generated: '2026-07-27' method: searched description: >- Results of probing the /.well-known/ discovery surface on every host in apis.yml and every OpenAPI servers[] host on 2026-07-27. AdvancedMD serves no host-root /.well-known/ documents; the real discovery surface is FHIR-scoped and lives under the R4 base path (/v1/r4/.well-known/*) plus the OAuth base path (/v1/oauth2/.well-known/jwks.json). fhir.advancedmd.com is a Google Apigee X integrated portal that answers HTTP 200 with an Angular SPA shell for every path, including every /.well-known/ path and /llms.txt, so those are recorded as present-but-not-a-real-document and were not saved. hosts: - host: https://providerapi.advancedmd.com note: FHIR API host. Discovery is path-scoped, not host-root. documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/smart-configuration status: 404 - path: /v1/r4/.well-known/smart-configuration status: 200 type: application/json standard: SMART App Launch discovery file: ../fhir/advancedmd-smart-configuration.json - path: /v1/r4/.well-known/openid-configuration status: 200 type: application/json standard: OpenID Connect Discovery 1.0 file: ../fhir/advancedmd-openid-configuration.json - path: /v1/r4/.well-known/oauth-authorization-server status: 404 note: Answers a FHIR OperationOutcome "Invalid resource" rather than RFC 8414 metadata. - path: /v1/oauth2/.well-known/jwks.json status: 200 type: application/json standard: RFC 7517 JSON Web Key Set file: advancedmd-jwks.json - path: /v1/oauth2/.well-known/oauth-authorization-server status: 404 - host: https://fhir.advancedmd.com note: >- Apigee X integrated developer portal (site id prj-prod-apigeex-advancedmdfhirportal). Returns HTTP 200 with a text/html SPA shell for every path probed, so a 200 here is not evidence a document exists. Nothing was saved from this host. documents: - path: /.well-known/security.txt status: 200 real_document: false note: HTML SPA shell. - path: /.well-known/openid-configuration status: 200 real_document: false - path: /.well-known/oauth-authorization-server status: 200 real_document: false - path: /.well-known/api-catalog status: 200 real_document: false - path: /.well-known/ai-plugin.json status: 200 real_document: false - path: /llms.txt status: 200 real_document: false - host: https://www.advancedmd.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /llms.txt status: 200 type: text/plain standard: llms.txt real_document: true file: ../llms/advancedmd-llms.txt - path: /llms-full.txt status: 404 - host: https://ptapi.advancedmd.com note: Application Access API host (Swagger 2.0 basePath /pt-api). Not probed anonymously beyond TLS; no discovery documents advertised. documents: [] - host: https://developer.advancedmd.com note: >- Gated Drupal/Apigee developer portal for the Connect APIs and ODBC driver. Returned HTTP 503 "Site under maintenance" for every path probed on 2026-07-27, unchanged from the initial review. documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 503 - path: /.well-known/oauth-authorization-server status: 503 - path: /.well-known/api-catalog status: 503 - path: /.well-known/ai-plugin.json status: 503 security_txt: published: false note: No RFC 9116 security.txt is served on any AdvancedMD host. agent_card: published: false probed: '2026-08-15' note: >- A2A Agent Card probe, re-run 2026-08-15 across every AdvancedMD host at both the canonical /.well-known/agent-card.json and the pre-0.3 legacy /.well-known/agent.json. No card exists. fhir.advancedmd.com answers HTTP 200 at both paths but the body is the same 2,138-byte Angular SPA shell it returns for every path — an HTML catch-all, not a document — so it is recorded as a miss, not a hit. Nothing was written to a2a/ and no AgentCard pointer is wired, because an agent card may only ever be harvested from a provider that actually serves one. results: - {host: fhir.advancedmd.com, path: /.well-known/agent-card.json, status: 200, real_document: false, body: html-spa-shell} - {host: fhir.advancedmd.com, path: /.well-known/agent.json, status: 200, real_document: false, body: html-spa-shell} - {host: www.advancedmd.com, path: /.well-known/agent-card.json, status: 404} - {host: www.advancedmd.com, path: /.well-known/agent.json, status: 404} - {host: providerapi.advancedmd.com, path: /.well-known/agent-card.json, status: 404} - {host: providerapi.advancedmd.com, path: /.well-known/agent.json, status: 404} - {host: ptapi.advancedmd.com, path: /.well-known/agent-card.json, status: 404} - {host: ptapi.advancedmd.com, path: /.well-known/agent.json, status: 404} - {host: developer.advancedmd.com, path: /.well-known/agent-card.json, status: 503} - {host: developer.advancedmd.com, path: /.well-known/agent.json, status: 503} x-recheck: date: '2026-08-15' findings: >- Contract discovery re-run against every API host root. providerapi.advancedmd.com 404s /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs and /redoc, but serves the live FHIR CapabilityStatement at /v1/r4/metadata (HTTP 200, 13,002 bytes) — byte-identical to the copy already harvested at fhir/advancedmd-fhir-r4-capabilitystatement.json (version 20220520), so nothing changed. ptapi.advancedmd.com returns HTTP 401 {"title":"Unauthorized","detail": "Invalid or missing API key."} for /pt-api/swagger.json and /pt-api/swagger/v1/swagger.json — the Swagger path exists but is API-key gated at the origin; the same document is already harvested from the portal into openapi/advancedmd-application-access-apis-swagger.json. developer.advancedmd.com still returns HTTP 503 on the site root, on every spec path and on a nonsense control path — unchanged since 2026-07-27, so the gated Connect API estate remains unreadable. probes: - {url: 'https://providerapi.advancedmd.com/v1/r4/metadata', status: 200} - {url: 'https://providerapi.advancedmd.com/openapi.json', status: 404} - {url: 'https://ptapi.advancedmd.com/pt-api/swagger.json', status: 401} - {url: 'https://developer.advancedmd.com/', status: 503} - {url: 'https://developer.advancedmd.com/zzz-control-path-check', status: 503}