generated: '2026-09-19' method: probed source: live probes of Syft Data hosts (www, app, docs, blog) note: 'app.syftdata.com serves three real /.well-known documents — the Auth0-backed OIDC discovery document plus the RFC 8414 authorization-server metadata and RFC 9728 protected-resource metadata that back the hosted MCP server''s OAuth flow. No security.txt, api-catalog or ai-plugin.json is served on any host. MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.' hosts: - host: app.syftdata.com documents: - path: /.well-known/openid-configuration status: 200 file: syft-data-openid-configuration.json note: Auth0 tenant (syft-studio.us.auth0.com) backing app + MCP OAuth login. url: https://app.syftdata.com/.well-known/openid-configuration - path: /.well-known/oauth-authorization-server status: 200 file: syft-data-oauth-authorization-server.json note: RFC 8414 metadata. issuer https://app.syftdata.com; authorize/token endpoints proxied at /api/mcp/authorize and /api/mcp/token; dynamic client registration endpoint advertised; jwks_uri on the Auth0 tenant. url: https://app.syftdata.com/.well-known/oauth-authorization-server - path: /.well-known/oauth-protected-resource status: 200 file: syft-data-oauth-protected-resource.json note: RFC 9728 metadata naming https://app.syftdata.com/api/mcp as the protected resource; referenced by the WWW-Authenticate header the MCP endpoint returns on an anonymous call. url: https://app.syftdata.com/.well-known/oauth-protected-resource - path: /.well-known/oauth-protected-resource/api/mcp status: 200 note: Path-suffixed variant returning the same protected-resource document. - path: /.well-known/oauth-authorization-server/api/mcp status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/oauth-protected-resource status: 200 file: syft-data-app-oauth-protected-resource.json bytes: 165 - path: /.well-known/oauth-authorization-server status: 200 file: syft-data-app-oauth-authorization-server.json bytes: 2346 path_echo_control: passed x-shape-fix: converted: '2026-08-20' from: entries note: Rewritten into hosts[] -> documents[], the only shape well_known_docs() in score.rb reads. A served .well-known surface recorded in any other shape scores as absent. x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://app.syftdata.com path: /.well-known/oauth-protected-resource file: syft-data-app-oauth-protected-resource.json - host: https://app.syftdata.com path: /.well-known/oauth-authorization-server file: syft-data-app-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host