generated: '2026-09-19' method: searched source: live probe of /.well-known/* on Monid API + MCP hosts host: https://api.monid.ai other_hosts: - host: https://mcp.monid.ai note: The hosted MCP server exposes the same anonymous OAuth discovery surface (/.well-known/openid-configuration, /.well-known/oauth-authorization-server, /.well-known/oauth-protected-resource all 200) so MCP clients can perform the OAuth 2.0 authorization-code + PKCE handshake automatically. - host: https://monid.ai note: Marketing/registry host — no /.well-known/* documents (all 404). notes: OAuth authorization + token endpoints are Clerk-hosted (https://clerk.app.monid.ai/oauth/authorize + /oauth/token); the issuer is https://api.monid.ai and the protected resource is https://api.monid.ai/v1. hosts: - host: https://api.monid.ai documents: - path: /.well-known/openid-configuration status: 200 file: monid-openid-configuration.json - path: /.well-known/oauth-authorization-server status: 200 file: monid-oauth-authorization-server.json - path: /.well-known/oauth-protected-resource status: 200 file: monid-oauth-protected-resource.json - path: /.well-known/security.txt status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://mcp.monid.ai documents: - path: /.well-known/oauth-protected-resource status: 200 file: monid-mcp-oauth-protected-resource.json bytes: 822 path_echo_control: passed - host: https://clerk.app.monid.ai documents: - path: /.well-known/oauth-authorization-server status: 200 file: monid-clerk-oauth-authorization-server.json bytes: 1224 path_echo_control: passed x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent. x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://mcp.monid.ai path: /.well-known/oauth-protected-resource file: monid-mcp-oauth-protected-resource.json - host: https://clerk.app.monid.ai path: /.well-known/oauth-authorization-server file: monid-clerk-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host note: 'MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.'