Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3ca55748ca978ecd0e2e23c2663d17c83a78f606f
GraphQL introspection enabled at /graphql Types: 61 (by kind: ENUM: 5, INPUT_OBJECT: 14, OBJECT: 35, SCALAR: 7) Operations: - Query: Query | fields: getAllBrands, getAllPlans, getDashboardAllBrands, getPlanDetails, getStripeCards - Mutation: Mutation | fields: createClaimRequest, createMembership, getToastBrands, getToastMenusItems, upgradeMembership Directives: deprecated, include, skip, specifiedBy (total: 4)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3ca55748ca978ecd0e2e23c2663d17c83a78f606f
GraphQL introspection enabled at /graphql Types: 61 (by kind: ENUM: 5, INPUT_OBJECT: 14, OBJECT: 35, SCALAR: 7) Operations: - Query: Query | fields: getAllBrands, getAllPlans, getDashboardAllBrands, getPlanDetails, getStripeCards - Mutation: Mutation | fields: createClaimRequest, createMembership, getToastBrands, getToastMenusItems, upgradeMembership Directives: deprecated, include, skip, specifiedBy (total: 4)
Open service 99.83.151.71:443 · api.bluekeys.io
2026-01-09 20:28
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Fri, 09 Jan 2026 20:28:24 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=dTDyl2sNmGDk%2B5H%2FsN76eqOEuwoMiyWSvNthhD2N5XQ%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767990504"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=dTDyl2sNmGDk%2B5H%2FsN76eqOEuwoMiyWSvNthhD2N5XQ%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767990504"
Server: Heroku
Set-Cookie: connect.sid=s%3AoDdEDBwOhMBcygDg_z6_kVfUfo66d9jf.pXg6OoIiRHYWL%2B6NBuaSqdx8IT0aU4MRrMROUIZh4lo; Path=/; Expires=Fri, 09 Jan 2026 21:28:24 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 35.71.145.101:80 · api.bluekeys.io
2026-01-08 23:40
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Thu, 08 Jan 2026 23:41:20 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=5yJO%2FCwYKcN8A%2F5GfsGgXtiIeVxtzOmA5kGgJcozivc%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767915680"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=5yJO%2FCwYKcN8A%2F5GfsGgXtiIeVxtzOmA5kGgJcozivc%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767915680"
Server: Heroku
Set-Cookie: connect.sid=s%3AlNTdvZf5p0H3WVWsiG9voA51aV-nR2yv.Nw4lLZMZIYluQohZIbL%2B6k0R3kQu8l7xEGBi54vn%2Fp0; Path=/; Expires=Fri, 09 Jan 2026 00:41:20 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 99.83.151.71:443 · api.bluekeys.io
2026-01-02 17:20
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Fri, 02 Jan 2026 17:20:41 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=qRIJzJhLZBRAmHWcxBjpzrrMe9%2FNwOGNFQN0UGwWlXg%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767374441"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=qRIJzJhLZBRAmHWcxBjpzrrMe9%2FNwOGNFQN0UGwWlXg%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767374441"
Server: Heroku
Set-Cookie: connect.sid=s%3AlYs4QssuJ-nMroYpGUw4H9d6EHEpto1R.npOov9X1IiQ%2B%2B5MYxmUta%2BgC3Rn8T6sZGujQtzIbE7E; Path=/; Expires=Fri, 02 Jan 2026 18:20:41 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 35.71.145.101:80 · api.bluekeys.io
2026-01-01 21:59
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Thu, 01 Jan 2026 22:00:02 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=7XFJHAOmDl9qtUFnx%2BBPLBF99ElhrAI0UET5ogjk%2F94%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767304802"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=7XFJHAOmDl9qtUFnx%2BBPLBF99ElhrAI0UET5ogjk%2F94%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767304802"
Server: Heroku
Set-Cookie: connect.sid=s%3Aj3B5n0dIJXWt2DWIvtEv-3hZFETgm8ui.JcsiG0Un%2FzxnG%2B2okg5cqlVu4MTUBhds4gdW%2FQGeR4Q; Path=/; Expires=Thu, 01 Jan 2026 23:00:02 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 35.71.145.101:80 · api.bluekeys.io
2025-12-30 06:35
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Tue, 30 Dec 2025 06:35:11 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=vK7ou%2BrVm9KtKDDq5EIbFxmDkWc%2FbKEZ5wUOaBwo0L4%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767076511"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=vK7ou%2BrVm9KtKDDq5EIbFxmDkWc%2FbKEZ5wUOaBwo0L4%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767076511"
Server: Heroku
Set-Cookie: connect.sid=s%3ArPcHRso_1nQkELjd9n8VDr83DVu0LqsJ.YNJhhXEuQNByPBm9U27%2FHjeGvLJVVunSjpaanY6aEiw; Path=/; Expires=Tue, 30 Dec 2025 07:35:11 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 99.83.151.71:443 · api.bluekeys.io
2025-12-23 01:30
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Tue, 23 Dec 2025 01:30:33 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Gdb0G3jlUN41G6Tg2K1fnnDO0htAX10KsXB0puXzId8%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766453433"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Gdb0G3jlUN41G6Tg2K1fnnDO0htAX10KsXB0puXzId8%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766453433"
Server: Heroku
Set-Cookie: connect.sid=s%3AqeVgviBCfzopI_nsht1EKTMKcS5TWlGz.xj1ADRzPluU35arQdNXmf0wmkYto%2FJeI2JJsxu4GUsU; Path=/; Expires=Tue, 23 Dec 2025 02:30:33 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 35.71.145.101:80 · api.bluekeys.io
2025-12-22 14:32
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Mon, 22 Dec 2025 14:32:54 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=etaYdQc9FCeA4nqi8PMa4dHkwGRjt1cb8gAIpQfICPY%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766413974"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=etaYdQc9FCeA4nqi8PMa4dHkwGRjt1cb8gAIpQfICPY%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766413974"
Server: Heroku
Set-Cookie: connect.sid=s%3ADFYaDRHLF9q3zPJg77N_yeb_0oVjrmhh.AEZL%2Bj8F3%2Bgoo4vWO%2FsGPSVvs0JYJuj%2B7i8dpcB4OoU; Path=/; Expires=Mon, 22 Dec 2025 15:32:54 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 99.83.151.71:443 · api.bluekeys.io
2025-12-20 14:57
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Sat, 20 Dec 2025 14:57:01 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=3c6uuU%2F8N%2Bn6S21YCicuNKEqZlGT1%2BvRMi8YqomZOWw%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766242621"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=3c6uuU%2F8N%2Bn6S21YCicuNKEqZlGT1%2BvRMi8YqomZOWw%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766242621"
Server: Heroku
Set-Cookie: connect.sid=s%3AnZy1vqntLrTLcUeD75UOE9bUcyOPXMe-.nobCt6M%2BfVj71azaiI258E6Qm8NO%2ByzUI3P3MI%2BUe%2BA; Path=/; Expires=Sat, 20 Dec 2025 15:57:01 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>
Open service 35.71.145.101:80 · api.bluekeys.io
2025-12-20 13:20
HTTP/1.1 404 Not Found
Access-Control-Allow-Credentials: true
Content-Length: 139
Content-Security-Policy: default-src 'none'
Content-Type: text/html; charset=utf-8
Date: Sat, 20 Dec 2025 13:20:47 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Rk%2Bwe8VY4SJuN5BSpF2w%2BXD%2FeR3wx1lD6yjsdd%2Be4Vo%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766236847"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Rk%2Bwe8VY4SJuN5BSpF2w%2BXD%2FeR3wx1lD6yjsdd%2Be4Vo%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766236847"
Server: Heroku
Set-Cookie: connect.sid=s%3AKb-Ju1S01MOdforfWrllf7DkMgC4mAP3.HDq3QjHhVVvd%2BPPpi5JH0lAAblR7%2F8v%2BFiN3DQAhgTk; Path=/; Expires=Sat, 20 Dec 2025 14:20:47 GMT; HttpOnly; SameSite=Strict
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Powered-By: Express
Connection: close
Page title: Error
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<title>Error</title>
</head>
<body>
<pre>Cannot GET /</pre>
</body>
</html>