generated: '2026-08-11' method: probed source: live GET probes of https://infer.flow7.org/.well-known/* on 2026-08-11 description: >- Probe record for every /.well-known/ path this pipeline checks, against the single host Infer publishes (infer.flow7.org). Infer serves TWO real well-known documents — an RFC 9727 API catalog and its own APIs.json index — plus an Agent Skills discovery index under the same namespace. It serves no security.txt, no OpenID/OAuth metadata (the API is Bearer API key, not OAuth), no ai-plugin.json, and no A2A agent card. host: infer.flow7.org paths: - path: /.well-known/api-catalog status: 200 content_type: application/linkset+json; profile="https://www.rfc-editor.org/info/rfc9727" document: true file: well-known/infer-by-flow7-api-catalog.json note: >- A real RFC 9727 linkset. Anchors /v1/responses to its service-desc (the OpenAPI), its service-doc (/docs) and a status resource (/api/public/status). This is the API-catalog hit that earns the WellKnown pointer. - path: /.well-known/apis.json status: 200 content_type: application/json document: true file: well-known/infer-by-flow7-apis.json note: >- Provider-authored APIs.json 0.21 index (aid infer.flow7.org:api-index). Self-published, not generated by API Evangelist. Declares OpenAPI, Documentation, StatusPage, Services and AgentSkills properties plus Signup/Support/Terms/Privacy/LlmsText/BlogFeed common entries. - path: /.well-known/agent-skills/index.json status: 200 content_type: application/json document: true file: well-known/infer-by-flow7-agent-skills-index.json note: >- Agent Skills discovery 0.2.0 index listing three skills with SHA-256 artifact digests. Feeds the AgentSkill artifacts in skills/. - path: /.well-known/security.txt status: 404 document: false note: >- Not served. A security contact IS published, but only in prose on /terms (security@flow7.org), not as an RFC 9116 document. No SecurityTxt pointer is emitted. - path: /.well-known/openid-configuration status: 404 document: false - path: /.well-known/oauth-authorization-server status: 404 document: false note: Consistent with the contract — the only securityScheme is HTTP Bearer with an Infer API key. - path: /.well-known/oauth-protected-resource status: 404 document: false - path: /.well-known/ai-plugin.json status: 404 document: false - path: /.well-known/agent-card.json status: 404 document: false note: >- No A2A agent card. The 404 body is the site's HTML 404 page, not a card. Nothing was written to a2a/ — an agent card is never authored on a provider's behalf. - path: /.well-known/agent.json status: 404 document: false note: Legacy pre-0.3 A2A path also checked and also absent. - path: /.well-known/mcp.json status: 404 document: false non_well_known_probes: - url: https://infer.flow7.org/openapi.json status: 404 note: The OpenAPI is served at /openapi-public.json, not the conventional path. - url: https://infer.flow7.org/swagger.json status: 404 - url: https://infer.flow7.org/v1/openapi.json status: 404 - url: https://infer.flow7.org/api-docs status: 404 - url: https://infer.flow7.org/asyncapi.yaml status: 404 - url: https://infer.flow7.org/mcp status: 404 - url: https://infer.flow7.org/robots.txt status: 200 note: "Allow: / with /app, /login, /verify-email, /reset-password, /accept-invitation disallowed. Sitemap declared." - url: https://infer.flow7.org/sitemap.xml status: 200 note: 22 public URLs, all of which resolved 200 when spot-checked.