generated: '2026-08-27' method: probed source: direct HTTPS probes on 2026-08-27 description: >- No /.well-known/ document is served on any Best Buy host. The API host api.bestbuy.com answers EVERY path — including every /.well-known/* path — with an identical 98-byte 403 JSON body ("We were unable to locate your API Key"), so the discovery surface there is not absent so much as unmeasurable behind a blanket API-key gate. developer.bestbuy.com and bestbuyapis.github.io return real 404 HTML for every path. www.bestbuy.com refused every connection from this crawler (curl exit, HTTP 000) and could not be measured at all. hit_count: 0 hosts: - host: https://api.bestbuy.com note: >- Blanket API-key gate. All paths return the same 403 JSON regardless of path, so a 403 here is not evidence the document is absent — it is evidence the host answers nothing anonymously. documents: - path: /.well-known/security.txt status: 403 file: null - path: /.well-known/openid-configuration status: 403 file: null - path: /.well-known/oauth-authorization-server status: 403 file: null - path: /.well-known/api-catalog status: 403 file: null - path: /.well-known/ai-plugin.json status: 403 file: null - path: /.well-known/agent-card.json status: 403 file: null - path: /.well-known/agent.json status: 403 file: null - host: https://developer.bestbuy.com note: Real 404 HTML page (5,018 bytes, 404 - Page not found) for every path — not a catch-all 200. documents: - path: /.well-known/security.txt status: 404 file: null - path: /.well-known/openid-configuration status: 404 file: null - path: /.well-known/oauth-authorization-server status: 404 file: null - path: /.well-known/api-catalog status: 404 file: null - path: /.well-known/ai-plugin.json status: 404 file: null - path: /.well-known/agent-card.json status: 404 file: null - path: /.well-known/agent.json status: 404 file: null - host: https://bestbuyapis.github.io note: GitHub Pages 404 for every path. documents: - path: /.well-known/agent-card.json status: 404 file: null - path: /.well-known/agent.json status: 404 file: null - path: /api-documentation/.well-known/security.txt status: 404 file: null - host: https://corporate.bestbuy.com note: WordPress 404 template (51KB HTML) for every path. documents: - path: /.well-known/security.txt status: 404 file: null - path: /.well-known/agent-card.json status: 404 file: null - host: https://www.bestbuy.com note: >- UNMEASURABLE. Every request from this crawler — including / and /robots.txt — terminated with no HTTP response (curl status 000, connection refused/reset). This is a bot policy on the retail host, not evidence about the documents. documents: - path: /.well-known/security.txt status: 0 file: null - path: /.well-known/openid-configuration status: 0 file: null - path: /.well-known/oauth-authorization-server status: 0 file: null - path: /.well-known/api-catalog status: 0 file: null - path: /.well-known/ai-plugin.json status: 0 file: null - path: /.well-known/agent-card.json status: 0 file: null - path: /.well-known/agent.json status: 0 file: null pointer_note: >- No WellKnown or SecurityTxt pointer is emitted in apis.yml. Nothing returned a 200 carrying a real document, so a pointer here would assert a surface Best Buy does not serve. Note that Best Buy DOES run a vulnerability disclosure program (hackerone.com/bestbuy) — it is simply not advertised via RFC 9116; see security/best-buy-vulnerability-disclosure.yml.