Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3ca55748ca978ecd0e2e23c26c2ddf2b49e821b0e
GraphQL introspection enabled at /graphql Types: 61 (by kind: ENUM: 5, INPUT_OBJECT: 14, OBJECT: 35, SCALAR: 7) Operations: - Query: Query | fields: getAllBrands, getAllPlans, getDashboardAllBrands, getPlanDetails, getStripeCards - Mutation: Mutation | fields: createOutMembership, createPortalLink, getToastBrands, getToastMenusItems, upgradeMembership Directives: deprecated, include, skip, specifiedBy (total: 4)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3ca55748ca978ecd0e2e23c26c2ddf2b49e821b0e
GraphQL introspection enabled at /graphql Types: 61 (by kind: ENUM: 5, INPUT_OBJECT: 14, OBJECT: 35, SCALAR: 7) Operations: - Query: Query | fields: getAllBrands, getAllPlans, getDashboardAllBrands, getPlanDetails, getStripeCards - Mutation: Mutation | fields: createOutMembership, createPortalLink, getToastBrands, getToastMenusItems, upgradeMembership Directives: deprecated, include, skip, specifiedBy (total: 4)
Open service 75.2.97.79:80 · api-stg.bluekeys.io
2026-01-10 00:12
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Sat, 10 Jan 2026 00:13:28 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=bcHGtoRBlnj7PDf5N9ooQIGkogJIhCoH%2FLbBy5SCLOk%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1768004008"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=bcHGtoRBlnj7PDf5N9ooQIGkogJIhCoH%2FLbBy5SCLOk%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1768004008"
Server: Heroku
Set-Cookie: connect.sid=s%3ACM2lVNjlnJ36hxbSewZpnyr8hMaef2DG.1CKkCpZu9Nb42sFXIH6rNdEL%2FWnLEKZG75ojpSOIOgA; Path=/; Expires=Sat, 10 Jan 2026 01:13:28 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 13.248.132.87:443 · api-stg.bluekeys.io
2026-01-09 02:48
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 02:48:29 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=4HVK%2Blvr5JD%2F9nyn6QSvWXttQ%2FrxAWqWAg3VI5AVH4s%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767926909"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=4HVK%2Blvr5JD%2F9nyn6QSvWXttQ%2FrxAWqWAg3VI5AVH4s%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767926909"
Server: Heroku
Set-Cookie: connect.sid=s%3AogpQGWSsR18IfbBRaPIdhfOtQpNBxD8I.q9uz0VWRLWzQNw6xIIkvrqtQNRMkmkDMeOlPH1wFtGM; Path=/; Expires=Fri, 09 Jan 2026 03:48:29 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 75.2.97.79:80 · api-stg.bluekeys.io
2026-01-02 20:34
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 20:34:55 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=0O%2FTmu1vLKplfja2JOSW%2FGCm963DUFTNmzXkrUa6l7g%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767386095"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=0O%2FTmu1vLKplfja2JOSW%2FGCm963DUFTNmzXkrUa6l7g%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767386095"
Server: Heroku
Set-Cookie: connect.sid=s%3AJP8WQwhUVmk9wWJTCXyoiSRQQzHwpPZ2.riqZxsLtWMFcmmAq7lrhS3IX3MC%2FJzBjRBWcSzqbiSM; Path=/; Expires=Fri, 02 Jan 2026 21:34:55 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 13.248.132.87:443 · api-stg.bluekeys.io
2026-01-02 00:18
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 00:18:35 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=C%2FY5Oq81Nb5%2BPolvd%2FN6EyVuX5qUO1%2FWHV4IHhP4F7g%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767313115"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=C%2FY5Oq81Nb5%2BPolvd%2FN6EyVuX5qUO1%2FWHV4IHhP4F7g%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767313115"
Server: Heroku
Set-Cookie: connect.sid=s%3A5uNsuZYGL0rNHOIowH05JoYwFET-AHLF.da%2BGfQsdg9rK4Gw5C2A2MyRvujA8%2BAJ55oyCVNsLWoA; Path=/; Expires=Fri, 02 Jan 2026 01:18:35 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 13.248.132.87:443 · api-stg.bluekeys.io
2025-12-30 08:31
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Tue, 30 Dec 2025 08:31:20 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=XyOjoPccNsDg37DmAKHcUOwaAMFWQ3oE0Dsd%2FNptUGU%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767083480"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=XyOjoPccNsDg37DmAKHcUOwaAMFWQ3oE0Dsd%2FNptUGU%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767083480"
Server: Heroku
Set-Cookie: connect.sid=s%3AhsPgfEcy91BeRwQLqWWv6pgXblIkHq49.7NEnAxlECk76nmret2ssPOcwx0Pv%2BqvcUuOekPyV70o; Path=/; Expires=Tue, 30 Dec 2025 09:31:20 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 75.2.97.79:80 · api-stg.bluekeys.io
2025-12-23 02:37
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Tue, 23 Dec 2025 02:37:06 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Zx7yWGV5T0npxyNfDb95msSYcUNB%2BGJXhk4hDkUkNdY%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766457426"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Zx7yWGV5T0npxyNfDb95msSYcUNB%2BGJXhk4hDkUkNdY%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766457426"
Server: Heroku
Set-Cookie: connect.sid=s%3Amn1uyB0XmIBPRPe91QOZUpAOOXHy-xj3.Xms6IyF43bmbNAiVLkHHbEeFZjBRF6Qkz5XBcMs5BlI; Path=/; Expires=Tue, 23 Dec 2025 03:37:06 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 13.248.132.87:443 · api-stg.bluekeys.io
2025-12-22 12:39
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 12:39:43 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=n6%2FKKNlLKCnNSN1EuEpwWC585u6qdZpfVcH4cBvevcY%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766407183"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=n6%2FKKNlLKCnNSN1EuEpwWC585u6qdZpfVcH4cBvevcY%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766407183"
Server: Heroku
Set-Cookie: connect.sid=s%3Az_1VX54Ct2h9-JbvMdvmjfpUSPVyY8Jx.l8iXv5UaJUsOEkstyzGqA8X5zeZYbDP0u8cNkgdtO0k; Path=/; Expires=Mon, 22 Dec 2025 13:39:43 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 75.2.97.79:80 · api-stg.bluekeys.io
2025-12-21 08:16
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Sun, 21 Dec 2025 08:16:37 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=9uqkPeZr%2FvLKDEIjn83H1wt8B5cFe1mliCTQoCdEnrY%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766304997"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=9uqkPeZr%2FvLKDEIjn83H1wt8B5cFe1mliCTQoCdEnrY%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766304997"
Server: Heroku
Set-Cookie: connect.sid=s%3A4a437kqH974UZkzVEe61Rf77Bgh0CONV.IzqudcoHQBf94K9Vm1CYTeFcDpV29jq1%2BGyNj98kVBE; Path=/; Expires=Sun, 21 Dec 2025 09:16:37 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 13.248.132.87:443 · api-stg.bluekeys.io
2025-12-20 10:21
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Sat, 20 Dec 2025 10:21:58 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=WGEwnuxPYFKSRJ6ljU9UkbDqUvp13qjFIQ3H16HP1Yw%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766226118"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=WGEwnuxPYFKSRJ6ljU9UkbDqUvp13qjFIQ3H16HP1Yw%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766226118"
Server: Heroku
Set-Cookie: connect.sid=s%3ATDktxfsnILoRThf277qQXXRDuCGX3JYP.yJzJOUJ7PrcSHRkmlJUTRWBb1P0ndsjKyJ36ydhw%2Bic; Path=/; Expires=Sat, 20 Dec 2025 11:21:58 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 75.2.97.79:80 · api-stg.bluekeys.io
2025-12-19 05:57
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Fri, 19 Dec 2025 05:57:09 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=n3fuKH1rjRnWjKpgg3l%2BLYMDhG5zuPBYBMOPFwzIVAs%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766123829"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=n3fuKH1rjRnWjKpgg3l%2BLYMDhG5zuPBYBMOPFwzIVAs%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766123829"
Server: Heroku
Set-Cookie: connect.sid=s%3A3UIKEOKKOsPjo36eGJKzql-a14UXKWlD.G7bNampu3HRiykqv99TqfySh%2B%2BsxjYyFwZTEMmg56f0; Path=/; Expires=Fri, 19 Dec 2025 06:57:09 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>