# Atolls > Atolls (formerly Global Savings Group) is a Munich-based consumer commerce-content group > operating coupon, cashback, deals and shopping-community destinations in more than 20 > markets. Atolls does NOT publish a public developer API, developer portal, OpenAPI > document or SDK. The only machine-readable contracts it serves are RFC 9116 security.txt > files and OpenID Connect discovery documents on its Pepper community brands. Generated by API Evangelist from probed public documents on 2026-08-13. This is an independent third-party profile, not an Atolls publication. Nothing here was obtained by using credentials or by evading an access control. ## What Atolls actually publishes - [security.txt (atolls.com)](https://atolls.com/.well-known/security.txt): RFC 9116, HTTP 200. Contact security@atolls.com, Policy https://atolls.com/disclosure-policy, Intigriti VDP. - [security.txt (mydealz.de)](https://www.mydealz.de/.well-known/security.txt): HTTP 200. Same group policy; brand runs an invite-only Intigriti program. - [security.txt (hotukdeals.com)](https://www.hotukdeals.com/.well-known/security.txt): HTTP 200. - [security.txt (igraal.com)](https://www.igraal.com/.well-known/security.txt): HTTP 200. Brand runs an invite-only Intigriti program. - [security.txt (shoop.de)](https://www.shoop.de/.well-known/security.txt): HTTP 200. - [OpenID Connect discovery (mydealz.de)](https://www.mydealz.de/.well-known/openid-configuration): HTTP 200, valid JSON. Issuer https://www.mydealz.de. - [OpenID Connect discovery (hotukdeals.com)](https://www.hotukdeals.com/.well-known/openid-configuration): HTTP 200, valid JSON. Issuer https://www.hotukdeals.com. - [robots.txt content signals](https://atolls.com/robots.txt): HTTP 200. search=yes, ai-train=no, use=reference; GPTBot, ClaudeBot, Google-Extended, CCBot, Bytespider, Amazonbot, Applebot-Extended and meta-externalagent are disallowed. ## Authorization surface The Pepper community brands run an OAuth 2.0 / OpenID Connect authorization server per locale. Discovery documents are live on mydealz.de, hotukdeals.com, dealabs.com, preisjaeger.at, chollometro.com, pepper.pl and promodescuentos.com. - Endpoints: `{issuer}/oauth/authorize`, `{issuer}/oauth/token`, `{issuer}/oauth/jwks` - Grants: authorization_code, client_credentials, refresh_token - Scopes: openid, profile, email (identity only — no product or resource scopes) - PKCE: S256 and plain - Signing: RS256 - Token errors: RFC 6749 JSON envelope, HTTP 400, with a non-standard `hint` member There is no client registration path, no protected-resource metadata, and no documented API these tokens are intended to call. Treat this as a sign-in surface, not a developer API. ## What Atolls does NOT publish (probed, not assumed) - No OpenAPI or Swagger on any host. api.atolls.com, developer.atolls.com and docs.atolls.com do not resolve in DNS. - No developer portal, API reference, getting-started guide, changelog, status page, pricing page, rate-limit documentation or SDK. - No A2A agent card at /.well-known/agent-card.json or /.well-known/agent.json. - No /.well-known/api-catalog, no ai-plugin.json, no llms.txt of its own. - A GraphQL endpoint exists at https://www.coupons.com/api/graphql but returns "introspection has been disabled"; no SDL is published. ## Traps for agents on these hosts - hotukdeals.com, shoop.de and pepper.com answer **HTTP 200 with an HTML page for arbitrary paths**. `/openapi.json`, `/llms.txt` and `/developers` all return 200 and are all the same catch-all body. A 200 on these hosts is not evidence a resource exists. - atolls.com HTML pages answer 403 with a Cloudflare interstitial to a plain HTTP client. - mydealz.de/graphql and hotukdeals.com/graphql answer HTTP 418 as an anti-bot response. ## Repository artifacts - well-known/atolls-well-known.yml: every probed path, host by host, with its status. - authentication/atolls-authentication.yml: the OIDC/OAuth profile. - scopes/atolls-scopes.yml: the three advertised scopes. - conformance/atolls-conformance.yml: standards observed and standards missed. - errors/atolls-problem-types.yml: the observed OAuth error envelope and transport traps. - security/atolls-vulnerability-disclosure.yml: the group-wide Intigriti VDP. - security/atolls-domain-security.yml: TLS/HSTS/DNSSEC/CAA/SPF/DMARC across seven domains. ## Contact - Security: security@atolls.com - Corrections to this profile: info@apievangelist.com