generated: '2026-09-19' method: searched source: live probes of every ChargeAfter host in apis.yml and OpenAPI servers[] hosts_probed: - chargeafter.com - www.chargeafter.com - docs.chargeafter.com - api.chargeafter.com - api-sandbox.ca-dev.co x-evidence: fetched: '2026-08-09' method: HTTP GET, redirects followed, bodies verified to parse as JSON before being recorded as a hit hosts: - host: '' documents: - path: /.well-known/api-catalog status: 200 file: chargeafter-api-catalog.json content_type: application/linkset+json note: 62 linkset entries, each advertising an OpenAPI service-desc at https://docs.chargeafter.com/openapi/. This is the richest discovery surface ChargeAfter publishes and it exposes definitions that are not linked from the documentation navigation — the Disputes Management for Lenders API and the Consumer credit-lookup API were both found here. - path: /.well-known/oauth-authorization-server status: 200 file: chargeafter-oauth-authorization-server.json content_type: application/json note: Authorization code + PKCE (S256), refresh_token, dynamic public clients, single scope `mcp`. This is the WordPress marketing site's MCP authorization server, NOT the payments API's auth surface. - path: /.well-known/oauth-protected-resource status: 200 file: chargeafter-oauth-protected-resource.json content_type: application/json note: 'resource: https://chargeafter.com/wp-json/mcp/mcp-oauth-server' - path: /.well-known/security.txt status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - host: https://chargeafter.com documents: - path: /.well-known/oauth-protected-resource status: 200 file: chargeafter-chargeafter-oauth-protected-resource.json bytes: 191 - path: /.well-known/oauth-authorization-server status: 200 file: chargeafter-chargeafter-oauth-authorization-server.json bytes: 551 path_echo_control: passed x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent. x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://chargeafter.com path: /.well-known/oauth-protected-resource file: chargeafter-chargeafter-oauth-protected-resource.json - host: https://chargeafter.com path: /.well-known/oauth-authorization-server file: chargeafter-chargeafter-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host note: 'MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.'