generated: '2026-08-13' method: probed source: live HTTP probes of every apis.yml baseURL host, every OpenAPI servers[] host, the developer docs host, the Search Console product host, and the OAuth authorization server named by the OpenAPI securitySchemes (accounts.google.com). provider: Google Search Console providerId: google-search-console summary: hosts_probed: 6 paths_probed_per_host: 5 hits: 3 note: 'The Search Console and Indexing API hosts (searchconsole.googleapis.com, indexing.googleapis.com) serve nothing under /.well-known/ — every path returns Google''s standard 404 HTML page. The real well-known surface for this API lives on two other Google hosts: security.txt on the google.com web properties, and the OAuth 2.0 / OpenID Connect authorization-server metadata on accounts.google.com, which is the authorization server the OpenAPI securitySchemes point at.' probes: - host: searchconsole.googleapis.com role: API base host (Search Console API) results: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: indexing.googleapis.com role: API base host (Web Search Indexing API) results: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: developers.google.com role: developer documentation host results: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: search.google.com role: Search Console product host (apis.yml url) results: - path: /.well-known/security.txt status: 200 content_type: text/plain file: google-search-console-security.txt note: Identical document to the one served on www.google.com. - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: www.google.com role: corporate web property results: - path: /.well-known/security.txt status: 200 content_type: text/plain file: google-search-console-security.txt - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: accounts.google.com role: OAuth 2.0 authorization server declared by the OpenAPI securitySchemes (authorizationUrl https://accounts.google.com/o/oauth2/v2/auth) results: - path: /.well-known/openid-configuration status: 200 content_type: application/json file: google-search-console-openid-configuration.json - path: /.well-known/oauth-authorization-server status: 200 content_type: application/json file: google-search-console-oauth-authorization-server.json - path: /.well-known/security.txt status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 maintainers: - FN: Kin Lane email: kin@apievangelist.com hosts: - host: www.google.com documents: - path: /.well-known/security.txt file: google-search-console-security.txt type: SecurityTxt url: https://www.google.com/.well-known/security.txt - path: /.well-known/openid-configuration file: google-search-console-openid-configuration.json type: OpenIDConfiguration url: https://accounts.google.com/.well-known/openid-configuration - path: /.well-known/oauth-authorization-server file: google-search-console-oauth-authorization-server.json type: OAuthAuthorizationServerMetadata url: https://accounts.google.com/.well-known/oauth-authorization-server x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.