generated: '2026-09-19' method: probed description: >- Results of probing the closed /.well-known/ path list on every host the record knows: the registrable domain smklog.com (the human site, also the host the A2A registry points at), www.smklog.com (a 301 to the apex on every path), and quote-api.smklog.com (the OpenAPI servers[] host, the MCP endpoint host, the A2A JSON-RPC host and the OAuth issuer named in authorization_servers — one host plays all four roles). smklog.com answers a real HTML 404 page (5,958 bytes) for unknown paths and quote-api answers a 30-byte JSON method_not_allowed body, so every miss below is a real miss; the negative-control path returned 404 / 405 on both hosts. Real documents served: security.txt (RFC 9116), RFC 8414 OAuth authorization-server metadata and RFC 9728 protected-resource metadata on both hosts (the quote-api copies are richer — an agent_auth block and an explicit authorization_required false), an RFC 9727 api-catalog linkset (identical on both hosts), the A2A agent card (identical on both hosts, indexed in a2a/), an MCP server card at /.well-known/mcp/server-card.json and an agentskills.io discovery index at /.well-known/agent-skills/index.json on the API host. No openid-configuration, ai-plugin, UCP/ACP/AAuth, mcp.json/mcp-server.json or apis.json anywhere. path_echo_control: passed hosts: - host: https://smklog.com documents: - {path: /.well-known/security.txt, status: 200, type: text/plain, file: smklog-com-security.txt, note: 'Contact mailto:info@smklog.com, Expires 2027-07-29, Canonical set; the comment block states no bug bounty is run'} - {path: /.well-known/openid-configuration, status: 404} - {path: /.well-known/oauth-authorization-server, status: 200, type: application/json, file: smklog-com-oauth-authorization-server.json, note: 'RFC 8414; issuer https://quote-api.smklog.com, client_credentials only, scope quote, registration_instructions https://smklog.com/auth.md'} - {path: /.well-known/oauth-protected-resource, status: 200, type: application/json, file: smklog-com-oauth-protected-resource.json, note: 'RFC 9728; resource https://smklog.com, authorization_servers [https://quote-api.smklog.com], bearer header'} - {path: /.well-known/oauth-protected-resource/mcp, status: 404} - {path: /.well-known/api-catalog, status: 200, type: 'application/linkset+json; profile="https://www.rfc-editor.org/info/rfc9727"', file: smklog-com-api-catalog.json, note: 'RFC 9727 linkset: anchor https://quote-api.smklog.com/, service-desc openapi.json (application/openapi+json), service-doc https://smklog.com/api, status https://quote-api.smklog.com/status'} - {path: /.well-known/api-catalog.json, status: 404} - {path: /.well-known/ai-plugin.json, status: 404} - {path: /.well-known/ucp.json, status: 404} - {path: /.well-known/acp.json, status: 404} - {path: /.well-known/aauth-resource.json, status: 404} - {path: /.well-known/apis.json, status: 404} - {path: /apis.json, status: 404} - {path: /apis.yml, status: 404} - {path: /.well-known/mcp.json, status: 404} - {path: /.well-known/mcp-server.json, status: 404} - {path: /.well-known/agent-card.json, status: 200, type: application/json, file: ../a2a/smklog-com-agent-card.json, note: 'A2A card "SMKlog Parcel Quotes" 1.4.0; the a2aregistry.org listing points here'} - {path: /.well-known/agent.json, status: 404} - {path: /.well-known/smklog-com-negative-control-9f2c7a1e.json, status: 404, note: negative control — the host does not echo unknown well-known paths} - {path: /llms.txt, status: 200, type: text/plain, file: ../llms/smklog-com-llms.txt} - {path: /robots.txt, status: 200, type: text/plain, note: 'Content-Signal: search=yes, ai-input=yes, ai-train=yes, use=reference (owner decision dated 2026-08-07 in the file); internal screens disallowed; Sitemap declared'} - host: https://www.smklog.com documents: - {path: /.well-known/security.txt, status: 301, redirect: https://smklog.com/.well-known/security.txt} - {path: /.well-known/openid-configuration, status: 301, redirect: https://smklog.com/.well-known/openid-configuration} - {path: /.well-known/oauth-authorization-server, status: 301, redirect: https://smklog.com/.well-known/oauth-authorization-server} - {path: /.well-known/oauth-protected-resource, status: 301, redirect: https://smklog.com/.well-known/oauth-protected-resource} - {path: /.well-known/api-catalog, status: 301, redirect: https://smklog.com/.well-known/api-catalog} - {path: /.well-known/ai-plugin.json, status: 301, redirect: https://smklog.com/.well-known/ai-plugin.json} - {path: /.well-known/ucp.json, status: 301, redirect: https://smklog.com/.well-known/ucp.json} - {path: /.well-known/acp.json, status: 301, redirect: https://smklog.com/.well-known/acp.json} - {path: /.well-known/aauth-resource.json, status: 301, redirect: https://smklog.com/.well-known/aauth-resource.json} - {path: /.well-known/apis.json, status: 301, redirect: https://smklog.com/.well-known/apis.json} - {path: /apis.json, status: 301, redirect: https://smklog.com/apis.json} - {path: /apis.yml, status: 301, redirect: https://smklog.com/apis.yml} - {path: /.well-known/agent-card.json, status: 301, redirect: https://smklog.com/.well-known/agent-card.json, note: the harvest record cited the www form; it resolves to the apex card} - {path: /.well-known/agent.json, status: 301, redirect: https://smklog.com/.well-known/agent.json} - host: https://quote-api.smklog.com documents: - {path: /.well-known/security.txt, status: 405, note: 'JSON {"error":"method_not_allowed"} — the API host does not serve one; the apex copy names smklog.com as Canonical'} - {path: /.well-known/openid-configuration, status: 405} - {path: /.well-known/oauth-authorization-server, status: 200, type: application/json, file: smklog-com-quote-api-oauth-authorization-server.json, note: 'RFC 8414 plus a non-standard agent_auth block (register_uri mailto:info@smklog.com, registration_methods [manual_email], identity_types_supported [service], credential_types_supported [client_secret])'} - {path: /.well-known/oauth-protected-resource, status: 200, type: application/json, file: smklog-com-quote-api-oauth-protected-resource.json, note: 'RFC 9728; resource https://quote-api.smklog.com, authorization_required false — "Quoting, tracking and the price index are open with no token. Credentials only raise the per-client rate limit"'} - {path: /.well-known/oauth-protected-resource/mcp, status: 405} - {path: /.well-known/api-catalog, status: 200, type: 'application/linkset+json; profile="https://www.rfc-editor.org/info/rfc9727"', file: smklog-com-api-catalog.json, note: byte-identical to the apex copy} - {path: /.well-known/api-catalog.json, status: 405} - {path: /.well-known/ai-plugin.json, status: 405} - {path: /.well-known/ucp.json, status: 405} - {path: /.well-known/acp.json, status: 405} - {path: /.well-known/aauth-resource.json, status: 405} - {path: /.well-known/apis.json, status: 405} - {path: /apis.json, status: 405} - {path: /apis.yml, status: 405} - {path: /.well-known/mcp.json, status: 405} - {path: /.well-known/mcp-server.json, status: 405} - {path: /.well-known/mcp/server-card.json, status: 200, type: application/json, file: smklog-com-mcp-server-card.json, note: 'MCP server card: name com.smklog/parcel-shipping-rates 1.4.0, transport streamable-http endpoint https://quote-api.smklog.com/mcp, protocolVersions [2026-07-28, 2025-06-18, 2025-03-26], authentication.required false, five tools, links to the MCP registry, docs and openapi'} - {path: /.well-known/agent-skills/index.json, status: 200, type: application/json, file: smklog-com-agent-skills-index.json, note: 'agentskills.io discovery 0.2.0 index: two skill-md entries (get-parcel-quote, create-checkout-link) with sha256 digests; the SKILL.md files are saved verbatim in skills/'} - {path: /.well-known/agent-card.json, status: 200, type: application/json, note: byte-identical (2,643 bytes) to the apex card indexed in a2a/} - {path: /.well-known/agent.json, status: 405} - {path: /.well-known/smklog-com-negative-control-9f2c7a1e.json, status: 405, note: negative control — unknown paths answer 405 JSON, never a document} - {path: /llms.txt, status: 405, note: the llms.txt lives on the apex} - {path: /robots.txt, status: 200, type: text/plain, note: 'Content-Signal: search=no, ai-input=yes, ai-train=yes, use=reference; Allow /$, /.well-known/, /openapi.json, /auth.md, /status; Disallow / — the API zone is deliberately discoverable but not indexable'} notes: - 'The apex root document https://quote-api.smklog.com/ (200, application/json) is itself a discovery index: service smklog-quote-api 1.4.0 with links to openapi, api_catalog, mcp, mcp_server_card, a2a_agent_card, agent_skills, auth, status and robots.' - /auth.md is served identically on both hosts (text/markdown, 1,947 bytes) and is the registration_instructions target of the OAuth metadata; saved as authentication/smklog-com-auth.md. - 'CORS: the discovery GETs answer access-control-allow-origin * with allow-headers Content-Type, Accept, MCP-Protocol-Version; the POST /quote error response answered access-control-allow-origin https://smklog.com (observed 2026-09-19).'