generated: '2026-09-19' method: probed source: live HTTP probes of every Clari host named in apis.yml and in the OpenAPI servers[] name: Clari .well-known probe description: Probe of the standard /.well-known/ discovery paths across every Clari host. The marketing site (www.clari.com) answers HTTP 200 with the same 51KB HTML shell for every unknown path, so its 200s are soft-404s and are recorded as misses, not documents. The real hits are the MCP OAuth metadata documents served by the Kong gateway on mcp.clari.com and api.clari.com, which advertise the Clari MCP Server as an OAuth 2.0 protected resource backed by Okta (clariciam.okta.com). hosts: - host: mcp.clari.com paths: - path: /.well-known/oauth-protected-resource/mcp status: 200 content_type: application/json document: true file: well-known/clari-mcp-oauth-protected-resource.json note: Real RFC 9728 protected-resource metadata. resource_name "Clari MCP Server", resource https://mcp.clari.com/mcp, scopes_supported [openid, profile]. - path: /.well-known/oauth-authorization-server/mcp status: 200 content_type: application/json document: true file: well-known/clari-mcp-oauth-authorization-server.json note: Real RFC 8414 authorization-server metadata. issuer https://clariciam.okta.com/oauth2/aus13shznanP7WOkp698, authorization_endpoint https://app.clari.com/authorize, dynamic client registration at https://mcp.clari.com/okta/clients, PKCE S256, DPoP supported. - path: /.well-known/oauth-authorization-server status: 404 document: false - path: / status: 404 document: false documents: - path: /.well-known/oauth-protected-resource status: 200 file: clari-mcp-oauth-protected-resource.json bytes: 256 - path: /mcp/.well-known/oauth-authorization-server status: 200 file: clari-mcp-oauth-authorization-server.json bytes: 1967 path_echo_control: passed - host: api.clari.com paths: - path: /.well-known/oauth-protected-resource/mcp status: 200 content_type: application/json document: true file: well-known/clari-api-oauth-protected-resource.json note: Same MCP resource metadata served from the primary API gateway host. - path: /.well-known/security.txt status: 404 document: false - path: /.well-known/openid-configuration status: 404 document: false - path: /.well-known/oauth-authorization-server status: 404 document: false - path: /.well-known/api-catalog status: 404 document: false - path: /.well-known/ai-plugin.json status: 404 document: false - path: /.well-known/agent-card.json status: 404 document: false - path: /.well-known/agent.json status: 404 document: false - path: /llms.txt status: 404 document: false - host: www.clari.com note: 'Every path below returned HTTP 200 with the identical 51,604-byte marketing HTML shell (confirmed: https://www.clari.com/mcp also returns 200 with Error 404 | Clari). These are soft-404s and carry no document.' paths: - path: /.well-known/security.txt status: 200 content_type: text/html document: false - path: /.well-known/openid-configuration status: 200 content_type: text/html document: false - path: /.well-known/oauth-authorization-server status: 200 content_type: text/html document: false - path: /.well-known/api-catalog status: 200 content_type: text/html document: false - path: /.well-known/ai-plugin.json status: 200 content_type: text/html document: false - path: /.well-known/agent-card.json status: 200 content_type: text/html document: false - path: /.well-known/agent.json status: 200 content_type: text/html document: false - path: /llms.txt status: 200 content_type: text/html document: false - path: /security.txt status: 200 content_type: text/html document: false - host: developer.clari.com note: Kong Developer Portal SPA. Answers 200 with the portal HTML shell for every unknown path, including /openapi.json and /swagger.json. Soft-404, no document. paths: - path: /.well-known/security.txt status: 200 content_type: text/html document: false - path: /.well-known/agent-card.json status: 200 content_type: application/json document: false note: Content-Type is application/json but the body is the portal HTML shell. - path: /.well-known/agent.json status: 200 content_type: application/json document: false - path: /llms.txt status: 200 content_type: text/html document: false - host: api-doc.copilot.clari.com note: ReDoc documentation host. Clean 404s. paths: - path: /.well-known/security.txt status: 404 document: false - path: /.well-known/agent-card.json status: 404 document: false - path: /.well-known/agent.json status: 404 document: false - path: /llms.txt status: 404 document: false - host: rest-api.copilot.clari.com note: Copilot REST API host. Every path, including /.well-known/*, returns HTTP 401 with {"errorMessage":"Credentials not provided!"} — the gateway authenticates before routing, so no anonymous discovery surface exists here. paths: - path: /.well-known/security.txt status: 401 document: false - path: /.well-known/agent-card.json status: 401 document: false - path: /.well-known/agent.json status: 401 document: false - path: /llms.txt status: 401 document: false - host: api.copilot.clari.com note: NXDOMAIN. This host was recorded as the Copilot baseURL in apis.yml before this pass and does not resolve; the real base is https://rest-api.copilot.clari.com per the servers[] block of the published Copilot OpenAPI. paths: - path: / status: 0 document: false summary: documents_found: 3 security_txt: false openid_configuration: false oauth_authorization_server: true oauth_protected_resource: true api_catalog: false ai_plugin: false agent_card: false llms_txt: false x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://mcp.clari.com path: /.well-known/oauth-protected-resource file: clari-mcp-oauth-protected-resource.json - host: https://mcp.clari.com path: /mcp/.well-known/oauth-authorization-server file: clari-mcp-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host note: 'MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.'