generated: '2026-08-09' method: searched source: https://www.spocket.dev/.well-known/ host: https://www.spocket.dev notes: The two OAuth discovery documents are served by the MCP authorization surface. The protected-resource document names https://www.spocket.dev/api/mcp as the resource and https://www.spocket.dev as its authorization server, which is what lets an MCP client complete RFC 7591 dynamic client registration with no pre-shared key. No security.txt, OIDC discovery, api-catalog, ai-plugin or A2A agent card is published. x-evidence: fetched: '2026-08-09' probed: - url: https://www.spocket.dev/.well-known/oauth-authorization-server status: 200 - url: https://www.spocket.dev/.well-known/oauth-protected-resource status: 200 - url: https://www.spocket.dev/.well-known/security.txt status: 404 - url: https://www.spocket.dev/.well-known/openid-configuration status: 404 - url: https://www.spocket.dev/.well-known/api-catalog status: 404 - url: https://www.spocket.dev/.well-known/ai-plugin.json status: 404 - url: https://www.spocket.dev/.well-known/agent-card.json status: 404 - url: https://www.spocket.dev/.well-known/agent.json status: 404 hosts: - host: https://www.spocket.dev documents: - path: /.well-known/oauth-authorization-server status: 200 file: spocket-oauth-authorization-server.json content_type: application/json - path: /.well-known/oauth-protected-resource status: 200 file: spocket-oauth-protected-resource.json content_type: application/json - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 x-shape-fix: converted: '2026-08-20' from: documents note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent.