generated: '2026-09-19' method: probed source: Direct HTTP probes of the /.well-known/ discovery surface on every Feedly host named in apis.yml (feedly.com, api.feedly.com, cloud.feedly.com) plus the docs host (developers.feedly.com) and the MCP host (mcp.feedly.com), 2026-08-12. description: Feedly serves two real /.well-known/ documents, and they are the reason this profile has a machine- readable contract at all. developers.feedly.com publishes an RFC 9727 API Catalog (linkset) naming 21 OpenAPI service-desc URLs — 17 of which resolve to live, first-party OpenAPI 3.x documents. The Threat Graph MCP host publishes RFC 8414 OAuth 2.0 Authorization Server Metadata with dynamic client registration. Neither is linked from the human documentation; both were found only by probing. hosts: - host: developers.feedly.com role: documentation documents: - path: /.well-known/api-catalog status: 200 content_type: application/linkset+json standard: RFC 9727 (API Catalog) file: feedly-api-catalog.json note: Real linkset. 21 service-desc entries of type application/vnd.oai.openapi+json pointing at https://developers.feedly.com/openapi/. 17 resolve 200 as OpenAPI 3.0/3.1; 3 return 404 (stale catalog entries, ids 69c15101706bb016d588b265, 69c16e9c94c0a2b0ac67267e, 655b81ac5ed961054e8f54b6); 1 is a duplicate href. Harvested into openapi/. - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: mcp.feedly.com role: mcp-server documents: - path: /.well-known/oauth-authorization-server status: 200 content_type: application/json standard: RFC 8414 (OAuth 2.0 Authorization Server Metadata) file: feedly-mcp-oauth-authorization-server.json note: Real metadata document. issuer https://mcp.feedly.com; authorization, token, registration and revocation endpoints; grant types authorization_code + refresh_token; PKCE S256 and plain; RFC 7591 dynamic client registration supported. Feeds authentication/ and conformance/. - path: /.well-known/oauth-protected-resource status: 404 note: Absent. The MCP server does return a compliant WWW-Authenticate challenge (Bearer realm="OAuth", error="invalid_token"), but does not publish the RFC 9728 protected- resource metadata that would let a client discover the authorization server automatically. - path: /.well-known/oauth-protected-resource/mcp status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/oauth-protected-resource status: 200 file: feedly-mcp-oauth-protected-resource.json bytes: 130 path_echo_control: passed - host: api.feedly.com role: api documents: - path: /.well-known/security.txt status: 200 note: NOT a document. The 200 body is the 37-byte string "Too Many Requests (HAP429)." — the edge rate-limiter answering with a success status. Re-probed and it returned a true 429. Recorded as a MISS; no SecurityTxt pointer is emitted. - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 429 - path: /.well-known/ai-plugin.json status: 429 - path: /.well-known/agent-card.json status: 429 - path: /.well-known/agent.json status: 429 - host: feedly.com role: website documents: - path: /.well-known/security.txt status: 200 note: Same soft-200 rate-limit body as api.feedly.com ("Too Many Requests (HAP429)."), not a RFC 9116 document. Treated as a miss. - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: cloud.feedly.com role: api-legacy documents: - path: /.well-known/security.txt status: 200 note: Soft-200 rate-limit body, not a document. Miss. - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 summary: hosts_probed: 5 real_documents: 2 api_catalog: true oauth_authorization_server: true security_txt: false openid_configuration: false ai_plugin: false agent_card: false x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://mcp.feedly.com path: /.well-known/oauth-protected-resource file: feedly-mcp-oauth-protected-resource.json - host: https://mcp.feedly.com path: /.well-known/oauth-authorization-server file: feedly-mcp-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host note: 'MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.'