This origin is the WebAuthn Related Origin Requests rpId target

This page intentionally does not trigger the leak test itself — the trigger must run from a different origin (see leaktest.cgt.io) that sets rpId=rp.leaktest.cgt.io. That cross-origin mismatch is what forces WebKit/the OS credential service to fetch this origin's /.well-known/webauthn to check whether the calling origin is permitted to use this rpId.

Current well-known file: