generated: '2026-09-19' method: searched description: Probe of the /.well-known/ discovery surface across Tabs hosts (website, docs, app, API, login). The integrators API host publishes RFC 8414 OAuth authorization-server metadata and RFC 9728 protected-resource metadata for the Tabs MCP server; login.tabs.com publishes OIDC discovery. SPA hosts (app.tabsplatform.com, trust.tabs.com) return their HTML shell with HTTP 200 for any path, recorded here as catch-all (not real well-known documents). hosts: - host: https://integrators.prod.api.tabsplatform.com documents: - path: /.well-known/oauth-authorization-server status: 200 file: tabs-oauth-authorization-server.json note: RFC 8414 metadata; issuer https://login.tabs.com, PKCE S256, dynamic client registration - path: /.well-known/oauth-protected-resource status: 200 file: tabs-mcp-oauth-protected-resource.json note: RFC 9728 metadata for the Tabs MCP server resource https://integrators.prod.api.tabsplatform.com/mcp - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://login.tabs.com documents: - path: /.well-known/openid-configuration status: 200 file: tabs-openid-configuration.json note: OIDC discovery; grants authorization_code, client_credentials, refresh_token, device_code; RS256 - path: /.well-known/oauth-authorization-server status: 200 file: tabs-login-oauth-authorization-server.json bytes: 855 path_echo_control: passed - host: https://usage-events.prod.api.tabsplatform.com documents: - path: /.well-known/security.txt status: 401 - path: /.well-known/openid-configuration status: 401 - path: /.well-known/oauth-authorization-server status: 401 - path: /.well-known/api-catalog status: 401 - path: /.well-known/ai-plugin.json status: 401 - host: https://tabs.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://docs.tabsplatform.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /llms.txt status: 200 file: ../llms/tabs-llms.txt note: llms.txt index of guides and API reference pages (ReadMe-hosted docs) - host: https://app.tabsplatform.com documents: - path: /.well-known/* status: 200 note: SPA catch-all — returns the application HTML shell for every path; no real well-known documents - host: https://trust.tabs.com documents: - path: /.well-known/* status: 200 note: SPA catch-all — trust-center HTML shell returned for every path; no real well-known documents x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://login.tabs.com path: /.well-known/oauth-authorization-server file: tabs-login-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host note: 'MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.'