generated: '2026-07-21' method: searched source: live probes of /.well-known/* on Pressable hosts hosts: - host: https://my.pressable.com documents: - path: /.well-known/oauth-authorization-server # RFC 8414 — MCP OAuth AS metadata status: 200 file: zippykid-oauth-authorization-server.json - path: /.well-known/security.txt # RFC 9116 status: 404 - path: /.well-known/openid-configuration # OIDC discovery status: 404 - path: /.well-known/api-catalog # RFC 9727 status: 404 - path: /.well-known/ai-plugin.json status: 404 - host: https://pressable.com documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 notes: >- The oauth-authorization-server metadata at my.pressable.com backs Pressable's remote MCP server OAuth (scopes_supported: [mcp], PKCE S256, dynamic client registration, authorization_code + refresh_token grants). The REST API v1 uses a separate OAuth 2.0 client-credentials flow (client_id/client_secret from the control panel) — see authentication/zippykid-authentication.yml.