generated: '2026-06-20' method: searched description: >- Results of probing the /.well-known/ discovery surface for every base host in apis.yml (baseURL) and the OpenAPI servers[]. Status is the HTTP code observed at fetch time. Only documents that returned a real, correctly-typed payload were saved verbatim. registry.terraform.io answers 200 with an Ember SPA HTML shell for /.well-known/security.txt and /.well-known/openid-configuration, so those are recorded as present-but-not-a-real-document and not saved. hosts: - host: https://app.terraform.io documents: - path: /.well-known/openid-configuration status: 200 type: application/json file: terraform-app-openid-configuration.json note: >- OIDC discovery for HCP Terraform's workload-identity (dynamic credentials) token issuer; id_token response type, RS256, terraform_* claims. - path: /.well-known/terraform.json status: 200 type: application/json file: terraform-app-terraform.json note: >- Terraform service discovery document (modules.v1, providers.v1, state.v2, tfe.v2, stacksplugin.v1, versions.v1 endpoints). - path: /.well-known/security.txt status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - host: https://registry.terraform.io documents: - path: /.well-known/terraform.json status: 200 type: application/json file: terraform-registry-terraform.json note: Terraform service discovery (modules.v1, providers.v1) for the public Registry. - path: /.well-known/security.txt status: 200 note: Returns the Ember SPA HTML shell, not an RFC 9116 document; not saved. - path: /.well-known/openid-configuration status: 200 note: Returns the Ember SPA HTML shell, not an OIDC document; not saved. - host: https://developer.hashicorp.com documents: - path: /.well-known/security.txt status: 404