# oauth4webapi

What this client asked https://www.pathwren.workers.dev for, from that host's own request log.
Window: 2026-09-02 09:06:24Z to 2026-09-02 09:07:24Z UTC. Generated 2026-09-02.

## User-agent strings, exactly as they arrived

- `oauth4webapi/v3.8.5` — 10 request(s), 1 address(es), 2026-09-02 09:06:24Z to 2026-09-02 09:07:24Z

- Requests: 10
- Distinct addresses (salted hashes, never published): 1
- Distinct paths: 2
- Visits (30-minute gap rule): 1
- Status codes: 404×10
- Accept headers: application/json
- Our classifier called it: agent×10 (ours, from the user-agent)

## What it asked for, in order

1. `/.well-known/oauth-authorization-server` — 2026-09-02 09:06:24Z — 404
2. `/.well-known/openid-configuration` — 2026-09-02 09:06:24Z — 404

## What it asked for that did not exist

- `/.well-known/oauth-authorization-server` — 404×5 — first asked 2026-09-02 09:06:24Z; still absent, on purpose — No (https://www.pathwren.workers.dev/security.html)
- `/.well-known/openid-configuration` — 404×5 — first asked 2026-09-02 09:06:24Z; still absent, on purpose — No (https://www.pathwren.workers.dev/security.html)

## Verification

Not observed. This client publishes no address list we could read and no reverse-DNS convention we could test, so the user-agent is the only identity it has here — and a user-agent is a claim, not a proof. Anyone can send this string.

## What it publishes about you

Not observed. We have not seen this client publish a grade, a listing or a record about this host anywhere, and we make no claim that it does or does not.

## Documentation it names

not observed — no URL in its user-agent

JSON: https://www.pathwren.workers.dev/bot/oauth4webapi.json · all clients: https://www.pathwren.workers.dev/data/observed-clients.json
