generated: '2026-07-19' method: searched source: live probes of /.well-known/* across Grammarly hosts hosts: - host: https://www.grammarly.com documents: - path: /.well-known/security.txt status: 200 file: grammarly-security.txt - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://developer.grammarly.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - host: https://api.grammarly.com documents: - path: /.well-known/security.txt status: 403 - path: /.well-known/oauth-authorization-server status: 404 - host: https://auth.grammarly.com documents: - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/openid-configuration status: 403 notes: >- Only www.grammarly.com publishes a /.well-known/security.txt (RFC 9116). The API and auth hosts return 403/404 for well-known discovery documents; no OIDC/OAuth authorization-server metadata or api-catalog is published.