generated: '2026-08-13' method: probed source: live HTTP probes of every Google Analytics API host, the docs host, and the Google identity hosts that issue tokens for these APIs provider: Google Analytics providerId: google-analytics summary: 'None of the Google Analytics API hosts serve any /.well-known/ document — every path returns 404 on analyticsdata.googleapis.com, analyticsadmin.googleapis.com, analyticsreporting.googleapis.com, www.google-analytics.com, www.googleapis.com and developers.google.com. The real, served documents live on Google''s shared identity and corporate hosts: accounts.google.com publishes the OpenID Provider and OAuth 2.0 Authorization Server metadata that every Google Analytics API client authenticates against, and www.google.com publishes Google''s security.txt (the vulnerability disclosure surface that covers Google Analytics).' probes: - host: analyticsdata.googleapis.com paths: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: analyticsadmin.googleapis.com paths: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: analyticsreporting.googleapis.com paths: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: www.google-analytics.com paths: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: www.googleapis.com paths: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: developers.google.com note: docs / developer portal host paths: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /llms.txt status: 404 - host: accounts.google.com note: Google's identity host. This is the authorization server named by every Google Analytics OpenAPI securityScheme (authorizationUrl https://accounts.google.com/o/oauth2/auth), so its metadata is the machine-readable auth contract for these APIs. paths: - path: /.well-known/openid-configuration status: 200 file: google-analytics-openid-configuration.json content_type: application/json - path: /.well-known/oauth-authorization-server status: 200 file: google-analytics-oauth-authorization-server.json content_type: application/json - host: www.google.com note: Google's corporate host serves the security.txt that covers all Google products including Google Analytics. paths: - path: /.well-known/security.txt status: 200 file: google-analytics-security.txt content_type: text/plain findings: - No Google Analytics API host publishes /.well-known/ anything. Discovery on these hosts happens through the Google API Discovery Service instead (https://analyticsdata.googleapis.com/$discovery/rest?version=v1beta, https://analyticsadmin.googleapis.com/$discovery/rest?version=v1beta — both 200, captured under discovery/). - No agent card is served on any host, at either the canonical /.well-known/agent-card.json path or the legacy /.well-known/agent.json path. No AgentCard artifact was written. - No ai-plugin.json and no api-catalog anywhere in the estate. maintainers: - FN: Kin Lane email: kin@apievangelist.com hosts: - host: accounts.google.com documents: - path: /.well-known/openid-configuration status: 200 file: google-analytics-openid-configuration.json url: https://accounts.google.com/.well-known/openid-configuration - path: /.well-known/oauth-authorization-server status: 200 file: google-analytics-oauth-authorization-server.json url: https://accounts.google.com/.well-known/oauth-authorization-server - path: /.well-known/security.txt status: 200 file: google-analytics-security.txt url: https://www.google.com/.well-known/security.txt x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.