generated: '2026-08-04' method: searched source: Live probes of https://harbinger-health.com/.well-known/* on 2026-08-04 host: https://harbinger-health.com summary: Harbinger Health serves two real RFC-defined discovery documents from its own host, both of them in service of the Model Context Protocol server registered on the site. It serves no security.txt, no OpenID Connect discovery document, no RFC 9727 api-catalog, no ai-plugin manifest and no A2A agent card at either the canonical or the legacy path. other_discovery_surfaces: - path: /wp-json/ status: 200 note: WordPress REST route-discovery document, 268 routes across 15 namespaces. Saved verbatim to openapi/harbinger-health-wp-json-discovery.json and derived into openapi/harbinger-health-wordpress-wp-v2-openapi.yml. - path: /wp-json/mcp status: 200 note: MCP namespace index listing mcp-oauth-server and mcp-adapter-default-server. - path: /wp-json/wp-abilities/v1/abilities status: 401 note: WordPress Abilities API — the likely tool source for the MCP server; gated to anonymous callers. - path: /robots.txt status: 200 note: 'Yoast-generated. Crawl-delay: 10, Disallow empty (all user agents permitted), sitemap declared.' - path: /sitemap_index.xml status: 200 note: Yoast sitemap index covering post, page, category and author sitemaps. hosts: - host: https://harbinger-health.com documents: - path: /.well-known/oauth-authorization-server status: 200 file: harbinger-health-oauth-authorization-server.json content_type: application/json - path: /.well-known/oauth-protected-resource status: 200 file: harbinger-health-oauth-protected-resource.json content_type: application/json - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.