status: 200 note: POST search, unauthenticated — returned 226 (term 1266) and 932 (term 1272) courses. - url: https://login.wisc.edu/idp/shibboleth status: 200 note: SAML 2.0 IdP metadata, entityID login.wisc.edu, shibmd:Scope wisc.edu. - url: https://login.wisc.edu/.well-known/openid-configuration status: 200 note: OIDC discovery document for campus SSO. - url: https://minds.wisc.edu/server/oai/request?verb=Identify status: 200 note: OAI-PMH 2.0, repositoryName 'MINDS@UW', adminEmail dspace-help@library.wisc.edu. - url: https://minds.wisc.edu/server/oai/request?verb=ListMetadataFormats status: 200 note: 13 metadata prefixes including oai_dc, mods, mets, marc, etdms, rioxx. - url: https://canvas.wisc.edu/ status: 200 note: 302 to login.wisc.edu SAML SSO — confirms tenant relationship + SAML in production. - url: https://canvas.wisc.edu/api/v1/accounts status: 401 note: Instructure Canvas API 401 JSON. Tenant surface; vendor's contract, not saved here. - url: https://git.doit.wisc.edu/interop/external-docs/api-program/-/raw/main/README.md status: 200 note: States the repository is ARCHIVED and redirects to api-publisher-documentation. - url: https://git.doit.wisc.edu/interop/external-docs/api-publisher-documentation status: 200 note: Live API Publisher documentation and UW-Madison API Standards. Replaces the archived pointer. - url: https://wams.doit.wisc.edu/chub/curricular-data-model-1.5/apidocs/index.html status: 200 note: Real generated Javadoc for the UW-Madison Curricular Data Model v1.5. Retained. - url: https://outages.doit.wisc.edu/ status: 200 note: Status page. Previous www. host in apis.yml failed TLS/connect; corrected to the bare host. - url: https://api.wisc.edu/ status: 404 note: Apigee gateway root — expected, not a defect. - url: https://www.wisc.edu/.well-known/security.txt status: 404 note: No RFC 9116 security.txt. - url: https://www.wisc.edu/llms.txt status: 404 note: No llms.txt. - date: '2026-06-03' rating: 4 summary: 'UW-Madison (QS World 2025 #46) operates a mature, formal API Program run by DoIT with a public developer portal at developer.wisc.edu, an Apigee API gateway, OAuth2 client-credentials auth, and published JSON:API/OpenAPI standards. I verified the portal and documented APIs (Person, HR, Curricular Data Model, DARS) return HTTP 200. Production APIs are access-gated requiring institutional approval, with openly published mock variants for development; no base URLs or live endpoints are fabricated here. All cataloged entries map to confirmed live documentation pages.' endpoints: - url: https://developer.wisc.edu/ status: 200 note: Developer portal home (JS-rendered). - url: https://developer.wisc.edu/apis status: 200 note: Portal API catalog listing. - url: https://developer.wisc.edu/docs/person-api/1/overview status: 200 note: Person API documentation. - url: https://developer.wisc.edu/person-api/getting-access status: 200 note: Person API access request (gated sign-up). - url: https://developer.wisc.edu/docs/api-team-mock-hr-api/1/routes/academicUnits/get status: 200 note: Mock HR API documentation. - url: https://wams.doit.wisc.edu/chub/curricular-data-model-1.5/apidocs/help-doc.html status: 200 note: Curricular Data Model API reference docs. - url: https://developer.wisc.edu/docs/dars/1/types/DarsBatchAuditRequest status: 200 note: DARS (Degree Audit) API documentation. - url: https://github.com/UW-Madison-DoIT status: 200 note: DoIT GitHub organization. - url: https://git.doit.wisc.edu/interop/external-docs/api-program status: 200 note: API Program standards and Apigee practices (GitLab). - url: https://www.outages.doit.wisc.edu/ status: 200 note: DoIT IT outages/status page. - url: https://www.linkedin.com/school/uw-madison/ status: 999 note: Official LinkedIn school page (999 = LinkedIn anti-bot, page exists).