generated: '2026-08-04' method: probed source: live HTTP probes of every reachable KreditBee host summary: >- KreditBee publishes no /.well-known document of any kind. Every KreditBee web host is a client-rendered single-page application whose origin answers HTTP 200 with the same HTML shell for every unmatched path — including /.well-known/security.txt, /.well-known/agent-card.json, /.well-known/agent.json, /.well-known/openid-configuration, /.well-known/oauth-authorization-server, /.well-known/api-catalog, /.well-known/ai-plugin.json, /llms.txt, /openapi.json and /swagger.json. Those 200s are catch-all false positives, not published documents: the body is text/html, byte-identical to the shell returned for a deliberately nonexistent control path (/nonexistent-page-xyz123, 9,646 bytes), and none parses as JSON or as RFC 9116 text. They are recorded below with valid: false so a later round does not re-discover them as hits. The only real, non-shell documents served on any KreditBee host are /robots.txt and /sitemap.xml on www.kreditbee.in. api.kreditbee.in is an AWS API Gateway behind Cloudflare that answers 403 ForbiddenException to every anonymous request, including every /.well-known/* path. hosts: - host: https://www.kreditbee.in role: consumer website (single-page app) documents: - {path: /robots.txt, status: 200, content_type: text/plain, valid: true, note: 'real document; declares Sitemap and 23 Disallow rules covering internal subdomains'} - {path: /sitemap.xml, status: 200, content_type: application/xml, valid: true, note: '741 URLs; no developer, API, documentation or changelog page among them'} - {path: /.well-known/security.txt, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /.well-known/agent-card.json, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /.well-known/agent.json, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /.well-known/openid-configuration, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /.well-known/oauth-authorization-server, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /.well-known/api-catalog, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /.well-known/ai-plugin.json, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /llms.txt, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /openapi.json, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /swagger.json, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /api-docs, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - host: https://kreditbee.in role: apex (serves the same SPA) documents: - {path: /.well-known/security.txt, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /.well-known/agent-card.json, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /.well-known/agent.json, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /.well-known/openid-configuration, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /llms.txt, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - {path: /openapi.json, status: 200, content_type: text/html, valid: false, note: SPA catch-all shell — rejected} - host: https://api.kreditbee.in role: private mobile/web backend (AWS API Gateway behind Cloudflare) documents: - {path: /, status: 403, content_type: application/json, valid: false, note: '{"message":"Forbidden"} with x-amzn-errortype ForbiddenException'} - {path: /.well-known/security.txt, status: 403, valid: false} - {path: /.well-known/agent-card.json, status: 403, valid: false} - {path: /.well-known/agent.json, status: 403, valid: false} - {path: /.well-known/openid-configuration, status: 403, valid: false} - {path: /.well-known/oauth-authorization-server, status: 403, valid: false} - {path: /.well-known/api-catalog, status: 403, valid: false} - {path: /.well-known/ai-plugin.json, status: 403, valid: false} - {path: /llms.txt, status: 403, valid: false} - {path: /openapi.json, status: 403, valid: false} - {path: /swagger.json, status: 403, valid: false} - {path: /v2/api-docs, status: 404, valid: false} - {path: /robots.txt, status: 403, valid: false} - host: https://dsa.kreditbee.in role: DSA (direct selling agent) admin console documents: - {path: /openapi.json, status: 200, content_type: text/html, valid: false, note: 'SPA catch-all shell (