generated: '2026-09-19' method: probed source: live GET probes of every apis.yml baseURL host, the docs host, the website host and the MCP host note: 'Four real documents were served. StackAdapt publishes RFC 8414 OAuth 2.0 Authorization Server Metadata on api.stackadapt.com, www.stackadapt.com and sandbox.stackadapt.com, and RFC 9728 OAuth 2.0 Protected Resource Metadata on mcp.stackadapt.com — the discovery chain a Model Context Protocol client walks to authorize against the hosted MCP server. No security.txt, no OpenID Connect discovery document, no api-catalog and no ai-plugin.json are served on any host. api.stackadapt.com answers 200 with the application''s HTML shell for /llms.txt and /robots.txt; those are soft-200s, not documents, and are recorded as misses. MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.' hosts: - host: https://api.stackadapt.com role: REST + GraphQL API host - host: https://www.stackadapt.com role: website / OAuth authorization server for the MCP resource documents: - path: /.well-known/oauth-authorization-server status: 200 file: stackadapt-www-oauth-authorization-server.json bytes: 853 path_echo_control: passed - host: https://mcp.stackadapt.com role: hosted MCP server documents: - path: /.well-known/oauth-protected-resource status: 200 file: stackadapt-mcp-oauth-protected-resource.json bytes: 164 path_echo_control: passed - host: https://sandbox.stackadapt.com role: sandbox environment - host: https://docs.stackadapt.com role: developer documentation documents: - host: https://api.stackadapt.com path: /.well-known/oauth-authorization-server status: 200 spec: RFC 8414 content_type: application/json file: stackadapt-oauth-authorization-server.json - host: https://mcp.stackadapt.com path: /.well-known/oauth-protected-resource status: 200 spec: RFC 9728 content_type: application/json file: stackadapt-oauth-protected-resource.json - host: https://sandbox.stackadapt.com path: /.well-known/oauth-authorization-server status: 200 spec: RFC 8414 content_type: application/json file: stackadapt-sandbox-oauth-authorization-server.json - host: https://www.stackadapt.com path: /.well-known/oauth-authorization-server status: 200 spec: RFC 8414 content_type: application/json file: null note: Identical document to the api.stackadapt.com one with the issuer rewritten to https://www.stackadapt.com. This is the issuer named by the MCP protected-resource metadata, so it is the authorization server an MCP client actually uses. Not saved separately — it is byte-equivalent apart from the host. - host: https://api.stackadapt.com path: /.well-known/security.txt status: 404 - host: https://api.stackadapt.com path: /.well-known/openid-configuration status: 404 - host: https://api.stackadapt.com path: /.well-known/oauth-protected-resource status: 404 - host: https://api.stackadapt.com path: /.well-known/api-catalog status: 404 - host: https://api.stackadapt.com path: /.well-known/ai-plugin.json status: 404 - host: https://api.stackadapt.com path: /.well-known/agent-card.json status: 404 - host: https://api.stackadapt.com path: /.well-known/agent.json status: 404 - host: https://api.stackadapt.com path: /llms.txt status: 200 hit: false note: Returns the application HTML shell, not an llms.txt document. Soft-200 — recorded as a miss. - host: https://www.stackadapt.com path: /.well-known/security.txt status: 404 - host: https://www.stackadapt.com path: /.well-known/openid-configuration status: 404 - host: https://www.stackadapt.com path: /.well-known/api-catalog status: 404 - host: https://www.stackadapt.com path: /.well-known/ai-plugin.json status: 404 - host: https://www.stackadapt.com path: /.well-known/agent-card.json status: 404 - host: https://www.stackadapt.com path: /.well-known/agent.json status: 404 - host: https://mcp.stackadapt.com path: /.well-known/oauth-authorization-server status: 404 - host: https://mcp.stackadapt.com path: /.well-known/agent-card.json status: 404 - host: https://mcp.stackadapt.com path: /.well-known/agent.json status: 404 - host: https://mcp.stackadapt.com path: /.well-known/security.txt status: 404 - host: https://docs.stackadapt.com path: /.well-known/security.txt status: 404 - host: https://docs.stackadapt.com path: /.well-known/openid-configuration status: 404 - host: https://docs.stackadapt.com path: /.well-known/oauth-authorization-server status: 404 - host: https://docs.stackadapt.com path: /.well-known/api-catalog status: 404 - host: https://docs.stackadapt.com path: /.well-known/ai-plugin.json status: 404 - host: https://docs.stackadapt.com path: /.well-known/agent-card.json status: 404 - host: https://docs.stackadapt.com path: /.well-known/agent.json status: 404 security_txt: served: false note: No /.well-known/security.txt on any host. StackAdapt does publish a named security contact (security@stackadapt.com) on its Trust and Security Center — see security/stackadapt-vulnerability-disclosure.yml — but not as an RFC 9116 document. x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://mcp.stackadapt.com path: /.well-known/oauth-protected-resource file: stackadapt-mcp-oauth-protected-resource.json - host: https://www.stackadapt.com path: /.well-known/oauth-authorization-server file: stackadapt-www-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host