generated: '2026-08-05' method: searched source: live probes of every apis.yml baseURL host, the docs host, and the auth host note: >- canopy.umbra.space is a single-page application whose catch-all answers HTTP 200 with an HTML shell for EVERY path, including /.well-known/agent-card.json and /openapi.json. A control probe of https://canopy.umbra.space/zzz-nope-12345 returned the identical HTML body, so every 200 on that host is a soft-404 and none of it is recorded as a discovery document. hosts: - host: https://docs.canopy.umbra.space documents: - path: /.well-known/api-catalog status: 200 content_type: application/linkset+json file: umbra-api-catalog.json standard: RFC 9727 note: >- Links all six Canopy OpenAPI documents by service-desc, which is how the machine-readable specs in openapi/ were located. - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /llms.txt status: 200 content_type: text/plain file: ../llms/umbra-llms.txt - path: /mcp status: 200 content_type: text/event-stream note: anonymous Model Context Protocol endpoint; see mcp/umbra-mcp.yml - host: https://auth.canopy.umbra.space documents: - path: /.well-known/openid-configuration status: 200 content_type: application/json file: umbra-openid-configuration.json standard: OpenID Connect Discovery 1.0 - path: /.well-known/oauth-authorization-server status: 200 content_type: application/json file: umbra-oauth-authorization-server.json standard: RFC 8414 - path: /.well-known/security.txt status: 404 - path: /.well-known/oauth-protected-resource status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: https://api.canopy.umbra.space note: >- Every path on the API host, including the control path /zzz-control-9931, returns 401 with application/json. The entire well-known surface here is authentication-gated, not absent. documents: - path: /.well-known/security.txt status: 401 - path: /.well-known/openid-configuration status: 401 - path: /.well-known/oauth-authorization-server status: 401 - path: /.well-known/oauth-protected-resource status: 401 - path: /.well-known/api-catalog status: 401 - path: /.well-known/agent-card.json status: 401 - path: /.well-known/agent.json status: 401 - host: https://api.canopy.prod.umbra-sandbox.space note: sandbox API host; identical 401-on-everything posture as the live API host documents: - path: /.well-known/security.txt status: 401 - path: /.well-known/agent-card.json status: 401 - path: /.well-known/agent.json status: 401 - host: https://umbra.space documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - path: /llms.txt status: 200 content_type: text/plain note: >- Marketing-site llms.txt auto-generated by the All in One SEO WordPress plugin (sitemap and blog-post index only). The developer-facing llms.txt is the docs-host one saved in llms/. absent: security_txt: >- No /.well-known/security.txt on any Umbra host (RFC 9116). No vulnerability disclosure policy, bug bounty program or security contact was found — see security/ for the probe record. agent_card: >- No A2A agent card at either /.well-known/agent-card.json or the legacy /.well-known/agent.json on any of the five hosts probed. No a2a/ artifact is written, by design.