generated: '2026-09-19' method: probed source: probed /.well-known/ on the Signal AI API, MCP, auth and marketing hosts notes: 'Signal AI serves NO /.well-known/ document from its API host or its marketing host — every path 404s there. The real well-known surface is on the MCP host: https://mcp.signal-ai.com serves both RFC 9728 OAuth protected-resource metadata and RFC 8414 authorization-server metadata anonymously, and answers an unauthenticated MCP call with a spec-correct `WWW-Authenticate: Bearer resource_metadata=...` challenge pointing at that document. The auth host (Keycloak) serves standard OIDC discovery.' hosts: - host: https://mcp.signal-ai.com documents: - path: /.well-known/oauth-protected-resource status: 200 content_type: application/json file: signal-ai-oauth-protected-resource.json note: RFC 9728. Declares resource https://mcp.signal-ai.com, authorization server https://login.signal-ai.com/auth/realms/signal, and scopes_supported [openid, mcp:tools, offline_access]. - path: /.well-known/oauth-authorization-server status: 200 content_type: application/json file: signal-ai-oauth-authorization-server.json note: RFC 8414. Keycloak realm `signal`; grant types include client_credentials and authorization_code with PKCE (S256). - path: /.well-known/agent-card.json status: 401 note: Not an A2A agent card — the host's blanket JWT gate answers every unmatched path with {"error":"Jwt is missing"}. No agent card asserted. - host: https://login.signal-ai.com documents: - path: /auth/realms/signal/.well-known/openid-configuration status: 200 file: signal-ai-openid-configuration.json note: Keycloak realm OIDC discovery backing the OAuth2 client-credentials flow. - path: /.well-known/oauth-authorization-server/auth/realms/signal status: 200 file: signal-ai-login-oauth-authorization-server.json bytes: 6909 path_echo_control: passed - host: https://api.signal-ai.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /llms.txt status: 404 - path: /openapi.json status: 200 content_type: application/json file: ../openapi/_original/signal-ai-openapi-original.json note: The API self-publishes its full OpenAPI 3.1.0 at the host root instead of under /.well-known/. - host: https://signal-ai.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /llms.txt status: 200 content_type: text/plain file: ../llms/signal-ai-llms.txt note: Provider-published llms.txt, saved verbatim. Not a /.well-known/ path but recorded here as part of the same discovery sweep. x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://login.signal-ai.com path: /.well-known/oauth-authorization-server/auth/realms/signal file: signal-ai-login-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host note: 'MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.'