generated: '2026-09-19' method: probed source: >- Live GET probes of the named /.well-known/* path list on rettfrabonden.com, www.rettfrabonden.com and lokal.fly.dev on 2026-09-19. Every row below is a request that was actually issued; every status is the one returned. www.rettfrabonden.com 301s every path to the apex, so it is recorded as a redirecting host with no documents of its own. summary: hosts_probed: 3 paths_probed: 40 documents_served: 10 path_echo_control: passed note: >- rettfrabonden.com serves an RFC 9727 API catalog linkset, RFC 9728 protected-resource metadata (with an EMPTY authorization_servers list — the resource is API-key protected, not OAuth), an OpenAI ai-plugin manifest, an A2A agent card at both the canonical and legacy paths, an MCP server card (SEP-1649 shape) plus a /.well-known/mcp endpoint manifest, an agentskills.io v0.2.0 skills index, and a dennj/agents.txt discovery file. It serves NO security.txt, NO OpenID or OAuth authorization-server metadata, NO apis.json and NO UCP/ACP/AAuth documents. The negative control (a path that cannot exist) returned a real 404 on both serving hosts, so every 200 here is a document the host actually routes, not a catch-all. mcp_host_note: >- The MCP server lives on the primary domain (https://rettfrabonden.com/mcp), so the MCP host and the registrable domain are the same host; there is no separate mcp. to probe. The RFC 9728 document names resource https://rettfrabonden.com and resource_documentation /teknologi. hosts: - host: rettfrabonden.com role: Primary domain — website, REST API base, MCP endpoint and A2A endpoint all on one host path_echo_control: path: /.well-known/rfb-negative-control-7f3ab91c.json status: 404 result: passed documents: - path: /.well-known/security.txt status: 404 standard: RFC 9116 - path: /.well-known/openid-configuration status: 404 standard: OpenID Connect Discovery 1.0 - path: /.well-known/oauth-authorization-server status: 404 standard: RFC 8414 - path: /.well-known/oauth-protected-resource status: 200 content_type: application/json; charset=utf-8 file: rettfrabonden-com-oauth-protected-resource.json standard: RFC 9728 note: >- resource https://rettfrabonden.com, resource_name "Lokal A2A Marketplace", authorization_servers [] (empty), bearer_methods_supported [header], scopes_supported [read, write], plus vendor x-auth-* fields naming X-API-Key as the credential and /api/marketplace/register as where to obtain it. A protected-resource document with no authorization server: the shape is RFC 9728, the auth model is API key. - path: /.well-known/api-catalog status: 200 content_type: application/linkset+json; charset=utf-8 file: rettfrabonden-com-api-catalog.json standard: RFC 9727 note: >- Linkset with three anchors: the site root (service-desc -> /openapi.yaml, service-doc -> /teknologi, service-meta -> agent card, MCP server card, agent-skills index), /a2a (service-desc -> agent card) and /mcp (service-desc -> MCP server card). The title says "OpenAPI 3.0" for a document that is openapi: 3.1.0. - path: /.well-known/api-catalog.json status: 404 note: only the extensionless RFC 9727 path is served - path: /.well-known/ai-plugin.json status: 200 content_type: application/json; charset=utf-8 file: rettfrabonden-com-ai-plugin.json standard: OpenAI plugin manifest v1 note: auth type none; api.url -> /openapi.json; contact_email hello@rettfrabonden.com; legal_info_url /terms. - path: /.well-known/ucp.json status: 404 standard: UCP - path: /.well-known/acp.json status: 404 standard: ACP note: >- No agentic-commerce well-known document. The provider does publish an ACP-conformant PRODUCT FEED (CSV, discovery-only, no checkout) at /api/marketplace/catalog/acp-feed.csv — recorded in conformance/ — but that is not the well-known document this row probes. - path: /.well-known/aauth-resource.json status: 404 standard: AAuth (draft-hardt-oauth-aauth-protocol) - path: /.well-known/apis.json status: 404 standard: APIs.json - path: /apis.json status: 404 standard: APIs.json - path: /apis.yml status: 404 standard: APIs.json (YAML) - path: /.well-known/agent-card.json status: 200 content_type: application/json; charset=utf-8 file: ../a2a/rettfrabonden-com-agent-card.json standard: A2A 1.0.0 Agent Card note: Saved verbatim under a2a/ and graded in a2a/rettfrabonden-com-a2a.yml (conformant). - path: /.well-known/agent.json status: 200 content_type: application/json; charset=utf-8 file: ../a2a/rettfrabonden-com-agent-card.json standard: A2A pre-0.3 legacy card path note: byte-identical to the canonical card - path: /.well-known/mcp/server-card.json status: 200 content_type: application/json; charset=utf-8 file: rettfrabonden-com-mcp-server-card.json standard: MCP Server Card (SEP-1649 shape, schemaVersion 2025-11) note: >- Also served byte-identical at /.well-known/mcp.json. Names the endpoint https://rettfrabonden.com/mcp, transports http/streamable-http, supported protocol versions 2025-11-25 back to 2024-10-07, and states explicitly that the 2026-07-28 era (per-request _meta, server/discover) is NOT supported. Its five listed tool names (search_producers, discover_by_category, get_producer, register_producer, start_negotiation) do NOT match the fifteen the live server returns from tools/list (lokal_search, lokal_discover, ...) — see mcp/rettfrabonden-com-mcp.yml. - path: /.well-known/mcp.json status: 200 content_type: application/json; charset=utf-8 file: rettfrabonden-com-mcp-server-card.json note: byte-identical to /.well-known/mcp/server-card.json - path: /.well-known/mcp status: 200 content_type: application/json; charset=utf-8 file: rettfrabonden-com-mcp.json standard: MCP endpoint manifest (non-standard, vendor shape) note: mcp_version 2025-11-25, one streamable-http endpoint at /mcp with capabilities [tools, resources]. - path: /.well-known/agent-skills/index.json status: 200 content_type: application/json; charset=utf-8 file: rettfrabonden-com-agent-skills-index.json standard: agentskills.io index schema v0.2.0 note: >- Four skills with per-skill invocation blocks (mcp / a2a / rest). Also served byte-identical at /.well-known/skills/index.json. The invocation.mcp.tool names reference the phantom server-card tool names, not the live lokal_* tools. - path: /.well-known/skills/index.json status: 200 content_type: application/json; charset=utf-8 file: rettfrabonden-com-agent-skills-index.json note: byte-identical to /.well-known/agent-skills/index.json - path: /.well-known/agents.txt status: 200 content_type: text/plain; charset=utf-8 file: rettfrabonden-com-agents.txt standard: agents.txt (github.com/dennj/agents.txt) note: Allow-actions search/read/discover/compare; Disallow-actions modify/delete/register-without-key; names the card, MCP, A2A and REST endpoints and both rate limits. - path: /robots.txt status: 200 content_type: text/plain; charset=utf-8 file: rettfrabonden-com-robots.txt standard: robots.txt with Content-Signal (search=yes, ai-input=yes, ai-train=no) note: >- Not a /.well-known/ path; saved here because it carries the provider's machine-readable AI usage preference (Content-Signal on the * group and on each named AI crawler group) and names every discovery endpoint. CCBot and Omgilibot are the only crawlers disallowed outright. - host: www.rettfrabonden.com role: Redirecting alias — every probed path 301s to the same path on rettfrabonden.com documents: - path: /.well-known/security.txt status: 301 - path: /.well-known/openid-configuration status: 301 - path: /.well-known/oauth-authorization-server status: 301 - path: /.well-known/oauth-protected-resource status: 301 - path: /.well-known/api-catalog status: 301 - path: /.well-known/ai-plugin.json status: 301 - path: /.well-known/agent-card.json status: 301 - path: /.well-known/apis.json status: 301 - path: /apis.json status: 301 - host: lokal.fly.dev role: Fly.io origin of the same application (named as wellKnownURI by the a2aregistry.org entry); serves the identical documents path_echo_control: path: /.well-known/rfb-negative-control-7f3ab91c.json status: 404 result: passed documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/oauth-protected-resource status: 200 content_type: application/json; charset=utf-8 file: rettfrabonden-com-oauth-protected-resource.json note: byte-identical to the rettfrabonden.com document (resource still declares https://rettfrabonden.com) - path: /.well-known/api-catalog status: 200 content_type: application/linkset+json; charset=utf-8 file: rettfrabonden-com-api-catalog.json note: byte-identical to the rettfrabonden.com document - path: /.well-known/ai-plugin.json status: 200 content_type: application/json; charset=utf-8 file: rettfrabonden-com-ai-plugin.json note: byte-identical - path: /.well-known/agent-card.json status: 200 content_type: application/json; charset=utf-8 file: ../a2a/rettfrabonden-com-agent-card.json note: byte-identical - path: /.well-known/ucp.json status: 404 - path: /.well-known/acp.json status: 404 - path: /.well-known/aauth-resource.json status: 404 - path: /.well-known/apis.json status: 404 - path: /apis.json status: 404 - path: /apis.yml status: 404