generated: '2026-07-19' method: searched source: probed /.well-known/ across Gigya (SAP Customer Data Cloud) REST hosts host: https://accounts.us1.gigya.com notes: accounts.{dc}.gigya.com exposes RFC 8414 OAuth 2.0 authorization-server metadata (issuer https://oauth2.gigya.com; client_credentials + refresh_token grants). The OIDC discovery document is served per-apiKey under the OIDC OP path, not at the host root, so a root probe returns 404. No security.txt is published at the API host. The legacy gigya.com marketing domain no longer resolves (NXDOMAIN) — the live surface is help.sap.com docs plus the accounts.{dc}.gigya.com REST hosts. hosts: - host: https://accounts.us1.gigya.com documents: - path: /.well-known/oauth-authorization-server status: 200 file: gigya-oauth-authorization-server.json - path: /.well-known/openid-configuration status: 404 - path: /.well-known/security.txt status: 404 x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.