Erasmus University Rotterdam
Erasmus University Rotterdam (EUR) is a Dutch public research university founded in 1913, ranked #158 in the QS World University Rankings 2025, with ROR https://ror.org/057w15z03 and the registrable domain eur.nl. Re-profiled on 2026-08-30 under the API Evangelist university pipeline, which settles WHO OPERATES a surface before crediting it to the institution. The June 2026 profile credited EUR with eleven API entries and ten OpenAPI contracts. Every one of them was api.figshare.com/v2 — one Figshare document that the same pass attributed to twenty-five different universities, split by tag into ten apparent surfaces titled "Figshare altmetric Articles API", "Figshare altmetric Authors API" and so on, and it put EUR fifth in the whole 248-institution university cohort. Those contracts, and the twenty Postman and OpenCollection files, four JSON Schemas, three JSON Structures, four payload examples, the JSON-LD context, the vocabulary, the OAuth scopes, the authentication summary, the agentic-access classification, the two Spectral rulesets and the capability map derived from them, have all been removed — 51 files. The attribution was wrong twice over: EUR's Figshare tenancy ENDED on 30 October 2025, when the EUR Data Repository moved to DataverseNL hosted by DANS, and datarepository.eur.nl now has no DNS record at all. What is left is what EUR actually operates. The genuine institution-run surface is the RePub OAI-PMH 2.0 endpoint at repub.eur.nl/oai — keyless, live, correctly configured with an OpenAIRE and an NWO set and three metadata formats, on the university library's own infrastructure with @ubib.eur.nl administrative contacts and no vendor CNAME in the chain. Beside it sits api.eur.nl, a Kong API gateway EUR runs on its own address space that answers 401 with WWW-Authenticate: Basic realm="kong" and publishes no route, no reference and no contract to the public internet. EUR holds its own DataCite membership (symbol DHCM, 3,722 DOIs minted) and publishes a live RFC 9116 security.txt. Everything else programmable is a tenancy that is a real institutional fact but somebody else's engineering: the EUR Research Repository on Elsevier Pure at pure.eur.nl, the EUR Data Repository on DataverseNL, the course catalogue on Caci's OSIRIS, the Canvas LMS with a live LTI 1.3 keyset, and the SURFconext/eduGAIN identity provider that is a Microsoft Entra tenant behind SURF's proxy. EUR publishes no OpenAPI of its own, no developer portal, no open data portal and no llms.txt.
Real signal across most facets with visible, nameable gaps — the contract exists but is thin, or the portal is good while governance and commercial terms are absent.
API Evangelist profiles Erasmus University Rotterdam the way a machine reads it — 14 machine-readable artifacts across 1 API, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Erasmus University Rotterdam scores 46.8/100 (developing), with a separate agent-readiness read of 27/100 (agent aware). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Why this profile is thin
Erasmus University Rotterdam publishes no API of its own — no OpenAPI, no developer portal, no API reference, no open data portal, no llms.txt. It operates exactly one public, callable, keyless API — the RePub OAI-PMH 2.0 harvesting endpoint — and it publishes no machine-readable contract for it. The OpenAPI in this repo is DERIVED by API Evangelist from live probes, not published by EUR. Everything else is either a vendor platform running under an eur.nl hostname or a gateway that exposes nothing to an unauthenticated caller. Nothing blocked us: sixty-plus hosts and paths were probed successfully and the thinness is the institution's, not a fetch failure. Verified institution-operated and live: https://repub.eur.nl/oai answers Identify (repositoryName "Erasmus University OAIPMH Feed", adminEmail opdecoul@ubib.eur.nl and vanhuisstede@ubib.eur.nl, earliestDatestamp 2023-11-24T00:00:00Z, deletedRecord transient), ListMetadataFormats (oai_dc, mods, nl_didl), ListSets (openaire, nwo) and ListIdentifiers, all 200, all keyless; repub.eur.nl is a CNAME to bib-app01.ubib.eur.nl -> 145.5.2.24 with no vendor in the chain. Institution-operated but closed: https://api.eur.nl/ returns 401 with WWW-Authenticate: Basic realm="kong" and {"message":"Unauthorized"}, and every probed path returns Kong's {"message":"no Route matched with those values"} — a real EUR-run API gateway (api.eur.nl -> api2.eur.nl -> 145.5.1.16) whose entire route table, documentation and contract are private; /openapi.json, /swagger.json, /docs, /v1, /api, /health and /status were all probed. Institution-operated non-API surfaces: a live RFC 9116 https://www.eur.nl/.well-known/security.txt (Contact mailto:cert@eur.nl, Expires 2026-12-07, policy and hall-of-fame URLs, both 200) and a status page at status.eur.nl (200, "Status: Erasmus University Rotterdam", on Netlify, with no JSON feed — /api/v2/status.json and /index.json both 404). Verified live but tenant-operated: pure.eur.nl (CNAME erasmus.elsevierpure.com -> eu.prod.elsevierpure.com, OAI-PMH 200 with the OpenAIRE CERIF 1.2 profile, adminEmail purehosted@elsevier.com, /ws/api/524/openapi.json 401), canvas.eur.nl (CNAME EUR-vanity.instructure.com, LTI 1.3 JWKS 200 and .well-known/openid-configuration 200, /api/v1/courses 401), eur.osiris-student.nl (Caci OSIRIS; the SPA shell 200s but POST /student/osiris/student/cursussen/zoeken returns a structured OSIRIS Link JSON error with an exchange-id, proving a live service behind it), and dataverse.nl/dataverse/eur (200; the dataverse.nl API is behind an Anubis proof-of-work bot challenge, so /api/info/version and /api/dataverses/eur return the challenge page rather than JSON — the host is live, we are the ones excluded). Confirmed dead or absent: datarepository.eur.nl returns NXDOMAIN — the Figshare-era repository hostname the June profile's vocabulary and rulesets still cited; no DNS for developer.eur.nl, developers.eur.nl, opendata.eur.nl, data.open.eur.nl, edr.eur.nl, dataverse.eur.nl, idp.eur.nl, adfs.eur.nl, hpc.eur.nl, mcp.eur.nl, library.eur.nl, primo.eur.nl, catalogue.eur.nl, vle.eur.nl or lms.eur.nl; data.eur.nl resolves but serves only a Taggrs server-side tracking endpoint, not open data; www.eur.nl/llms.txt, /.well-known/api-catalog, /.well-known/ai-plugin.json and /openapi.json all return the site's soft 404 ("Pagina niet gevonden", 146,268 bytes of HTML under an HTTP 404 status).
An API exists — we simply could not reach the contract without credentials or a sales conversation. This one is Erasmus University Rotterdam's to change: publishing the reference and a machine-readable spec at a public URL, while keeping key issuance behind whatever gate they like, would let an integrator evaluate the API before committing to a call.
What we probed
https://repub.eur.nl/oai?verb=Identify→ HTTP 200https://repub.eur.nl/oai?verb=ListMetadataFormats→ HTTP 200https://repub.eur.nl/oai?verb=ListSets→ HTTP 200https://repub.eur.nl/oai?verb=ListIdentifiers&metadataPrefix=oai_dc→ HTTP 200https://repub.eur.nl/oai?verb=BadVerb→ HTTP 200https://repub.eur.nl/→ HTTP 200https://repub.eur.nl/openapi.json→ HTTP 404https://api.eur.nl/→ HTTP 401https://api.eur.nl/openapi.json→ HTTP 404https://api.eur.nl/swagger.json→ HTTP 404https://api.eur.nl/docs→ HTTP 401https://api.eur.nl/v1→ HTTP 404https://pure.eur.nl/ws/oai?verb=Identify→ HTTP 200https://pure.eur.nl/ws/oai?verb=ListMetadataFormats→ HTTP 200https://pure.eur.nl/ws/oai?verb=ListSets→ HTTP 200https://pure.eur.nl/ws/api→ HTTP 200https://pure.eur.nl/ws/api/524/openapi.json→ HTTP 401https://canvas.eur.nl/api/lti/security/jwks→ HTTP 200https://canvas.eur.nl/.well-known/openid-configuration→ HTTP 200https://canvas.eur.nl/api/v1/courses→ HTTP 401https://canvas.eur.nl/login/oauth2/auth→ HTTP 401https://eur.osiris-student.nl/student/osiris/student/cursussen/zoeken→ HTTP 500https://courses.eur.nl/→ HTTP 200https://dataverse.nl/dataverse/eur→ HTTP 200https://dataverse.nl/api/info/version→ HTTP 200https://metadata.surfconext.nl/idps-metadata.xml→ HTTP 200https://api.datacite.org/providers/dhcm→ HTTP 200https://api.datacite.org/repositories?provider-id=dhcm→ HTTP 200https://api.datacite.org/dois?provider-id=dhcm→ HTTP 200https://api.crossref.org/members?query=erasmus+university+rotterdam→ HTTP 200https://api.ror.org/v2/organizations/057w15z03→ HTTP 200https://www.eur.nl/.well-known/security.txt→ HTTP 200https://status.eur.nl/→ HTTP 200https://status.eur.nl/api/v2/status.json→ HTTP 404https://www.eur.nl/llms.txt→ HTTP 404https://www.eur.nl/.well-known/api-catalog→ HTTP 404https://www.eur.nl/openapi.json→ HTTP 404https://github.com/eur-nl→ HTTP 200https://datarepository.eur.nl/→ HTTP 0https://eur.figshare.com/→ HTTP 202
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance. Every facet and dimension name is a link: it opens that measurement's page on APIs.io, where the rating runs across the whole catalog — the exact checks that feed it, how every profiled provider distributes on it, and who is at the top of it.
Put this on your own site. The badge is drawn live from Erasmus University Rotterdam's current Kin Score — paste it once and it updates itself every time the score is recomputed. It follows your visitor's light or dark setting, and it links back here so anyone who sees it can read the full breakdown.
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/erasmus-university-rotterdam/"
title="Erasmus University Rotterdam on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/erasmus-university-rotterdam.svg"
alt="Erasmus University Rotterdam Kin Score — API readiness rating by API Evangelist" width="150" height="150" loading="lazy">
</a>
[](https://providers.apievangelist.com/providers/erasmus-university-rotterdam/)
<!-- Kin Score · API Evangelist -->
<a href="https://providers.apievangelist.com/providers/erasmus-university-rotterdam/"
title="Erasmus University Rotterdam on API Evangelist — API profile and Kin Score">
<img src="https://apis.io/badge/erasmus-university-rotterdam/card.svg"
alt="Erasmus University Rotterdam Kin Score — API readiness rating by API Evangelist" width="340" height="120" loading="lazy">
</a>
More shapes, themes and sizes → · Score as JSON · How badges work
How we profile Erasmus University Rotterdam
Each block below is one kind of artifact we hold for Erasmus University Rotterdam. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
APIs 7
Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.
Individual APIs this provider publishes, each with its own machine-readable definition.
RePub OAI-PMH Metadata Harvesting Interface
OAI-PMH 2.0 harvesting interface for RePub, the Erasmus University Rotterdam institutional publication repository. Keyless and live: Identify, ListMetadataFormats, ListSets and ...
EUR API Gateway (api.eur.nl)
An EUR-operated Kong API gateway. It is unambiguously live and unambiguously closed: the root returns 401 application/json {"message":"Unauthorized"} with WWW-Authenticate: Basi...
EUR Research Repository — Pure OAI-PMH (Elsevier tenancy)
The EUR & Erasmus MC research information portal runs on Elsevier Pure (CRIS). Its OAI-PMH endpoint is live (Identify 200, repositoryName "EUR Research Repository", earliestDate...
EUR Data Repository (DataverseNL tenancy)
EUR's institutional research DATA repository, distinct from the RePub publication repository. This entry replaces the ten Figshare contracts the June 2026 profile saved here. Tw...
Canvas LMS (Instructure tenancy) — REST + LTI 1.3
EUR's learning management system. Live and credentialed: /api/v1/courses returns 401 {"status":"unauthenticated","errors":[{"message":"user authorisation required"}]}. Two machi...
OSIRIS Course Catalogue (Caci tenancy)
EUR's course catalogue and student self-service, on Caci's OSIRIS. The public entry points courses.eur.nl and osiris.eur.nl both land on an Angular SPA shell that returns HTTP 2...
SURFconext / eduGAIN Identity Provider
EUR's identity federation entry — the machine-readable institutional surface universities almost never get catalogued for. EUR is registered as an identity provider in SURFconex...
Scroll within the panel for all 7 ·
Open Collections 1
Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
API Collection
OPEN COLLECTIONPricing Plans 1
Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the things the Kin Score reads for access clarity — renamed from commercial clarity in rubric 0.12, because a free statutory interface has access terms and no commercial ones.
Published pricing tiers and plan structures.
Rate Limits 1
Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.
Documented rate limits and quota policies.
Erasmus University Rotterdam Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.
Cost, billing, and metering signals for API financial operations.
Security Posture 3
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Resources
Every other property we hold for Erasmus University Rotterdam — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Get Started 1
Portal, sign-up, and the first successful call
Documentation 1
Reference material describing how the API behaves
Design & Contract 2
Pagination, idempotency, versioning, errors, and events
Build 4
SDKs, sample code, and the tooling you integrate with
Access & Security 4
Authentication, authorization, and security posture
Learn 1
Tutorials, courses, talks, and written guidance
Operate 2
Status, limits, changes, and where to get help
Commercial 4
Pricing, plans, and the legal terms of use
Company 2
The organization behind the API
Other 6
Properties that don't map to a standard resource type
← All providers · Data indexed from github.com/api-evangelist/erasmus-university-rotterdam · machine-readable index on apis.io
This is an independent, third-party profile of Erasmus University Rotterdam, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.
The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.
Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.
info@apievangelist.com
·
Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and
you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.