generated: '2026-09-19' method: probed source: live probes of /.well-known/ on Harmonic hosts revised: '2026-08-14' summary: 'Two real documents are served, both on the MCP host: RFC 8414 authorization-server metadata and RFC 9728 protected-resource metadata. That is a genuine WellKnown hit and the pointer is earned. Nothing else is served anywhere: no security.txt (so NO SecurityTxt pointer), no api-catalog, no ai-plugin.json, no OIDC discovery, and no A2A agent card.' pointer_basis: WellKnown pointer emitted on the strength of the two 200s on mcp.api.harmonic.ai. SecurityTxt pointer NOT emitted — RFC 9116 is unimplemented on every host. false_positive_watch: console.harmonic.ai answers HTTP 200 with the dashboard SPA shell for EVERY /.well-known/* path, including paths that do not exist. Those 200s are recorded below as misses, not hits. Any future round that treats a console.harmonic.ai /.well-known/ 200 as a served document is wrong. hosts: - host: https://mcp.api.harmonic.ai documents: - path: /.well-known/oauth-authorization-server status: 200 file: harmonic-ai-mcp-oauth-authorization-server.json - path: /.well-known/oauth-protected-resource status: 200 file: harmonic-ai-mcp-oauth-protected-resource.json - path: /.well-known/openid-configuration status: 404 - path: /.well-known/agent-card.json status: 404 body: Not Found checked: '2026-08-14' - path: /.well-known/agent.json status: 404 body: Not Found checked: '2026-08-14' - host: https://api.harmonic.ai documents: - path: /.well-known/security.txt status: 403 - path: /.well-known/openid-configuration status: 403 - path: /.well-known/oauth-authorization-server status: 403 - path: /.well-known/api-catalog status: 403 - path: /.well-known/ai-plugin.json status: 403 - path: /.well-known/agent-card.json status: 403 body: '{"message":"Authentication required. Include either an api key or a JWT."}' checked: '2026-08-14' - path: /.well-known/agent.json status: 403 body: '{"message":"Authentication required. Include either an api key or a JWT."}' checked: '2026-08-14' note: api.harmonic.ai is fronted by Kong 3.0.2 and 403s every unauthenticated path before any /.well-known/ handler is reached, so these are "unreachable", not "confirmed absent". - host: https://harmonic.ai documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/agent-card.json status: 404 body: ...
Invalid .well-known request
checked: '2026-08-14' - path: /.well-known/agent.json status: 404 body: ...Invalid .well-known request
checked: '2026-08-14' note: Webflow-hosted marketing site; it returns a generic "Invalid .well-known request" 404 for every /.well-known/* path. Same result on www.harmonic.ai. - host: https://console.harmonic.ai documents: - path: /.well-known/agent-card.json status: 200 served_document: false body: SPA shell (HTML,