generated: '2026-09-19' method: probed source: live HTTP probes of every host named in apis.yml and the OpenAPI servers[] block note: 'Three of the probed paths returned a real document. bitly.com serves an RFC 9116 security.txt, and the API host api-ssl.bitly.com serves both RFC 8414 OAuth authorization-server metadata and RFC 9728 protected-resource metadata — the latter is what Bitly''s MCP server advertises in its 401 WWW-Authenticate challenge. Every other path 404d. dev.bitly.com and bitly.com answer unknown /.well-known/* paths with an HTML 404 (correct status, HTML body), so no soft-200 false positives were possible. MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.' hosts: - bitly.com - dev.bitly.com - api-ssl.bitly.com - host: https://api-ssl.bitly.com documents: - path: /.well-known/oauth-protected-resource status: 200 file: bitly-api-ssl-oauth-protected-resource.json bytes: 243 - path: /.well-known/oauth-authorization-server status: 200 file: bitly-api-ssl-oauth-authorization-server.json bytes: 590 path_echo_control: passed probes: - host: bitly.com path: /.well-known/security.txt status: 200 content_type: text/plain; charset=utf-8 file: well-known/bitly-security.txt document: true - host: api-ssl.bitly.com path: /.well-known/oauth-authorization-server status: 200 content_type: application/json file: well-known/bitly-oauth-authorization-server.json document: true - host: api-ssl.bitly.com path: /.well-known/oauth-protected-resource status: 200 content_type: application/json file: well-known/bitly-oauth-protected-resource.json document: true note: Declares resource https://api-ssl.bitly.com/v4/mcp — the MCP server — and lists api-ssl.bitly.com as its authorization server. - host: dev.bitly.com path: /.well-known/security.txt status: 404 document: false - host: api-ssl.bitly.com path: /.well-known/security.txt status: 404 document: false - host: bitly.com path: /.well-known/openid-configuration status: 404 document: false - host: api-ssl.bitly.com path: /.well-known/openid-configuration status: 404 document: false - host: bitly.com path: /.well-known/api-catalog status: 404 document: false - host: bitly.com path: /.well-known/ai-plugin.json status: 404 document: false - host: bitly.com path: /.well-known/agent-card.json status: 404 document: false - host: dev.bitly.com path: /.well-known/agent-card.json status: 404 document: false - host: api-ssl.bitly.com path: /.well-known/agent-card.json status: 404 document: false - host: bitly.com path: /.well-known/agent.json status: 404 document: false - host: api-ssl.bitly.com path: /.well-known/agent.json status: 404 document: false summary: probed: 14 documents: 3 security_txt: true oauth_metadata: true agent_card: false x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://api-ssl.bitly.com path: /.well-known/oauth-protected-resource file: bitly-api-ssl-oauth-protected-resource.json - host: https://api-ssl.bitly.com path: /.well-known/oauth-authorization-server file: bitly-api-ssl-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host