generated: '2026-07-25' method: searched source: live probes of the Aviva developer portal and corporate hosts note: >- Aviva's developer portal (Kong Konnect) answers several /.well-known/ paths with HTTP 200, but only /.well-known/oauth-authorization-server returns a real document. Every other path returns the portal's single-page-application HTML shell (identical 2,226-byte Nuxt document, Developer Portal) — a catch-all route, not a published discovery document. Those are recorded as status 200 with published: false so a later round does not mistake the shell for a real artifact. hosts: - host: https://developer.aviva.co.uk documents: - path: /.well-known/oauth-authorization-server status: 200 published: true standard: RFC 8414 file: aviva-plc-oauth-authorization-server.json note: >- Authorization server metadata for the DEVELOPER PORTAL login only (issuer https://developer.aviva.co.uk, authorization_code + PKCE S256). It is not the authorization server that issues tokens for consuming Aviva's business APIs — that one is not publicly documented. - path: /.well-known/openid-configuration status: 200 published: false note: Returns the portal SPA HTML shell, not an OIDC discovery document. - path: /.well-known/oauth-protected-resource status: 200 published: false note: Returns the portal SPA HTML shell (RFC 9728 metadata not published). - path: /.well-known/security.txt status: 200 published: false note: Returns the portal SPA HTML shell, not an RFC 9116 security.txt. - path: /.well-known/api-catalog status: 200 published: false note: Returns the portal SPA HTML shell; no RFC 9727 API catalog published. - path: /.well-known/ai-plugin.json status: 200 published: false note: Returns the portal SPA HTML shell. - path: /robots.txt status: 200 published: true note: >- Real robots.txt. Allows all, disallows /login, /login/sso, /logout, /forgot-password, /reset-password, /apps/, /_preview-mode/ and blocks a list of non-helpful crawlers. Confirms the portal exposes a login/SSO surface. - path: /llms.txt status: 403 published: false - host: https://www.aviva.com documents: - path: /.well-known/security.txt status: 404 published: false - path: /llms.txt status: 404 published: false - host: https://www.aviva.co.uk documents: - path: /.well-known/security.txt status: 404 published: false - path: /llms.txt status: 404 published: false - host: https://api.aviva.co.uk documents: - path: /.well-known/security.txt status: 403 published: false note: >- Akamai edge returns a blanket "Access Denied" for every path on this host (x-reference-error / errors.edgesuite.net body). No anonymous discovery surface exists.