why would someone have both /.well-known/citrons/auth and /citrons/auth?

I'm not saying they would. just read RFC 8615. it explains /.well-known.