generated: '2026-07-24' method: searched source: https://www.nhs.uk/.well-known/security.txt note: >- The NHS runtime API platform host (api.service.nhs.uk) returns 404 for every /.well-known/ discovery path (it is a bare API gateway, not a docs origin) and the developer portal (digital.nhs.uk) returns 403 to automated clients (Akamai bot mitigation). The one discovery document that resolves anonymously is the RFC 9116 security.txt on the canonical nhs.uk host, saved verbatim below. hosts: - host: https://www.nhs.uk documents: - path: /.well-known/security.txt status: 200 file: nhs-england-security.txt - host: https://api.service.nhs.uk documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://digital.nhs.uk documents: - path: /.well-known/security.txt status: 403 note: Akamai bot mitigation; browser-reachable, 403 to automated clients.