# Wellfound > Wellfound (formerly AngelList Talent) is a startup hiring marketplace and AI recruiting > platform. Its entire public, machine-readable API surface is two OAuth-protected Model > Context Protocol (MCP) servers. There is no OpenAPI document, no public GraphQL endpoint, > no REST reference and no developer portal. This file was GENERATED by API Evangelist from probed evidence, not published by Wellfound. Wellfound serves no /llms.txt of its own (https://wellfound.com/llms.txt returns 404, as does https://reach.wellfound.com/llms.txt). Everything below was fetched on 2026-09-04 and each claim carries the URL and HTTP status it came from. ## API surface Two remote MCP servers, each with its own OAuth authorization server, scope vocabulary and RFC 9728 protected-resource document. Both are live and both are OAuth-gated: an unauthenticated `tools/list` returns HTTP 401 with a WWW-Authenticate challenge, so the tool names and input schemas are not public and are not reproduced here. - Wellfound recruiter applications MCP — https://wellfound.com/api/mcp (POST, JSON-RPC; 401 without a bearer token). Scopes: `applications:read`, `applications:accept`, `applications:reject`. - Wellfound Reach MCP — https://reach.wellfound.com/mcp (POST, JSON-RPC; 401 without a bearer token). Scopes: `projects:read`, `agents:read`, `agents:write`, `candidates:read`, `candidates:write`, `company_lists:read`, `company_lists:write`. ## Discovery documents (all HTTP 200) - https://wellfound.com/.well-known/openid-configuration - https://wellfound.com/.well-known/oauth-authorization-server - https://wellfound.com/.well-known/oauth-protected-resource - https://wellfound.com/.well-known/oauth-protected-resource/api/mcp - https://wellfound.com/.well-known/security.txt - https://reach.wellfound.com/.well-known/oauth-authorization-server - https://reach.wellfound.com/.well-known/oauth-protected-resource - https://reach.wellfound.com/.well-known/security.txt ## How to authenticate Both servers are authorization-code + PKCE (S256) only, with refresh tokens and RFC 7591 dynamic client registration. Neither supports `client_credentials`, so there is no machine-to-machine path without a human authorization step. Bearer token goes in the `Authorization` header. - wellfound.com — authorize https://wellfound.com/api/oauth/authorize, token https://wellfound.com/api/oauth/token, register https://wellfound.com/api/oauth/register, revoke https://wellfound.com/api/oauth/revoke. Public and confidential clients (`none`, `client_secret_post`). - reach.wellfound.com — authorize https://reach.wellfound.com/oauth/authorize, token https://reach.wellfound.com/oauth/token, register https://reach.wellfound.com/oauth/register, revoke https://reach.wellfound.com/oauth/revoke. PUBLIC CLIENTS ONLY (`token_endpoint_auth_methods_supported: ["none"]`). ## What agents should know before acting - Five of the sixteen published scopes are write scopes. `applications:accept` and `applications:reject` act on a named person's job application. - No idempotency mechanism is published on either server. A retried write has no documented replay protection. - No reversal operation and no reversal window is published for any write. Do not assume an accept or a reject can be undone. - No rate limits and no rate-limit response headers are published or observed. - Error bodies are the flat OAuth `{"error", "error_description"}` shape, not RFC 9457 problem+json — and the two servers use different error codes for the same condition (`invalid_token` vs the non-standard `missing_or_invalid_token`). ## Human pages - Home: https://wellfound.com/ - Pricing: https://wellfound.com/recruit/pricing - Help center: https://help.wellfound.com/ - Status: https://status.wellfound.com/ (Atlassian Statuspage; Atom and RSS history feeds) - Trust center: https://trust.wellfound.ai/ (Vanta; SOC 2 claimed) - Blog: https://wellfound.com/blog (RSS: https://wellfound.com/blog.rss) - Terms: https://wellfound.com/terms - Privacy: https://wellfound.com/privacy - Security contact: security@wellfound.com ## Not available - OpenAPI / Swagger — 404 on every probed path across wellfound.com, api.wellfound.com, reach.wellfound.com and cloud.wellfound.com. - Public GraphQL — https://wellfound.com/graphql exists but returns HTTP 403 behind a Cloudflare managed challenge; it is an internal endpoint, not a published API. - AsyncAPI, webhooks, agent card (A2A), api-catalog, ai-plugin.json — all 404. - SDKs, CLI, Postman collection, changelog, developer portal, API reference — none found. - Wellfound has no GitHub organization. github.com/angellist belongs to AngelList (angellist.com), a different company. - Third-party "Wellfound MCP servers" on Apify and Bright Data are scrapers operated by other companies. They are not Wellfound's and should not be treated as first-party.