generated: '2026-09-19' method: searched source: live probes of openworklabs.com and api.openworklabs.com endpoints: - path: /.well-known/api-catalog host: https://openworklabs.com status: 200 file: openwork-api-catalog.json note: RFC 9727 linkset pointing at the Den API OpenAPI, docs, health, and llms.txt. - path: /.well-known/oauth-authorization-server host: https://api.openworklabs.com status: 200 file: openwork-oauth-authorization-server.json note: RFC 8414 OAuth 2.0 authorization server metadata (issuer app.openworklabs.com/api/auth). - path: /.well-known/openid-configuration host: https://api.openworklabs.com status: 200 file: openwork-openid-configuration.json note: OpenID Connect discovery document. - path: /.well-known/oauth-protected-resource host: https://api.openworklabs.com status: 200 file: openwork-oauth-protected-resource.json note: RFC 9728 protected-resource metadata for the MCP endpoint (scopes mcp:read, mcp:write, offline_access). - path: /.well-known/security.txt host: https://openworklabs.com status: 404 file: null - path: /.well-known/security.txt host: https://api.openworklabs.com status: 404 file: null - path: /.well-known/ai-plugin.json host: https://openworklabs.com status: 404 file: null - path: /llms.txt host: https://openworklabs.com status: 200 file: ../llms/openwork-llms.txt hosts: - host: '' documents: - path: /.well-known/api-catalog status: 200 file: openwork-api-catalog.json note: RFC 9727 linkset pointing at the Den API OpenAPI, docs, health, and llms.txt. - path: /.well-known/oauth-authorization-server status: 200 file: openwork-oauth-authorization-server.json note: RFC 8414 OAuth 2.0 authorization server metadata (issuer app.openworklabs.com/api/auth). - path: /.well-known/openid-configuration status: 200 file: openwork-openid-configuration.json note: OpenID Connect discovery document. - path: /.well-known/oauth-protected-resource status: 200 file: openwork-oauth-protected-resource.json note: RFC 9728 protected-resource metadata for the MCP endpoint (scopes mcp:read, mcp:write, offline_access). - host: https://api.openworklabs.com documents: - path: /.well-known/oauth-protected-resource status: 200 file: openwork-api-oauth-protected-resource.json bytes: 218 path_echo_control: passed - host: https://app.openworklabs.com documents: - path: /api/auth/.well-known/oauth-authorization-server status: 200 file: openwork-app-oauth-authorization-server.json bytes: 2383 path_echo_control: passed x-shape-fix: converted: '2026-08-20' from: endpoints note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent. Promoted ONLY the 2xx rows out of the probe log; non-2xx probes are real negative results and were left in place, not converted into documents. x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://api.openworklabs.com path: /.well-known/oauth-protected-resource file: openwork-api-oauth-protected-resource.json - host: https://app.openworklabs.com path: /api/auth/.well-known/oauth-authorization-server file: openwork-app-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host note: 'MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.'