generated: '2026-06-20' method: searched source: >- Live probe of the /.well-known/ discovery surface on the AWS website and API hosts. Only aws.amazon.com/.well-known/security.txt returns a real document (200, saved verbatim). The API host secretsmanager.amazonaws.com serves only signed SigV4 requests and does not answer HTTP GET (connection refused). The aws.amazon.com OIDC/OAuth/api-catalog/ai-plugin paths 301-redirect to a trailing-slash marketing route rather than serving a real discovery document. hosts: - host: https://aws.amazon.com documents: - path: /.well-known/security.txt status: 200 file: amazon-secrets-manager-security.txt - path: /.well-known/openid-configuration status: 301 note: redirects to marketing route; not an OIDC discovery document - path: /.well-known/oauth-authorization-server status: 301 note: redirects to marketing route; not an RFC 8414 document - path: /.well-known/api-catalog status: 301 - path: /.well-known/ai-plugin.json status: 301 - host: https://docs.aws.amazon.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/api-catalog status: 404 - host: https://secretsmanager.amazonaws.com documents: - path: /.well-known/security.txt status: 000 note: API endpoint answers only signed AWS SigV4 requests; no HTTP GET surface