generated: '2026-08-06' method: probed source: https://api.arkestro.com/.well-known/ host: https://api.arkestro.com summary: hosts_probed: 4 documents_found: 1 note: Only api.arkestro.com serves a /.well-known/ document. It publishes RFC 8414 OAuth 2.0 Authorization Server Metadata whose scopes_supported (mcp:read, mcp:write, offline_access) is the public evidence that Arkestro operates a remote MCP server. No security.txt, OIDC discovery, api-catalog, ai-plugin.json or agent card is served on any Arkestro host. hosts_probed: - arkestro.com - api.arkestro.com - docs.arkestro.com - developer.arkestro.com - mcp.arkestro.com x-evidence: fetched: '2026-08-06' url: https://api.arkestro.com/.well-known/oauth-authorization-server http_status: 200 content_type: application/json; charset=utf-8 hosts: - host: https://api.arkestro.com documents: - path: /.well-known/oauth-authorization-server status: 200 file: arkestro-oauth-authorization-server.json content_type: application/json - path: /.well-known/security.txt status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-protected-resource status: 404 note: Absent even though a protected MCP resource exists at /api/v2/mcp; MCP clients must fall back to the authorization-server document above for discovery. - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/agent.json status: 404 x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.