generated: '2026-08-12' method: probed source: live probes of every First Digital host found in apis.yml note: >- Only /.well-known/security.txt returns a real document. IMPORTANT: portal.1stdigital.com answers HTTP 200 to EVERY other /.well-known/* path, but the body is the Angular single-page-app shell (`` … `FDTClientPortalNextGen`), not a discovery document — the classic SPA catch-all false positive. Those rows are recorded as `status: 200` with `document: false` and must not be read as a served surface. The marketing host 1stdigital.com sits behind a Cloudflare bot challenge that answers 403 to automated clients on most paths, but exempts /robots.txt and /.well-known/security.txt, both of which returned real text/plain documents. hosts: - host: https://1stdigital.com documents: - path: /.well-known/security.txt status: 200 content_type: text/plain; charset=utf-8 document: true file: first-digital-trust-security.txt - path: /.well-known/openid-configuration status: 403 document: false note: Cloudflare bot challenge interstitial - path: /.well-known/oauth-authorization-server status: 403 document: false note: Cloudflare bot challenge interstitial - path: /.well-known/api-catalog status: 403 document: false note: Cloudflare bot challenge interstitial - path: /.well-known/ai-plugin.json status: 403 document: false note: Cloudflare bot challenge interstitial - path: /.well-known/agent-card.json status: 403 document: false - path: /.well-known/agent.json status: 403 document: false - host: https://www.1stdigital.com documents: - path: /.well-known/security.txt status: 200 content_type: text/plain; charset=utf-8 document: true note: identical body to the apex host; not stored twice - path: /.well-known/openid-configuration status: 403 document: false - path: /.well-known/oauth-authorization-server status: 403 document: false - path: /.well-known/api-catalog status: 403 document: false - path: /.well-known/ai-plugin.json status: 403 document: false - path: /.well-known/agent-card.json status: 403 document: false - path: /.well-known/agent.json status: 403 document: false - host: https://portal.1stdigital.com note: FDTClientPortalNextGen — the Angular client portal SPA (version 2.3.0, commit c3aaa2c) documents: - path: /.well-known/security.txt status: 200 content_type: text/plain; charset=utf-8 document: true note: identical body to the apex host; not stored twice - path: /.well-known/openid-configuration status: 200 content_type: text/html document: false note: SPA catch-all — returns the Angular index shell, NOT an OIDC discovery document - path: /.well-known/oauth-authorization-server status: 200 content_type: text/html document: false note: SPA catch-all — returns the Angular index shell - path: /.well-known/api-catalog status: 200 content_type: text/html document: false note: SPA catch-all — returns the Angular index shell - path: /.well-known/ai-plugin.json status: 200 content_type: text/html document: false note: SPA catch-all — returns the Angular index shell - path: /.well-known/agent-card.json status: 200 content_type: text/html document: false note: SPA catch-all — HTML body, rejected as an agent card; no a2a/ artifact written - path: /.well-known/agent.json status: 200 content_type: text/html document: false note: SPA catch-all — HTML body, rejected as an agent card - host: https://helpdesk.1stdigital.com note: Deskpro-hosted "First Digital Support Center" documents: - path: /.well-known/security.txt status: 404 document: false - path: /.well-known/openid-configuration status: 404 document: false - path: /.well-known/oauth-authorization-server status: 404 document: false - path: /.well-known/api-catalog status: 404 document: false - path: /.well-known/ai-plugin.json status: 404 document: false - path: /.well-known/agent-card.json status: 404 document: false - path: /.well-known/agent.json status: 404 document: false summary: paths_probed: 30 real_documents: 1 document_types: - security.txt spa_catchall_200s: 6