# AOL > AOL is a consumer internet media and communications brand — AOL.com news, AOL > Mail, AOL Search and AOL Desktop — operated by AOL Media LLC. Yahoo sold AOL to > the Italian software company Bending Spoons in 2026. AOL runs no developer > program and publishes no product API. The one machine-readable, publicly > callable contract it serves is its OpenID Connect provider at > api.login.aol.com, which lets a third-party application sign a user in with > their AOL account. Generated by the API Evangelist enrichment pipeline on 2026-09-02 from AOL's own published documents and this repository. AOL does not serve an llms.txt of its own (https://www.aol.com/llms.txt returned 404 on 2026-09-02). ## What is actually callable - [OpenID Connect discovery document](https://api.login.aol.com/.well-known/openid-configuration): The authoritative, AOL-served description of the identity API. Issuer `https://api.login.aol.com`. Probed 200 on 2026-09-02. - [JWKS](https://api.login.aol.com/openid/v1/certs): Public keys for verifying AOL-issued ID tokens. Anonymous, probed 200. - [Authorization endpoint](https://api.login.aol.com/oauth2/request_auth): Start the OAuth 2.0 Authorization Code flow. - [Token endpoint](https://api.login.aol.com/oauth2/get_token): Exchange a code, or refresh an access token. Client auth: client_secret_basic or client_secret_post. - [UserInfo endpoint](https://api.login.aol.com/openid/v1/userinfo): OIDC standard claims for the signed-in user. Bearer token required. - [Token revocation endpoint](https://api.login.aol.com/oauth2/revoke): The reversal path for an issued token. - [Token introspection endpoint](https://api.login.aol.com/oauth2/introspect): Declared in discovery; refuses anonymous callers (403). Scopes: `openid`, `openid2` (legacy OpenID 2.0 compatibility), `profile`, `email`. Grants: `authorization_code`, `refresh_token`. ID token algorithms: ES256, RS256. Assurance levels: `AAL1`, `AAL2` (NIST SP 800-63B). ## Specifications in this repository - [OAuth 2.0 API OpenAPI](openapi/aol-oauth2-api-openapi.yml): Authorization and token endpoints. - [OpenID Connect API OpenAPI](openapi/aol-openid-connect-api-openapi.yml): UserInfo and JWKS endpoints. - [OpenAPI Overlay — OAuth 2.0](overlays/aol-oauth2-api-overlay.yaml) - [OpenAPI Overlay — OpenID Connect](overlays/aol-openid-connect-api-overlay.yaml) ## Operating artifacts - [Authentication profile](authentication/aol-authentication.yml) - [OAuth scopes](scopes/aol-scopes.yml) - [API conventions and reversibility](conventions/aol-conventions.yml) - [Error catalog](errors/aol-problem-types.yml) - [Data model](data-model/aol-data-model.yml) - [Conformance](conformance/aol-conformance.yml) - [Lifecycle and status](lifecycle/aol-lifecycle.yml) - [Well-known index](well-known/aol-well-known.yml) - [Rate limits](rate-limits/aol-rate-limits.yml) - [Plans and pricing](plans/aol-plans-pricing.yml) - [Agent skills](skills/_index.yml) ## Human surfaces - [AOL.com](https://www.aol.com) - [AOL Help](https://help.aol.com/) - [AOL system status](https://status.aol.com/) - [Sign in](https://login.aol.com/) - [Account management](https://myaccount.aol.com/) - [Terms of service](https://legal.aol.com/terms/index.html) - [Privacy policy](https://legal.aol.com/privacy/index.html) - [Responsible disclosure policy](https://legal.aol.com/responsible-disclosure.html) - [security.txt](https://www.aol.com/.well-known/security.txt) - [Legacy developer documentation for this identity stack](https://developer.yahoo.com/oauth2/guide/openid_connect/) — hosted by Yahoo Inc., which built and still runs a sibling deployment of the same OAuth/OIDC platform at api.login.yahoo.com. ## What AOL does not publish Stated so an agent stops looking rather than inventing: - No llms.txt, no MCP server, no A2A agent card, no /.well-known/api-catalog. - No OpenAPI, AsyncAPI, GraphQL SDL, Protobuf or WSDL served by AOL itself. - No SDK, CLI, Postman collection, sandbox, changelog or embedded components. - No published rate limits, API pricing, versioning policy, deprecation policy or SLA. - No RFC 9457 problem+json; the identity host uses a proprietary error envelope. ## Agent access policy AOL's robots.txt (https://www.aol.com/robots.txt) applies a blanket `Disallow: /` to more than forty named AI crawlers and agents — anthropic-ai, ClaudeBot, Claude-Web, GPTBot, ChatGPT-User, CCBot, Google-Extended, PerplexityBot, Perplexity-ai, cohere-ai, Bytespider, Diffbot, FacebookBot, huggingface, img2dataset, YouBot and others — and disallows `/api/` for every user-agent. The identity host api.login.aol.com is a separate origin and is not covered by that file. Respect the policy: do not crawl www.aol.com content as an AI agent.