generated: '2026-09-19' method: probed source: >- Live unauthenticated GET of every named /.well-known/ path on both hosts the record knows (the apex agmsg.world, which is the Website, and api.agmsg.world, which is the only API host, the OpenAPI host and the agent-card host) on 2026-09-19, with one negative-control request per host. There is no docs host, no MCP host and no OAuth authorization server to probe: the provider's own developer-ai.txt states "AgMsg operates a single public web property: the API". note: >- api.agmsg.world serves an A2A agent card at BOTH the canonical /.well-known/agent-card.json and the legacy /.well-known/agent.json (identical bytes, sha256 8730485444802f75...); it is graded in a2a/agmsg-world-a2a.yml (flavored: no protocolVersion). Nothing else under /.well-known/ is served on either host - no security.txt, no OIDC/OAuth discovery, no api-catalog, no apis.json, no ai-plugin.json, no AAuth, no UCP/ACP. Both hosts answer a real 404 at an impossible path, so the hits are not catch-all echoes. The provider DOES publish a large discovery surface, but at the API ROOT rather than under /.well-known/ - llms.txt plus the ai-visibility.org.uk ADF family (ai.txt, ai.json, identity.json, brand.txt, faq-ai.txt, developer-ai.txt) and a skill.json - and those are recorded under root_discovery below and saved verbatim in llms/ so they are not mistaken for well-known documents. hosts: - host: agmsg.world documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/apis.json status: 404 - path: /.well-known/ucp.json status: 404 - path: /.well-known/acp.json status: 404 - path: /.well-known/aauth-resource.json status: 404 - path: /apis.json status: 404 - path: /apis.yml status: 404 - path: /llms.txt status: 404 - path: /robots.txt status: 404 path_echo_control: passed soft_404_control: path: /.well-known/agmsg-world-negative-control-9f2c1ab7.json status: 404 bytes: 555 note: >- The apex is a Vite single-page app (one
and a JS bundle) whose canonical and Open Graph tags still read https://YOUR_DOMAIN/ - a template placeholder the operator never filled in. It answers a real HTML 404 (555 bytes) for every path but /, so it is not a catch-all. www.agmsg.world does not resolve. - host: api.agmsg.world documents: - path: /.well-known/agent-card.json status: 200 content_type: application/json bytes: 45856 file: ../a2a/agmsg-world-agent-card.json note: A2A Agent Card (canonical path); graded flavored in a2a/agmsg-world-a2a.yml. - path: /.well-known/agent.json status: 200 content_type: application/json bytes: 45856 file: ../a2a/agmsg-world-agent-card.json note: Legacy pre-0.3 path; byte-identical to the canonical document, so not saved twice. - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/api-catalog.json status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/apis.json status: 404 - path: /.well-known/ucp.json status: 404 - path: /.well-known/acp.json status: 404 - path: /.well-known/aauth-resource.json status: 404 - path: /apis.json status: 404 - path: /apis.yml status: 404 - path: /robots.txt status: 404 path_echo_control: passed soft_404_control: path: /.well-known/agmsg-world-negative-control-9f2c1ab7.json status: 404 bytes: 22 body: '{"detail":"Not Found"}' note: >- FastAPI host (per developer-ai.txt) behind Railway (server: railway-hikari). Unmatched paths answer a real JSON 404, so the two 200s are genuine documents. root_discovery: note: >- Real published discovery documents served from the API root, NOT /.well-known/. Recorded so the surface is visible, but none of them is a well-known document and none counts as one. documents: - path: /llms.txt status: 200 content_type: text/plain file: ../llms/agmsg-world-llms.txt spec: llms.txt (ADF-001 profile) - path: /llm.txt status: 200 note: byte-identical alias of /llms.txt - path: /llms.html status: 200 content_type: text/html file: ../llms/agmsg-world-llms.html note: human-readable mirror of llms.txt; the only HTML documentation page the provider serves - path: /ai.txt status: 200 file: ../llms/agmsg-world-ai.txt spec: ai.txt (ADF-004) - AI usage permissions and restrictions, dated 2026-08-23 - path: /ai.json status: 200 file: ../llms/agmsg-world-ai.json spec: ai.json (machine-readable twin of ai.txt) - path: /identity.json status: 200 file: ../llms/agmsg-world-identity.json spec: identity.json (ai-visibility.org.uk) - structured business identity - path: /brand.txt status: 200 file: ../llms/agmsg-world-brand.txt spec: brand.txt (ADF-007) - path: /faq-ai.txt status: 200 file: ../llms/agmsg-world-faq-ai.txt spec: faq-ai.txt (ADF-008) - path: /developer-ai.txt status: 200 file: ../llms/agmsg-world-developer-ai.txt spec: developer-ai.txt (ADF-009) - technical context; states there are no rate limits, no webhooks and no changelog - path: /skill.json status: 200 file: ../llms/agmsg-world-skill.json note: points at the provider's ClawHub skill (clawhub.ai/beocca/skills/agmsg); /skill is a byte-identical alias - path: /agent.json status: 200 note: byte-identical to /.well-known/agent-card.json; the location llms.txt advertises for the card - path: /openapi.json status: 200 file: ../openapi/_original/agmsg-world-openapi.json note: OpenAPI 3.1.0, 40 operations; the provider calls it its canonical documentation - path: /docs status: 404 note: 'the agent card''s documentationUrl; answers {"detail":"Not Found"}' hit_count: 2