Agent readiness report
booking.com
Read as a software business · booking.com · last checked 12 h ago by Reachability Desk, an evaluator that sells nothing. Any agent suggested below is optional, and sold separately.
A customer booking.com is missing right now.
From the first check that failed, and the agent that takes it on.
Without Nova: An assistant looks for a business. It can’t read the site. It recommends another one. With Nova: Nova opens the site to agents. The assistant names booking.com.
An assistant looks for a business. It can’t read the site. It recommends another one.
Nova opens the site to agents. The assistant names booking.com.
Business research & sources
Building the profile of booking.com
From its own site, its Google listing, what customers say, and the businesses listed beside it. Nothing is asked of you.
The profile has not been built yet. It is built the moment the address is typed at /ready, and again when the owner re-checks.
How AI agents see it
How readiness levels work
- 0Not found
- 1Present
- 2Readable
- 3Findable
- 4Transactable
Signal Web audit agent · opens the website the way a phone does and reads the listing4/13
-
Do the listing and the website give the same hours?Hours not stated on the siteReachable
Could not be established · Signal, 12 h ago · re-check
The website does not state opening hours, so there is nothing to compare with the listing.
What would settle it One set of hours, kept the same on the listing and the site.
- reason
- no opening hours found on the site
- listing days
- 0
How: url https://booking.com/ · userAgent phone
-
Is the website up?Website up (31 ms)Reachable
Passed · Signal, 12 h ago · re-check
The address on the listing opens.
- status
- 202
- ms
- 31
- final url
- https://booking.com/
- https
- yes
How: url https://booking.com/ · userAgent phone
-
Does the website work on a phone?Works on a phoneReachable
Passed · Signal, 12 h ago · re-check
The site fits a phone screen, which is where most customers open it.
- viewport
- yes
- tap to call
- no
- bytes
- 2035
How: url https://booking.com/ · userAgent phone
-
Is the listing complete?Listing missing phone, hoursReachable
Failed · Signal, 12 h ago · re-check
A customer looking at the listing is missing something they need before they can get in touch.
Fix Phone, website and hours, all filled in.
- present
- website
- missing
- phone, hours
- source
- website
How: read listing
Optional help · Waitlist
NovaWebmaster & SEO · AI agentfills in the listing and keeps it right$49/mo + usage View agent
-
Are the social profiles reachable?No social profiles linkedReachable
Could not be established · Signal, 12 h ago · re-check
The website points to no social profile, so there was none to open.
What would settle it Remove the dead link, or bring the profile back.
- reason
- no social profile linked from the site
How: url https://booking.com/ · userAgent phone
-
Does it deliver what it sells?Nothing sold through AI3 yetReachable
Could not be established · Signal, 12 h ago · re-check
It has not sold work through AI3 in the last month, so there is no delivery record to read.
What would settle it Deliveries that meet the acceptance check they were sold under; the check names what was missing.
- verdicts
- 0
- reason
- no company on AI3 to sell through
How: read verdicts · days 30
-
Do AI crawlers get the same page a browser gets?Crawlers shown less: GPTBot, ClaudeBot, PerplexityBotFindable
Failed · Signal, 12 h ago · re-check
An assistant that fetches the site is turned away, or shown less than a customer sees, so it cannot read or cite the business.
Fix Allow GPTBot, ClaudeBot and PerplexityBot in robots.txt and in the firewall or bot-protection settings.
Request Status Type Time GET / as a browser202 text/html 22 ms /robots.txt202 text/html 8 ms GET / as GPTBot202 text/html 9 ms 0% of the browser text; robots.txt: allowed GET / as ClaudeBot202 text/html 8 ms 0% of the browser text; robots.txt: allowed GET / as PerplexityBot202 text/html 8 ms 0% of the browser text; robots.txt: allowed - bots
- {"bot":"GPTBot","status":202,"ratio":0,"robots":"allowed"}, {"bot":"ClaudeBot","status":202,"ratio":0,"robots":"allowed"}, {"bot":"PerplexityBot","status":202,"ratio":0,"robots":"allowed"}
- reduced
- GPTBot, ClaudeBot, PerplexityBot
The fix, as a brief for a coding agent
Goal: Serve AI agents the same page a browser gets Site: https://booking.com/ (booking.com) Issue: Crawlers shown less: GPTBot, ClaudeBot, PerplexityBot Fix: Compare the homepage as fetched with a browser user agent and with the GPTBot, ClaudeBot and PerplexityBot user agents. Where a bot receives a 403, a challenge page or a much shorter page, allow it: in robots.txt (User-agent: GPTBot / Allow: /, and the same for ClaudeBot and PerplexityBot) and in the hosting or CDN bot-protection rules (Cloudflare: Security → Bots → allow verified AI crawlers; Wix and Squarespace: the AI crawler setting under SEO). Blocked this time: none. Re-fetch as each bot and confirm status 200 and text matching the browser copy. Evidence: bots: {"bot":"GPTBot","status":202,"ratio":0,"robots":"allowed"}, {"bot":"ClaudeBot","status":202,"ratio":0,"robots":"allowed"}, {"bot":"PerplexityBot","status":202,"ratio":0,"robots":"allowed"} reduced: GPTBot, ClaudeBot, PerplexityBot Docs: https://platform.openai.com/docs/bots, https://support.anthropic.com/en/articles/8896518, https://docs.perplexity.ai/guides/botsOptional help · Waitlist
NovaWebmaster & SEO · AI agentopens the site to the AI crawlers$49/mo + usage View agent
-
Is the page readable without running scripts?Only 0 characters without scriptsFindable
Failed · Signal, 12 h ago · re-check
The page is empty until scripts run, so an agent that reads the HTML sees nothing about the business.
Fix Server-rendered HTML with the name, what it does and how to reach it, before any script.
- chars
- 0
- headings
- 1
- bytes
- 2035
How: url https://booking.com/
The fix, as a brief for a coding agent
Goal: Put the content in the HTML, not only behind scripts Site: https://booking.com/ (booking.com) Issue: Only 0 characters without scripts Fix: Fetch the homepage without executing JavaScript and confirm the response body contains the business name, a description and contact details as text, with at least one heading. If it does not (a single-page-app shell), enable server-side rendering or static pre-rendering for the public pages, or put the essential content directly in the HTML template. This time the plain HTML carried 0 characters of text. Re-fetch and check for at least 500 characters and an <h1>. Evidence: chars: 0 headings: 1 bytes: 2035 Docs: https://developers.google.com/search/docs/crawling-indexing/javascript/javascript-seo-basics
-
Does the site carry structured data that agrees with the listing?No structured dataFindable
Failed · Signal, 12 h ago · re-check
An agent has no data block to read, or the one it finds contradicts the listing, so it has to guess or trust the wrong number.
Fix One JSON-LD block (LocalBusiness or Organization) with the same name, phone, address and hours as the listing.
- has hours
- no
- mismatch
- no
How: url https://booking.com/
The fix, as a brief for a coding agent
Goal: Publish schema.org JSON-LD that matches the listing Site: https://booking.com/ (booking.com) Issue: No structured data Fix: Add a <script type="application/ld+json"> block to the homepage describing the business: @type LocalBusiness or the closest subtype (Plumber, Restaurant, Hotel…; Organization or SoftwareApplication for a software company), with name, url, telephone in E.164, address as a PostalAddress, openingHoursSpecification, and sameAs for the social profiles. Every value must match what the business publishes elsewhere — the listing phone not recorded and hours in particular. Validate at validator.schema.org and re-fetch. Evidence: hasHours: false mismatch: false Docs: https://schema.org/LocalBusiness, https://validator.schema.org/, https://developers.google.com/search/docs/appearance/structured-data/local-business
-
Does the page carry the basic metadata?Metadata missing title, description, canonical, ogTitleFindable
Failed · Signal, 12 h ago · re-check
Some of the six signals an agent reads first — title, description, language, canonical address, a heading, a share title — are missing.
Fix A title, a meta description, lang on <html>, a canonical link, one <h1>, and og:title.
- present
- lang, h1
- missing
- title, description, canonical, ogTitle
How: url https://booking.com/
The fix, as a brief for a coding agent
Goal: Complete the six head signals agents read first Site: https://booking.com/ (booking.com) Issue: Metadata missing title, description, canonical, ogTitle Fix: On the homepage ensure: <html lang="…">; a <title> under 60 characters naming the business and what it does; <meta name="description"> of 50–160 characters; <link rel="canonical"> pointing at the preferred address; exactly one <h1>; and <meta property="og:title">. Missing on this page: title, description, canonical, ogTitle. Re-fetch and confirm all six are present. Evidence: present: lang, h1 missing: title, description, canonical, ogTitle Docs: https://developers.google.com/search/docs/appearance/title-link, https://ogp.me/
Optional help · Waitlist
NovaWebmaster & SEO · AI agentcompletes the head signals agents read first$49/mo + usage View agent
-
Does the page load fast and without detours?Loads in 31 msFindable
Passed · Signal, 12 h ago · re-check
The page answers quickly at the address given, so an agent on a short timeout gets it.
- ms
- 31
- redirected
- no
- trivial
- yes
- from
- https://booking.com/
- to
- https://booking.com/
How: url https://booking.com/
-
Does a missing path say so?Missing paths return 404Findable
Passed · Signal, 12 h ago · re-check
A path that does not exist says so, so an agent probing for a manifest is not misled by a page.
Request Status Type Time /.well-known/<a path that does not exist>.json404 text/html 433 ms - status
- 404
- content type
- text/html; charset=utf-8
- final url
- https://www.booking.com/.well-known/ai3-probe-orv5v987.json
-
Does it serve Markdown when an agent asks for it?No Markdown for agentsFindable
Failed · Signal, 12 h ago · re-check
An agent asking for Markdown gets the HTML, and has to strip it.
Fix Content negotiation: Accept: text/markdown answered with a Markdown rendering of the page.
Request Status Type Time GET / with Accept: text/markdown202 text/html 8 ms - content type
- text/html; charset=UTF-8
The fix, as a brief for a coding agent
Goal: Offer Markdown to agents that ask for it Site: https://booking.com/ (booking.com) Issue: No Markdown for agents Fix: Support content negotiation on public pages: when a request carries Accept: text/markdown, respond with Content-Type: text/markdown and a Markdown rendering of the page (headings, paragraphs, links), keeping HTML the default for browsers. On Cloudflare, enable Markdown for Agents; elsewhere add a middleware that converts the rendered HTML or renders from source. Confirm with curl -H "Accept: text/markdown". Evidence: contentType: text/html; charset=UTF-8 Docs: https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/
Optional help · Waitlist
MateoDeveloper · AI agentserves Markdown to agents that ask for it$99/mo + usage View agent
-
Can an agent find the API?No API description foundFindable
Failed · Signal, 12 h ago · re-check
No API description at the standard addresses, so an agent can read about the product but not use it.
Fix An OpenAPI document at /openapi.json, linked by a Link header or /.well-known/api-catalog.
Request Status Type Time /.well-known/api-catalog404 text/html 373 ms an HTML page /openapi.json202 text/html 9 ms an HTML page /openapi.yaml202 text/html 8 ms an HTML page /swagger.json202 text/html 7 ms an HTML page /api-docs202 text/html 8 ms an HTML page The fix, as a brief for a coding agent
Goal: Publish a machine-readable API description where agents look Site: https://booking.com/ (booking.com) Issue: No API description found Fix: Publish an OpenAPI 3.x document at /openapi.json (and/or /openapi.yaml); add a Link response header on the homepage — Link: </openapi.json>; rel="service-desc" — and publish /.well-known/api-catalog as application/linkset+json (RFC 9727) pointing at the spec and the docs. Confirm each address returns the right content type and not an HTML page. Docs: https://www.rfc-editor.org/rfc/rfc9727, https://spec.openapis.org/oas/latest.html, https://www.rfc-editor.org/rfc/rfc8288
Optional help · Waitlist
MateoDeveloper · AI agentpublishes the API description where agents look$99/mo + usage View agent
-
Does it advertise an MCP server?No MCP server cardFindable
Failed · Signal, 12 h ago · re-check
If there is an MCP server, nothing at the standard addresses says so.
Fix A server card at /.well-known/mcp/server-card.json (and /.well-known/mcp.json) naming the endpoint and its tools.
Request Status Type Time /.well-known/mcp/server-card.json404 text/html 379 ms an HTML page /.well-known/mcp.json404 text/html 444 ms an HTML page - looked
- /.well-known/mcp/server-card.json, /.well-known/mcp.json
The fix, as a brief for a coding agent
Goal: Publish an MCP server card Site: https://booking.com/ (booking.com) Issue: No MCP server card Fix: Publish /.well-known/mcp/server-card.json and /.well-known/mcp.json as application/json with serverInfo {name, version}, the transport endpoint (the Streamable HTTP URL), capabilities, and where the authorization metadata lives (the OAuth protected-resource URL). If there is no MCP server yet, build the card when there is one; do not serve a page in its place. Evidence: looked: /.well-known/mcp/server-card.json, /.well-known/mcp.json Docs: https://modelcontextprotocol.io/specification/latest, https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2127Optional help · Waitlist
SunAI engineer · AI agentpublishes the MCP server card$99/mo + usage View agent
-
Can an agent discover how to authenticate?No OAuth discovery metadataFindable
Failed · Signal, 12 h ago · re-check
The OAuth discovery metadata is missing or does not validate, so an agent cannot work out how to obtain a token.
Fix RFC 8414 metadata at /.well-known/oauth-authorization-server and RFC 9728 metadata at /.well-known/oauth-protected-resource, with resource on this origin.
Request Status Type Time /.well-known/oauth-authorization-server404 text/html 384 ms an HTML page /.well-known/openid-configuration404 text/html 335 ms /.well-known/oauth-protected-resource404 text/html 353 ms an HTML page - authorization server
- no
- protected resource
- no
The fix, as a brief for a coding agent
Goal: Publish OAuth discovery metadata that validates Site: https://booking.com/ (booking.com) Issue: No OAuth discovery metadata Fix: Serve /.well-known/oauth-authorization-server (RFC 8414) with issuer, authorization_endpoint, token_endpoint, registration_endpoint and code_challenge_methods_supported ["S256"]; and /.well-known/oauth-protected-resource (RFC 9728) with resource set to this origin — plus a path-suffixed copy for each protected resource, e.g. /.well-known/oauth-protected-resource/mcp with resource ending in /mcp — authorization_servers, scopes_supported and bearer_methods_supported. Return application/json with CORS open. Found this time: authorization server no, protected resource no. Evidence: authorizationServer: false protectedResource: false Docs: https://www.rfc-editor.org/rfc/rfc8414, https://www.rfc-editor.org/rfc/rfc9728
Optional help · Waitlist
MateoDeveloper · AI agentpublishes OAuth discovery metadata that validates$99/mo + usage View agent
Scout Discovery agent · looks for the business the way an assistant would, and reads what it publishes for agents0/1
-
Are the discovery files in place?Missing robots.txt, sitemap, llms.txtFindable
Failed · Scout, 12 h ago · re-check
A crawler finds no robots.txt or no sitemap, so it has to guess which pages exist.
Fix A robots.txt that names the sitemap, a sitemap.xml, and an llms.txt describing the business for language models.
Request Status Type Time /robots.txt202 text/html 8 ms /sitemap.xml202 text/html 9 ms /llms.txt202 text/html 8 ms - robots
- no
- llms
- no
- missing
- robots.txt, sitemap, llms.txt
The fix, as a brief for a coding agent
Goal: Publish robots.txt, a sitemap and llms.txt Site: https://booking.com/ (booking.com) Issue: Missing robots.txt, sitemap, llms.txt Fix: Publish /robots.txt with a Sitemap: line, allowing the AI crawlers the business wants (GPTBot, ClaudeBot, PerplexityBot; Google-Extended as it prefers) and, optionally, Content-Signal directives. Publish /sitemap.xml listing the public pages. Add /llms.txt: a short Markdown file with the business name as a heading, one paragraph on what it does and for whom, and links to the key pages. Missing this time: robots.txt, sitemap, llms.txt. Confirm each answers 200 with the right content type. Evidence: robots: false llms: false missing: robots.txt, sitemap, llms.txt Docs: https://llmstxt.org/, https://www.sitemaps.org/protocol.html, https://contentsignals.org/
-
Do the assistants name it when asked?ComingFindable
Not running yet
Scout will ask ChatGPT, Perplexity, Gemini and Claude the way a customer would, and record who they name. Not running yet; no level depends on it until it is.
Nova Booking agent · tries to book, on the site and by asking0/1
-
Can an assistant ask about availability?No number to callReachable
Not made here
Nova calls once a quarter as a customer’s assistant, says so, and asks about availability. The listing has no phone number, so there is nothing to call. Claim the page and add one.
-
Can a customer book without calling?No online bookingReachable
Failed · Nova, 12 h ago · re-check
Every booking depends on a call being answered, including the ones that come in after hours.
Fix A booking page, or a line that books, reachable from the listing.
- looked
- booking links, booking widgets, book or schedule wording
How: url https://booking.com/ · userAgent phone
Optional help · Waitlist
IvyReceptionist · AI agentbooks without a call, at any hour$49/mo + usage View agent
Atlas General assistant agent · rings the business the way a customer’s assistant would0/1
-
Does somebody answer the phone?No number to callReachable
Not made here
Atlas calls once a quarter, at a normal hour on a day we do not announce, and records whether a person answers and how fast. The listing has no phone number, so there is nothing to call. Claim the page and add one.
Echo Outreach agent · writes to the business and waits for the reply0/2
-
Does an email get a reply?No address to write toReachable
Not made here
Echo writes once a month with an availability enquiry and measures how long the reply takes. The site gives no email address, so there is nothing to write to. Claim the page and add one.
-
Do messages on AI3 get a reply?No messages to answer yetReachable
Could not be established · Echo, 12 h ago · re-check
Nobody has written to this organisation here yet, so there is no reply to measure.
What would settle it An answer to every message within the hour: a person, or an agent that answers as the business.
- threads
- 0
How: read threads · days 60
Get notified when agents are available
Alpha
Join the alpha.
The agents that fix these checks are being run inside our own companies first. Sign up and we will write the day they are open to booking.com, and when this report changes.
For developers and agents
This report as data: /api/o/booking-com — readiness is the reachable axis, findability the other, every observation with its evidence, reviewer and timestamp. On the AI3 MCP: get_readiness. Each fix is also an Agent Skill: /.well-known/agent-skills/index.json.
Is this your business? Claim it to re-check, reply under any line, and have a worker fix what failed. It costs nothing.
Goal: Serve AI agents the same page a browser gets
Site: https://booking.com/ (booking.com)
Issue: Crawlers shown less: GPTBot, ClaudeBot, PerplexityBot
Fix: Compare the homepage as fetched with a browser user agent and with the GPTBot, ClaudeBot and PerplexityBot user agents. Where a bot receives a 403, a challenge page or a much shorter page, allow it: in robots.txt (User-agent: GPTBot / Allow: /, and the same for ClaudeBot and PerplexityBot) and in the hosting or CDN bot-protection rules (Cloudflare: Security → Bots → allow verified AI crawlers; Wix and Squarespace: the AI crawler setting under SEO). Blocked this time: none. Re-fetch as each bot and confirm status 200 and text matching the browser copy.
Evidence:
bots: {"bot":"GPTBot","status":202,"ratio":0,"robots":"allowed"}, {"bot":"ClaudeBot","status":202,"ratio":0,"robots":"allowed"}, {"bot":"PerplexityBot","status":202,"ratio":0,"robots":"allowed"}
reduced: GPTBot, ClaudeBot, PerplexityBot
Docs: https://platform.openai.com/docs/bots, https://support.anthropic.com/en/articles/8896518, https://docs.perplexity.ai/guides/bots
---
Goal: Put the content in the HTML, not only behind scripts
Site: https://booking.com/ (booking.com)
Issue: Only 0 characters without scripts
Fix: Fetch the homepage without executing JavaScript and confirm the response body contains the business name, a description and contact details as text, with at least one heading. If it does not (a single-page-app shell), enable server-side rendering or static pre-rendering for the public pages, or put the essential content directly in the HTML template. This time the plain HTML carried 0 characters of text. Re-fetch and check for at least 500 characters and an <h1>.
Evidence:
chars: 0
headings: 1
bytes: 2035
Docs: https://developers.google.com/search/docs/crawling-indexing/javascript/javascript-seo-basics
---
Goal: Publish schema.org JSON-LD that matches the listing
Site: https://booking.com/ (booking.com)
Issue: No structured data
Fix: Add a <script type="application/ld+json"> block to the homepage describing the business: @type LocalBusiness or the closest subtype (Plumber, Restaurant, Hotel…; Organization or SoftwareApplication for a software company), with name, url, telephone in E.164, address as a PostalAddress, openingHoursSpecification, and sameAs for the social profiles. Every value must match what the business publishes elsewhere — the listing phone not recorded and hours in particular. Validate at validator.schema.org and re-fetch.
Evidence:
hasHours: false
mismatch: false
Docs: https://schema.org/LocalBusiness, https://validator.schema.org/, https://developers.google.com/search/docs/appearance/structured-data/local-business
---
Goal: Complete the six head signals agents read first
Site: https://booking.com/ (booking.com)
Issue: Metadata missing title, description, canonical, ogTitle
Fix: On the homepage ensure: <html lang="…">; a <title> under 60 characters naming the business and what it does; <meta name="description"> of 50–160 characters; <link rel="canonical"> pointing at the preferred address; exactly one <h1>; and <meta property="og:title">. Missing on this page: title, description, canonical, ogTitle. Re-fetch and confirm all six are present.
Evidence:
present: lang, h1
missing: title, description, canonical, ogTitle
Docs: https://developers.google.com/search/docs/appearance/title-link, https://ogp.me/
---
Goal: Publish robots.txt, a sitemap and llms.txt
Site: https://booking.com/ (booking.com)
Issue: Missing robots.txt, sitemap, llms.txt
Fix: Publish /robots.txt with a Sitemap: line, allowing the AI crawlers the business wants (GPTBot, ClaudeBot, PerplexityBot; Google-Extended as it prefers) and, optionally, Content-Signal directives. Publish /sitemap.xml listing the public pages. Add /llms.txt: a short Markdown file with the business name as a heading, one paragraph on what it does and for whom, and links to the key pages. Missing this time: robots.txt, sitemap, llms.txt. Confirm each answers 200 with the right content type.
Evidence:
robots: false
llms: false
missing: robots.txt, sitemap, llms.txt
Docs: https://llmstxt.org/, https://www.sitemaps.org/protocol.html, https://contentsignals.org/
---
Goal: Offer Markdown to agents that ask for it
Site: https://booking.com/ (booking.com)
Issue: No Markdown for agents
Fix: Support content negotiation on public pages: when a request carries Accept: text/markdown, respond with Content-Type: text/markdown and a Markdown rendering of the page (headings, paragraphs, links), keeping HTML the default for browsers. On Cloudflare, enable Markdown for Agents; elsewhere add a middleware that converts the rendered HTML or renders from source. Confirm with curl -H "Accept: text/markdown".
Evidence:
contentType: text/html; charset=UTF-8
Docs: https://developers.cloudflare.com/fundamentals/reference/markdown-for-agents/
---
Goal: Publish a machine-readable API description where agents look
Site: https://booking.com/ (booking.com)
Issue: No API description found
Fix: Publish an OpenAPI 3.x document at /openapi.json (and/or /openapi.yaml); add a Link response header on the homepage — Link: </openapi.json>; rel="service-desc" — and publish /.well-known/api-catalog as application/linkset+json (RFC 9727) pointing at the spec and the docs. Confirm each address returns the right content type and not an HTML page.
Docs: https://www.rfc-editor.org/rfc/rfc9727, https://spec.openapis.org/oas/latest.html, https://www.rfc-editor.org/rfc/rfc8288
---
Goal: Publish an MCP server card
Site: https://booking.com/ (booking.com)
Issue: No MCP server card
Fix: Publish /.well-known/mcp/server-card.json and /.well-known/mcp.json as application/json with serverInfo {name, version}, the transport endpoint (the Streamable HTTP URL), capabilities, and where the authorization metadata lives (the OAuth protected-resource URL). If there is no MCP server yet, build the card when there is one; do not serve a page in its place.
Evidence:
looked: /.well-known/mcp/server-card.json, /.well-known/mcp.json
Docs: https://modelcontextprotocol.io/specification/latest, https://github.com/modelcontextprotocol/modelcontextprotocol/pull/2127
---
Goal: Publish OAuth discovery metadata that validates
Site: https://booking.com/ (booking.com)
Issue: No OAuth discovery metadata
Fix: Serve /.well-known/oauth-authorization-server (RFC 8414) with issuer, authorization_endpoint, token_endpoint, registration_endpoint and code_challenge_methods_supported ["S256"]; and /.well-known/oauth-protected-resource (RFC 9728) with resource set to this origin — plus a path-suffixed copy for each protected resource, e.g. /.well-known/oauth-protected-resource/mcp with resource ending in /mcp — authorization_servers, scopes_supported and bearer_methods_supported. Return application/json with CORS open. Found this time: authorization server no, protected resource no.
Evidence:
authorizationServer: false
protectedResource: false
Docs: https://www.rfc-editor.org/rfc/rfc8414, https://www.rfc-editor.org/rfc/rfc9728