generated: '2026-09-19' method: probed source: live probes of transcriptfetch.com and clerk.transcriptfetch.com (auth server named in oauth-protected-resource authorization_servers), 2026-09-09 note: 'Five real documents served on the primary host, including a public MCP server card at /.well-known/mcp/server-card.json with full tool input/output schemas. OAuth authorization-server metadata is served both on the primary host and on the Clerk-run auth host clerk.transcriptfetch.com (issuer). agent-card.json / agent.json 404 — no A2A surface. api-catalog and ai-plugin.json 404 (the 404 bodies are the site''s HTML not-found page, recorded as misses). MCP-host OAuth discovery added 2026-09-19 (roadmap#321/#337): the harvest visits a provider''s primary hosts, and RFC 9728 protected-resource metadata lives on the MCP host, so these documents existed and were invisible to the scorer. Fetched live and validated on `resource`/`issuer`; one negative control per host.' hosts: - host: transcriptfetch.com documents: - path: /.well-known/security.txt status: 200 file: transcriptfetch-security.txt - path: /.well-known/openid-configuration status: 200 file: transcriptfetch-openid-configuration.json - path: /.well-known/oauth-authorization-server status: 200 file: transcriptfetch-oauth-authorization-server.json - path: /.well-known/oauth-protected-resource status: 200 file: transcriptfetch-oauth-protected-resource.json - path: /.well-known/mcp/server-card.json status: 200 file: transcriptfetch-mcp-server-card.json - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /.well-known/oauth-protected-resource status: 200 file: transcriptfetch-transcriptfetch-oauth-protected-resource.json bytes: 309 path_echo_control: passed - host: clerk.transcriptfetch.com documents: - path: /.well-known/oauth-authorization-server status: 200 file: clerk-transcriptfetch-oauth-authorization-server.json - path: /.well-known/openid-configuration status: 200 file: clerk-transcriptfetch-openid-configuration.json - path: /.well-known/jwks.json status: 200 - path: /.well-known/security.txt status: 404 - path: /.well-known/oauth-authorization-server status: 200 file: transcriptfetch-clerk-oauth-authorization-server.json bytes: 1262 path_echo_control: passed x-mcp-probe: probed: '2026-09-19' issue: roadmap#321, roadmap#337 documents: - host: https://transcriptfetch.com path: /.well-known/oauth-protected-resource file: transcriptfetch-transcriptfetch-oauth-protected-resource.json - host: https://clerk.transcriptfetch.com path: /.well-known/oauth-authorization-server file: transcriptfetch-clerk-oauth-authorization-server.json validated_on: resource (RFC 9728) / issuer (RFC 8414, OIDC) negative_control: one per host; a 2xx JSON object at an impossible path discards the host