generated: '2026-08-13' method: probed source: live GET of every /.well-known/ path on every host in apis.yml and every OpenAPI servers[] host notes: 'The AdMob API host (admob.googleapis.com) and the AdMob developer/product hosts serve NOTHING at /.well-known/ — every path returns a Google 404 page. The well-known surface that is real for this API belongs to two other Google hosts that this API genuinely depends on: www.google.com serves the corporate RFC 9116 security.txt (the vulnerability-disclosure contact for AdMob), and accounts.google.com serves the OIDC discovery + RFC 8414 authorization-server metadata for the OAuth 2.0 authorization server every AdMob API call authenticates against (its authorizationUrl/tokenUrl are exactly the ones the Discovery Document declares). Both are recorded here with the host they were served from, so the record never implies admob.googleapis.com serves them.' hosts_probed: - admob.googleapis.com - developers.google.com - admob.google.com - www.google.com - accounts.google.com api_catalog: served: false note: Google publishes no RFC 9727 /.well-known/api-catalog for AdMob or for googleapis.com. cross_links: authentication: authentication/google-admob-authentication.yml scopes: scopes/google-admob-scopes.yml vulnerability_disclosure: security/google-admob-vulnerability-disclosure.yml hosts: - host: '' documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/security.txt status: 200 file: google-admob-security.txt content_type: text/plain note: Google's corporate security.txt — the disclosure contact that governs AdMob. - path: /.well-known/openid-configuration status: 200 file: google-admob-openid-configuration.json content_type: application/json note: The OIDC discovery document for the authorization server AdMob API tokens are issued by. Its authorization_endpoint/token_endpoint match the flow declared in the AdMob Discovery Document. - path: /.well-known/oauth-authorization-server status: 200 file: google-admob-oauth-authorization-server.json content_type: application/json note: OAuth 2.0 Authorization Server Metadata for accounts.google.com. x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.