generated: '2026-08-22' method: searched source: >- Probed /.well-known/ on every ianacare-controlled host discovered via certificate transparency (api.certspotter.com, ianacare.com + subdomains) on 2026-08-22. note: >- auth.ianacare.com is ianacare's own Auth0 custom domain (CNAME prod-env-ianacare-cd-wcczcfxw9amotowp.edge.tenants.us.auth0.com) and serves a real OIDC discovery document, an identical RFC 8414 authorization-server document, and a live JWKS. Those three are the only served /.well-known/ documents ianacare has. ianacare.com sits behind a SiteGround JS bot challenge that answers HTTP 202 with a meta-refresh interstitial for every path, so no /.well-known/ probe there can be resolved either way; app.ianacare.com and growth.ianacare.com are SPA catch-alls that answer HTTP 200 with the same HTML shell for every path and are recorded as misses, not hits. hit_count: 3 hosts: - host: https://auth.ianacare.com documents: - path: /.well-known/openid-configuration status: 200 file: ianacare-openid-configuration.json - path: /.well-known/oauth-authorization-server status: 200 file: ianacare-oauth-authorization-server.json - path: /.well-known/jwks.json status: 200 file: ianacare-jwks.json - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: https://api.ianacare.com note: >- CloudFront distribution d3k3w0z7cvvteo.cloudfront.net; every path, including the root, returns HTTP 403 {"message":"Forbidden"} to an anonymous browser-UA request. documents: - path: /.well-known/security.txt status: 403 - path: /.well-known/openid-configuration status: 403 - path: /.well-known/oauth-authorization-server status: 403 - path: /.well-known/api-catalog status: 403 - path: /.well-known/ai-plugin.json status: 403 - path: /.well-known/agent-card.json status: 403 - path: /.well-known/agent.json status: 403 - host: https://iana.ianacare.com note: >- Bearer-token API host. Returns a structured JSON error envelope; /.well-known/ paths resolve to a genuine application 404 rather than a catch-all. documents: - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - host: https://ianacare.com note: >- Unresolvable. SiteGround bot challenge (response header sg-captcha: challenge) answers HTTP 202 with a 169-byte meta-refresh interstitial for EVERY path, so a 202 here is neither a hit nor a confirmed absence. documents: - path: /.well-known/security.txt status: 202 - path: /.well-known/openid-configuration status: 202 - path: /.well-known/api-catalog status: 202 - path: /.well-known/agent-card.json status: 202 - path: /.well-known/assetlinks.json status: 202 - host: https://app.ianacare.com note: >- SPA catch-all. Every path returns HTTP 200 with the identical 11,390-byte HTML shell, so no 200 here is a document. Recorded as a miss. soft_404_control: path: /.well-known/this-path-does-not-exist status: 200 bytes: 11390 documents: [] - host: https://growth.ianacare.com note: >- SPA catch-all (Next.js). Every path returns HTTP 200 with the same ~10.4KB HTML shell. Recorded as a miss. documents: []