generated: '2026-08-15' method: probed source: live HTTP probes of every Clarify Health host reachable from public DNS note: >- Clarify Health publishes no developer program and no API host. The only /.well-known/ documents it actually serves are the OIDC / OAuth 2.0 authorization-server discovery documents on its two identity hosts — auth.clarifyhealth.com (an Auth0 tenant on a vanity CNAME) and okta.clarifyhealth.com (an Okta org). Both are provider-controlled hosts under clarifyhealth.com, so they pass the ownership check. Everything else 404s. hosts: - host: https://clarifyhealth.com platform: Squarespace (marketing site) documents: - path: /.well-known/security.txt status: 404 body: '{"message":"security.txt not found"}' - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /llms.txt status: 404 - path: /openapi.json status: 404 - path: /robots.txt status: 200 note: Squarespace default robots.txt; enumerates AI crawler user-agents. Not a discovery document. - path: /sitemap.xml status: 200 note: 79 URLs, all marketing/resource pages. No developer, API, or documentation path. - host: https://auth.clarifyhealth.com platform: Auth0 (vanity domain) documents: - path: /.well-known/openid-configuration status: 200 content_type: application/json file: clarify-health-auth-openid-configuration.json issuer: https://auth.clarifyhealth.com/ - path: /.well-known/oauth-authorization-server status: 200 content_type: application/json file: clarify-health-auth-oauth-authorization-server.json issuer: https://auth.clarifyhealth.com/ - path: /.well-known/security.txt status: 404 - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://okta.clarifyhealth.com platform: Okta (org authorization server) documents: - path: /.well-known/openid-configuration status: 200 content_type: application/json file: clarify-health-okta-openid-configuration.json issuer: https://okta.clarifyhealth.com - path: /.well-known/oauth-authorization-server status: 200 content_type: application/json file: clarify-health-okta-oauth-authorization-server.json issuer: https://okta.clarifyhealth.com - path: /oauth2/default/.well-known/openid-configuration status: 401 note: >- Okta custom authorization server "default" is not enabled for anonymous discovery (errorCode E0000015). Only the org authorization server is public. - path: /.well-known/agent-card.json status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/api-catalog status: 405 - path: /.well-known/oauth-protected-resource status: 405 - host: https://status.clarifyhealth.com platform: Atlassian Statuspage (hosted) documents: - path: /.well-known/security.txt status: 200 content_type: text/plain owner: atlassian saved: false note: >- NOT Clarify Health's. The document is Atlassian's own PGP-signed security.txt served by the Statuspage platform — Contact security@atlassian.com, and it declares "Canonical: https://www.atlassian.com/.well-known/security.txt". Recorded as a MISS for Clarify Health; no SecurityTxt or Security pointer is emitted from it. - path: /.well-known/agent-card.json status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://reports.adv.clarifyhealth.com platform: Amazon S3 / CloudFront (private) documents: - path: / status: 403 note: S3 AccessDenied on every path probed; no anonymous surface. - path: /openapi.json status: 403 - path: /.well-known/openid-configuration status: 403 summary: hosts_probed: 5 paths_probed: 40 documents_served: 4 documents_saved: 4 security_txt_served_by_provider: false agent_card_found: false api_catalog_found: false ai_plugin_found: false