generated: '2026-09-19' method: searched description: Results of probing the /.well-known/ discovery surface for the SpAItial base hosts (apis.yml baseURL + OpenAPI servers[] = https://api.spaitial.ai) plus the hosted MCP server host. Status is the HTTP code observed at fetch time. Only documents that returned a real, correctly-typed payload were saved verbatim. The MCP server publishes an MCP Server Card (both the versioned path and the compatibility alias) — both saved. No security.txt, OpenID, or OAuth authorization-server metadata is published on the API host. hosts: - host: https://api.spaitial.ai documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /v1/openapi.json status: 200 type: application/json note: Machine-readable OpenAPI 3.0 spec — saved as openapi/spaitial-developer-api-openapi.json - host: https://mcp.spaitial.ai documents: - path: /.well-known/mcp/server-card.json status: 200 type: application/json file: spaitial-mcp-server-card.json - path: /.well-known/mcp.json status: 200 type: application/json file: spaitial-mcp.json - path: /.well-known/oauth-protected-resource status: 200 file: spaitial-mcp-oauth-protected-resource.json bytes: 164 - path: /.well-known/oauth-authorization-server status: 200 file: spaitial-mcp-oauth-authorization-server.json bytes: 617 path_echo_control: passed - host: https://spaitial.ai documents: - path: /.well-known/security.txt status: 404 - path: /llms.txt status: 200 type: text/plain note: Saved as llms/spaitial-llms.txt - host: https://docs.spaitial.ai documents: - path: /.well-known/security.txt status: 404 - path: /llms.txt status: 200 type: text/plain note: Saved as llms/spaitial-docs-llms.txt x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://mcp.spaitial.ai path: /.well-known/oauth-protected-resource file: spaitial-mcp-oauth-protected-resource.json - host: https://mcp.spaitial.ai path: /.well-known/oauth-authorization-server file: spaitial-mcp-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host note: 'MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.'