generated: '2026-08-30'
method: probed
source: >-
Live probes of USC-operated and USC-tenanted public endpoints on 2026-08-30. No contract was
generated or inferred; every `conforms: true` below points at a URL that returned the cited
status and body at probe time.
docs: https://itservices.usc.edu/
note: >-
Conformance targets are the Kin Score `education` regime standards[]: scim, lti, oneroster,
ed-fi, caliper, qti, oai-pmh, shibboleth, saml, orcid, datacite, crossref. Reward-only — a
standard USC's vendors merely support is NOT recorded as USC conformance unless USC publishes
evidence of the deployment itself. USC operates no OpenAPI, no AsyncAPI and no developer
portal, so no specification-format conformance is claimed.
standards:
- id: shibboleth
conforms: true
evidence: >-
USC operates its own Shibboleth Identity Provider and publishes its metadata unauthenticated
at https://shibboleth.usc.edu/idp/shibboleth (200, application/xml, 17,096 bytes). The
document is titled "USC Metadata", Name="usc-idp-metadata", validUntil 2028-04-06, and
carries usc.edu plus a KeyDescriptor whose
X509 certificate subject is O=University of Southern California, OU=Information Technology
Services. Institution-operated: the host, the scope and the certificate are all USC's.
- id: saml
conforms: true
evidence: >-
The same document is a SAML 2.0 EntitiesDescriptor
(urn:oasis:names:tc:SAML:2.0:metadata) with an IDPSSODescriptor advertising
protocolSupportEnumeration "urn:oasis:names:tc:SAML:2.0:protocol
urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0" for entityID
https://shibboleth.usc.edu/shibboleth-idp. USC's federation registration is independently
resolvable from the InCommon metadata query service: GET
https://mdq.incommon.org/entities/%7Bsha1%7D returns 200
with 13,035 bytes of signed SAML 2.0 metadata for entityID urn:mace:incommon:usc.edu,
binding SSO to https://shibboleth.usc.edu/idp/profile/SAML2/{POST,POST-SimpleSign,Redirect}/SSO
and artifact resolution to https://shibboleth.usc.edu:8444/idp/profile/SAML{1,2}/SOAP/ArtifactResolution.
https://my.usc.edu/ redirects into that IdP, confirming it is the production login path.
- id: datacite
conforms: true
evidence: >-
USC is a DataCite direct_member in its own name, not through a vendor. GET
https://api.datacite.org/providers/usc returns 200 with name "University of Southern
California", memberType direct_member, organizationType academicInstitution, country US,
joined 2017-06-02, rorId https://ror.org/03taz7m60. GET
https://api.datacite.org/clients?provider-id=usc returns 200 with 11 repositories registered
under that account — usc.dl (USC Digital Library), usc.dataverse, usc.isi, usc.ini
(Stevens Neuroimaging and Informatics Institute), usc.cesr, usc.facebase, usc.gateway,
usc.kidney, usc.metrans, usc.pgahp, usc.test. GET
https://api.datacite.org/dois?provider-id=usc reports 1,513,793 DOIs minted under the USC
account, of which 1,511,764 are usc.dl. The DataCite REST API itself is DataCite's contract,
not USC's — what is USC's is the provider account, the eleven repositories and the DOIs.
- id: oai-pmh
conforms: false
evidence: >-
No working OAI-PMH provider was found on any USC-operated host. Probed 2026-08-30:
https://digitallibrary.usc.edu/oai?verb=Identify 404,
https://digitallibrary.usc.edu/oai-pmh?verb=Identify 404,
https://digitallibrary.usc.edu/oai/oai.aspx?verb=Identify 400 with the plain-text body
"Error had occured." (the Orange Logic OAI handler is routed but not serving),
https://repository.usc.edu/oai 404, https://libraries.usc.edu/oai 403 (bot challenge).
The Ex Libris Alma OAI path for the USC institution code is not public either:
https://na01.alma.exlibrisgroup.com/view/oai/01USC_INST/request?verb=Identify returns 200
carrying an OAI error body "Institution code 01USC_INST is invalid".
- id: crossref
conforms: false
evidence: >-
GET https://api.crossref.org/members?query=university+of+southern+california returns 200
with total-results 0. USC is not a Crossref member in its own name; its DOI registration
runs through DataCite (above).
- id: orcid
conforms: false
evidence: >-
14,594 ORCID records self-declare a University of Southern California affiliation
(https://pub.orcid.org/v3.0/expanded-search/?q=affiliation-org-name:"University of Southern
California", 200), but that is researcher-declared, not an institutional integration. No
USC-operated ORCID member API deployment, ORCID Trusted Party consent flow, or
ORCID-configured repository endpoint was found on any USC host.
- id: lti
conforms: false
evidence: >-
USC runs a Canvas tenant at https://usc.instructure.com/ (200, redirects to
/login/canvas). Canvas is an LTI 1.3 platform, but that is Instructure's conformance, not
USC's, and USC publishes no LTI platform registration, tool configuration, or JWKS on any
public USC host. Reward-only: not credited.
- id: caliper
conforms: false
evidence: >-
No Caliper Analytics event store, sensor endpoint or IMS Global/1EdTech certification claim
was found on any USC host or in the Canvas tenant's public surface.
- id: scim
conforms: false
evidence: >-
No SCIM 2.0 endpoint (/scim/v2, /ServiceProviderConfig, /ResourceTypes) is public on any USC
host. Identity provisioning at USC runs behind the Shibboleth IdP and the ITS service portal,
neither of which exposes a public SCIM surface.
- id: oneroster
conforms: false
evidence: >-
OneRoster is a K-12 rostering standard; no OneRoster endpoint or claim was found on any USC
host. Not applicable to USC's higher-education SIS.
- id: ed-fi
conforms: false
evidence: >-
Ed-Fi is a US K-12 state-education data standard; no Ed-Fi ODS/API deployment or claim was
found on any USC host. Not applicable.
- id: qti
conforms: false
evidence: >-
No QTI assessment item bank, QTI import/export endpoint or 1EdTech QTI certification claim
was found on any USC host. Assessment runs inside the Canvas tenant, whose QTI support is
Instructure's.