generated: '2026-09-19' method: probed source: >- Live GET probes of the named /.well-known/* path list on merchant-0.com, api.merchant-0.com and www.merchant-0.com, 2026-09-19. Every row below is a request that was actually issued; every status is the one returned. summary: hosts_probed: 3 paths_probed: 46 documents_served: 5 hit_count: 5 path_echo_control: passed note: >- Merchant-0 serves four discovery documents on the apex and one on the API host: the A2A agent card at /.well-known/agent-card.json, a second older AP2-shaped card at the legacy /.well-known/agent.json, a W3C DID document at /.well-known/did.json (the did:web resolution location for did:web:merchant-0.com), and a UCP manifest at the non-standard path /.well-known/ucp-manifest.json on BOTH hosts (the API host's copy is generated by the FastAPI route get_ucp_manifest__well_known_ucp_manifest_json_get and carries a fresh created_at timestamp on every request). Nothing else: no security.txt, no OAuth/OIDC discovery, no RFC 9727 API catalog, no APIs.json, no AAuth resource document, no ai-plugin, no ucp.json/acp.json at the paths those specs define, no MCP server card. The apex answers every miss with a real Next.js 404 page (HTTP 404, ~11 KB HTML titled "404: This page could not be found."), the API host with {"detail":"Not Found"} (22 bytes, application/json), and a negative-control path 404s on both, so every 200 above is a served document. www.merchant-0.com does not exist in DNS. There is no MCP server host (no MCP-protocol endpoint exists — see mcp/), so the RFC 9728 protected-resource probe on the API host stands in for it (404). The UCP manifest's capability endpoints and contact addresses name merchant0.com (no hyphen), which does not resolve. hosts: - host: merchant-0.com role: Website (Next.js "Command Center"), DID / agent-card / UCP-manifest host documents: - path: /.well-known/agent-card.json status: 200 content_type: application/json; charset=UTF-8 bytes: 10318 file: ../a2a/merchant-0-com-agent-card.json standard: A2A Agent Card (no protocolVersion; graded flavored in a2a/merchant-0-com-a2a.yml) - path: /.well-known/agent.json status: 200 content_type: application/json bytes: 1770 file: ../a2a/merchant-0-com-agent-card-legacy.json standard: Legacy pre-0.3 agent-card path; an AP2-shaped discovery document, not an A2A card - path: /.well-known/did.json status: 200 content_type: application/json bytes: 463 file: merchant-0-com-did.json standard: W3C DID Core document, did:web method (id did:web:merchant-0.com, Ed25519VerificationKey2020 #key-1, authentication + assertionMethod) - path: /.well-known/ucp-manifest.json status: 200 content_type: application/json bytes: 2600 file: merchant-0-com-ucp-manifest.json standard: UCP manifest (ucp_version 2026.1, manifest_version 1.0.0, eight dev.ucp.* capabilities) note: Non-standard path. The endpoints inside point at https://merchant0.com/... (NXDOMAIN) and contact.api_docs at https://merchant0.com/api/docs. - path: /.well-known/security.txt status: 404 - path: /security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/api-catalog.json status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/ucp.json status: 404 note: The UCP-defined discovery path is not served; the provider's manifest sits at /.well-known/ucp-manifest.json instead. - path: /.well-known/acp.json status: 404 - path: /.well-known/aauth-resource.json status: 404 - path: /.well-known/apis.json status: 404 - path: /apis.json status: 404 - path: /apis.yml status: 404 - path: /.well-known/mcp.json status: 404 - path: /.well-known/mcp/server-card.json status: 404 - path: /llms.txt status: 404 - path: /robots.txt status: 404 - path: /.well-known/apievangelist-negative-control-7f3a9c.json status: 404 control: negative note: A path that cannot exist. Its 404 (a real Next.js 404 page) proves the host does not catch-all /.well-known/* requests. - host: api.merchant-0.com role: API host (OpenAPI servers[] / apis.yml baseURL; the agent card's url and agent_api); FastAPI behind nginx documents: - path: /.well-known/ucp-manifest.json status: 200 content_type: application/json bytes: 2602 file: merchant-0-com-ucp-manifest.json note: Identical to the apex copy apart from the created_at/last_updated timestamps, which are regenerated per request. Declared in the OpenAPI as operation get_ucp_manifest__well_known_ucp_manifest_json_get. - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/did.json status: 404 - path: /.well-known/security.txt status: 404 - path: /security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/oauth-protected-resource status: 404 note: No MCP server host exists; this row is the RFC 9728 probe for the only API resource host. - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/ucp.json status: 404 - path: /.well-known/acp.json status: 404 - path: /.well-known/aauth-resource.json status: 404 - path: /.well-known/apis.json status: 404 - path: /apis.json status: 404 - path: /apis.yml status: 404 - path: /.well-known/mcp.json status: 404 - path: /.well-known/mcp/server-card.json status: 404 - path: /llms.txt status: 404 - path: /.well-known/apievangelist-negative-control-7f3a9c.json status: 404 control: negative note: Real JSON 404 ({"detail":"Not Found"}), the same body every unknown path returns. - host: www.merchant-0.com role: Does not exist — NXDOMAIN documents: - path: /.well-known/agent-card.json status: 0 note: DNS resolution failed (no A/CNAME record). No www alias is published. - path: /.well-known/security.txt status: 0 note: NXDOMAIN.