generated: '2026-08-04' method: probed source: live GET probes of the /.well-known/ surface on every LIVEKINDLY host, 2026-08-04 host: https://thelivekindlyco.com note: 'LIVEKINDLY serves two real /.well-known/ discovery documents, and both exist only because the site runs the WordPress MCP Adapter: an RFC 8414 OAuth 2.0 authorization-server metadata document at the site root, and the RFC 9728 protected-resource document that points at the MCP endpoint. That is an unusually complete OAuth discovery surface for a corporate marketing site and is the single most interesting machine-readable thing LIVEKINDLY publishes. Everything else below returned the WordPress/Sucuri 404 page, including both agent-card paths and security.txt. Absence is recorded as observed; nothing was authored on LIVEKINDLY''s behalf.' hosts_probed: - host: thelivekindlyco.com resolves: true primary: true - host: www.thelivekindlyco.com resolves: true note: same origin, identical results on every path - host: livekindly.com resolves: true note: A separate plant-based lifestyle media property, not the Collective's corporate site. Probed for completeness — every /.well-known/ path returned 404, including oauth-authorization-server. - host: api.thelivekindlyco.com resolves: false note: NXDOMAIN — no API host - host: docs.thelivekindlyco.com resolves: false note: NXDOMAIN — no docs host adjacent_discovery_found: - path: /wp-json/ status: 200 content_type: application/json note: The WordPress REST route-discovery document — 307 routes across 21 registered namespaces. This is the real machine-readable contract on thelivekindlyco.com and is the source the OpenAPI in openapi/ was derived from. Saved verbatim at openapi/_source/livekindly-wp-json-root.json. - path: /wp-json/mcp status: 200 content_type: application/json note: The MCP namespace index, listing mcp-adapter-default-server and mcp-oauth-server. See mcp/livekindly-mcp.yml. - path: /robots.txt status: 200 note: 'Yoast-generated. "User-agent: * / Disallow:" — nothing is disallowed, and no AI crawler is named either way. Points at the sitemap index.' - path: /sitemap_index.xml status: 200 note: Yoast sitemap index — post, page, job and category sitemaps. No brand or partner sitemap is emitted even though both are public custom post types in the REST API. - path: /llms.txt status: 404 note: Not published. The file in llms/ was GENERATED by API Evangelist from this repo's artifacts, not harvested — see its provenance header. - path: /feed/ status: 404 note: The site's RSS feeds are disabled; the newsroom is only readable as JSON via wp/v2. hosts: - host: https://thelivekindlyco.com documents: - path: /.well-known/oauth-authorization-server status: 200 file: livekindly-oauth-authorization-server.json content_type: application/json note: 'Real authorization-server metadata — issuer https://thelivekindlyco.com, authorization/token/ revocation endpoints under /oauth/, response_types [code], grant_types [authorization_code, refresh_token], PKCE S256 required, token_endpoint_auth_methods [none] (public clients), and client_id_metadata_document_supported: true. scopes_supported is the single scope "mcp".' - path: /.well-known/oauth-protected-resource status: 200 file: livekindly-oauth-protected-resource.json content_type: application/json note: Names https://thelivekindlyco.com/wp-json/mcp/mcp-oauth-server as the protected resource, thelivekindlyco.com as its authorization server, header bearer methods, scope "mcp". - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 note: OAuth 2.0 only — no OIDC layer is advertised. - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.