generated: '2026-09-19' method: probed source: https://leadpages.com/.well-known/ host: https://leadpages.com summary: probed: 7 hits: 3 note: 'Three real documents are served: RFC 8414 OAuth authorization-server metadata, RFC 9728 OAuth protected-resource metadata, and an A2A agent card. No security.txt and no api-catalog. The 404 responses return the site''s HTML 404 page, not an empty body.' other_hosts: - host: https://mcp.leadpages.com note: MCP endpoint host. Resolves to the same Cloudflare origin as leadpages.com; the OAuth protected-resource document names https://leadpages.com as the single authorization server, so discovery is centralized on the apex. - host: https://api.leadpages.com note: The REST base URL published in the developer docs. DNS resolves to ghs.googlehosted.com but the host does not complete a TLS handshake (curl error 35), so no /.well-known/ probe was possible. See lifecycle/leadpages-lifecycle.yml. x-evidence: fetched: '2026-08-12' probes: - url: https://leadpages.com/.well-known/oauth-authorization-server status: 200 - url: https://leadpages.com/.well-known/oauth-protected-resource status: 200 - url: https://leadpages.com/.well-known/agent-card.json status: 200 - url: https://leadpages.com/.well-known/security.txt status: 404 - url: https://leadpages.com/.well-known/openid-configuration status: 404 - url: https://leadpages.com/.well-known/api-catalog status: 404 - url: https://leadpages.com/.well-known/ai-plugin.json status: 404 hosts: - host: https://leadpages.com documents: - path: /.well-known/oauth-authorization-server status: 200 file: leadpages-oauth-authorization-server.json standard: RFC 8414 content_type: application/json - path: /.well-known/oauth-protected-resource status: 200 file: leadpages-oauth-protected-resource.json standard: RFC 9728 content_type: application/json - path: /.well-known/agent-card.json status: 200 file: ../a2a/leadpages-agent-card.json standard: A2A 1.0.0 content_type: application/json - path: /.well-known/security.txt status: 404 standard: RFC 9116 note: Not served. A responsible-disclosure program IS published in HTML at https://leadpages.com/security with a security@leadpages.com contact — it is simply not mirrored to the machine-readable RFC 9116 location. - path: /.well-known/openid-configuration status: 404 standard: OpenID Connect Discovery - path: /.well-known/api-catalog status: 404 standard: RFC 9727 - path: /.well-known/ai-plugin.json status: 404 standard: OpenAI plugin manifest (deprecated) - path: /.well-known/agent.json status: 404 standard: A2A pre-0.3 legacy path note: Card is served at the canonical /.well-known/agent-card.json path instead. - host: https://mcp.leadpages.com documents: - path: /.well-known/oauth-protected-resource status: 200 file: leadpages-mcp-oauth-protected-resource.json bytes: 325 - path: /.well-known/oauth-authorization-server status: 200 file: leadpages-mcp-oauth-authorization-server.json bytes: 700 path_echo_control: passed x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent. x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://mcp.leadpages.com path: /.well-known/oauth-protected-resource file: leadpages-mcp-oauth-protected-resource.json - host: https://mcp.leadpages.com path: /.well-known/oauth-authorization-server file: leadpages-mcp-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host note: 'MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.'