generated: '2026-09-19' method: searched source: live probe of /.well-known/ on every Larridin host in apis.yml + OpenAPI servers[] notes: Only https://app.larridin.com/ serves real .well-known documents, and only the two OAuth metadata documents that back the beta MCP server. The remaining paths on that host return HTTP 200 with the application's SPA HTML shell rather than a discovery document, so they are recorded as not present. hosts: - host: https://app.larridin.com documents: - path: /.well-known/oauth-authorization-server standard: RFC 8414 status: 200 content_type: application/json file: larridin-oauth-authorization-server.json - path: /.well-known/oauth-protected-resource standard: RFC 9728 status: 200 content_type: application/json file: larridin-oauth-protected-resource.json - path: /.well-known/security.txt standard: RFC 9116 status: 200 present: false note: returns the SPA HTML shell, not an RFC 9116 document - path: /.well-known/openid-configuration status: 200 present: false note: returns the SPA HTML shell, not OIDC discovery metadata - path: /.well-known/api-catalog standard: RFC 9727 status: 200 present: false note: returns the SPA HTML shell, not an api-catalog document - path: /.well-known/ai-plugin.json status: 200 present: false note: returns the SPA HTML shell - host: https://larridin.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://scout-api.larridin.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://docs.larridin.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://login.larridin.com documents: - path: /.well-known/oauth-authorization-server status: 200 file: larridin-login-oauth-authorization-server.json bytes: 883 path_echo_control: passed x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://login.larridin.com path: /.well-known/oauth-authorization-server file: larridin-login-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host note: 'MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.'