generated: '2026-08-13' method: probed source: live GET of /.well-known/* on every apis.yml host and every OpenAPI servers[] host note: >- Two real documents are served: an RFC 9116 security.txt on the marketing/docs host (www.zoho.com) and an OpenID Connect discovery document on the identity host (accounts.zoho.com), which is the authorization server every Zoho CRM OpenAPI securityScheme points at. The API host itself (www.zohoapis.com) serves no /.well-known/ surface — every path there returns the API gateway's own JSON 404 ("API endpoint not found"), not an HTML shell. hosts: - host: https://www.zoho.com role: website / developer docs documents: - path: /.well-known/security.txt status: 200 file: zoho-crm-security.txt kind: RFC 9116 security.txt - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: https://accounts.zoho.com role: OAuth 2.0 / OIDC authorization server (authorizationUrl + tokenUrl in every CRM OpenAPI) documents: - path: /.well-known/openid-configuration status: 200 file: zoho-crm-openid-configuration.json kind: OpenID Connect Discovery 1.0 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: https://www.zohoapis.com role: API host (servers[] in every Zoho CRM OpenAPI, dc=com) documents: - path: /.well-known/security.txt status: 404 - path: /.well-known/openid-configuration status: 404 - path: /.well-known/oauth-authorization-server status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 - host: https://mcp.zoho.com role: Zoho MCP console host documents: - path: /.well-known/oauth-authorization-server status: 400 note: returns "Invalid request uri." plain text, not an RFC 8414 document - path: /.well-known/oauth-protected-resource status: 400 note: returns "Invalid request uri." plain text, not an RFC 9728 document - path: /.well-known/openid-configuration status: 404 - path: /.well-known/security.txt status: 404 - path: /.well-known/api-catalog status: 404 - path: /.well-known/ai-plugin.json status: 404 - path: /.well-known/agent-card.json status: 404 - path: /.well-known/agent.json status: 404 oidc: issuer: https://accounts.zoho.com authorization_endpoint: https://accounts.zoho.com/oauth/v2/auth token_endpoint: https://accounts.zoho.com/oauth/v2/token revocation_endpoint: https://accounts.zoho.com/oauth/v2/token/revoke introspection_endpoint: https://accounts.zoho.com/oauth/v2/introspect userinfo_endpoint: https://accounts.zoho.com/oauth/v2/userinfo device_authorization_endpoint: https://accounts.zoho.com/oauth/v3/device/code jwks_uri: https://accounts.zoho.com/oauth/v2/keys grant_types_supported: - authorization_code - implicit - refresh_token - urn:ietf:params:oauth:grant-type:device_code - urn:ietf:params:oauth:grant-type:jwt-bearer code_challenge_methods_supported: [plain, S256] token_endpoint_auth_methods_supported: [client_secret_basic, client_secret_post, private_key_jwt] id_token_signing_alg_values_supported: [RS256, RS384] oidc_scopes_supported: [email, profile, openid, phone]