Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549a63423627ed9590b8b541ce006b312ff1f100a1b
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/v1/Benefits/CancelSubscription/{claimId}
DELETE /api/v1/PaymentMethods/{id}
DELETE /api/v1/Rfids/{id}
DELETE /api/v1/Users/CloseAccount
DELETE /api/v1/Vehicles/{id}
GET /api/v1/Benefits
GET /api/v1/Benefits/AvailableContractDetails/{contractId}
GET /api/v1/Benefits/AvailableContracts/{spaceId}
GET /api/v1/Benefits/AvailableSubscriptionDetails/{subscriptionId}
GET /api/v1/Benefits/Avinor
GET /api/v1/Benefits/Feide
GET /api/v1/Benefits/Feide/{claimId}
GET /api/v1/Benefits/GetAvinorEmployerOptions/{airportIcaoCode}
GET /api/v1/Benefits/Hc
GET /api/v1/Benefits/Invitation/{id}
GET /api/v1/Benefits/Voucher/{voucherCode}
GET /api/v1/Benefits/{claimId}
GET /api/v1/Benefits/{grantingBenefitId}/AvailableSubscriptions
GET /api/v1/Corporates
GET /api/v1/Corporates/Vehicles
GET /api/v1/EvChargers/{spaceId}
GET /api/v1/PaymentMethods
GET /api/v1/PaymentMethods/StartNmiPaymentSubscription
GET /api/v1/Prices
GET /api/v1/Prices/LengthOfStayPresets
GET /api/v1/Prices/UpdatedPrice
GET /api/v1/Receipts/Download/{receiptId}
GET /api/v1/Rfids
GET /api/v1/Search
GET /api/v1/Search/SearchContractSpaces
GET /api/v1/Sessions
GET /api/v1/SessionsHistory
GET /api/v1/SessionsHistory/Anonymous
GET /api/v1/SessionsHistory/Anonymous/Batch/{sessionIds}
GET /api/v1/SessionsHistory/Anonymous/{sessionId}
GET /api/v1/SessionsHistory/{sessionId}
GET /api/v1/Spaces/GetByBoundingBox
GET /api/v1/Spaces/{spaceId}
GET /api/v1/SubscriptionsHistory
GET /api/v1/SubscriptionsHistory/{subscriptionRenewId}
GET /api/v1/Users/NotificationsSetting
GET /api/v1/Users/Privacy
GET /api/v1/Users/Profile
GET /api/v1/Users/Settings
GET /api/v1/Users/Terms
GET /api/v1/Vehicles
PATCH /api/v1/Vehicles/UpdateAnprAutoPayment/{vehicleId}
POST /api/v1/Auth/AcceptTerms
POST /api/v1/Auth/Initialize
POST /api/v1/Auth/RequestPasswordReset
POST /api/v1/Auth/ResendOtp
POST /api/v1/Auth/SetPassword
POST /api/v1/Auth/Token/FaToken
POST /api/v1/Auth/Token/Password
POST /api/v1/Auth/Token/SMS
POST /api/v1/Auth/Token/SmsPasswordReset
POST /api/v1/Benefits/ClaimAvinor
POST /api/v1/Benefits/ClaimContract/{contractId}
POST /api/v1/Benefits/ClaimFeide
POST /api/v1/Benefits/ClaimGeneric/{claimId}
POST /api/v1/Benefits/ClaimHc/{code}
POST /api/v1/Benefits/ClaimSubscription/{subscriptionId}
POST /api/v1/Benefits/ClaimVoucher/{voucherCode}
POST /api/v1/Benefits/OpenDoor/{doorId}
POST /api/v1/Corporates/Apply
POST /api/v1/PaymentMethods/FinalizeNmiPaymentSubscription
POST /api/v1/PaymentMethods/FinalizePaymentSubscription
POST /api/v1/PaymentMethods/SetDefault/{id}
POST /api/v1/PaymentMethods/StartNetsPaymentSubscription
POST /api/v1/PaymentMethods/StartStripePaymentSubscription
POST /api/v1/PaymentMethods/StartVippsPaymentSubscription
POST /api/v1/Payments/FinalizeOneTimeNetsPayment/{externalId}
POST /api/v1/Payments/OneTimeNetsPaymentForSession/{sessionId}
POST /api/v1/Payments/OneTimeStripePaymentForSession/{sessionId}
POST /api/v1/Payments/OneTimeVippsPaymentForSession/{sessionId}
POST /api/v1/Payments/PayForSession/{sessionId}
POST /api/v1/Payments/PayForSubscription/{subscriptionRenewId}
POST /api/v1/Sessions/StartCharging
POST /api/v1/Sessions/StartParking
POST /api/v1/Sessions/StopCharging/{sessionId}
POST /api/v1/Sessions/StopParking
POST /api/v1/Sessions/StopParking/{sessionId}
POST /api/v1/Sessions/UpdateParkingDuration
POST /api/v1/Users/AcceptTerms
POST /api/v1/Users/UpsertUserDevice
POST /api/v1/Vehicles/Create
PUT /api/v1/Benefits/UpdateLicensePlates/{claimId}
PUT /api/v1/Benefits/UpdatePaymentMethod/{claimId}
PUT /api/v1/Users/AddOrRefreshPushToken
PUT /api/v1/Users/UpdateAutoPaymentLimitSetting
PUT /api/v1/Users/UpdateEmail
PUT /api/v1/Users/UpdateLanguage
PUT /api/v1/Users/UpdateName
PUT /api/v1/Users/UpdateNotificationsSetting
PUT /api/v1/Vehicles/UpdateDescription/{vehicleId}
PUT /api/v1/Vehicles/UpdateValidity/{vehicleId}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549a63423627ed9590b8b541ce006b312ff14ae221d
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/v1/Benefits/CancelSubscription/{claimId}
DELETE /api/v1/PaymentMethods/{id}
DELETE /api/v1/Rfids/{id}
DELETE /api/v1/Users/CloseAccount
DELETE /api/v1/Vehicles/{id}
GET /api/v1/Benefits
GET /api/v1/Benefits/AvailableContractDetails/{contractId}
GET /api/v1/Benefits/AvailableContracts/{spaceId}
GET /api/v1/Benefits/AvailableSubscriptionDetails/{subscriptionId}
GET /api/v1/Benefits/Avinor
GET /api/v1/Benefits/CPS
GET /api/v1/Benefits/Feide
GET /api/v1/Benefits/Feide/{claimId}
GET /api/v1/Benefits/GetAvinorEmployerOptions/{airportIcaoCode}
GET /api/v1/Benefits/Hc
GET /api/v1/Benefits/Invitation/{id}
GET /api/v1/Benefits/Voucher/{voucherCode}
GET /api/v1/Benefits/{claimId}
GET /api/v1/Benefits/{grantingBenefitId}/AvailableSubscriptions
GET /api/v1/Corporates
GET /api/v1/Corporates/Vehicles
GET /api/v1/EvChargers/{spaceId}
GET /api/v1/PaymentMethods
GET /api/v1/PaymentMethods/StartNmiPaymentSubscription
GET /api/v1/Prices
GET /api/v1/Prices/LengthOfStayPresets
GET /api/v1/Prices/UpdatedPrice
GET /api/v1/Receipts/Download/{receiptId}
GET /api/v1/Rfids
GET /api/v1/Search
GET /api/v1/Search/SearchContractSpaces
GET /api/v1/Sessions
GET /api/v1/SessionsHistory
GET /api/v1/SessionsHistory/Anonymous
GET /api/v1/SessionsHistory/Anonymous/Batch/{sessionIds}
GET /api/v1/SessionsHistory/Anonymous/{sessionId}
GET /api/v1/SessionsHistory/{sessionId}
GET /api/v1/Spaces/GetByBoundingBox
GET /api/v1/Spaces/{spaceId}
GET /api/v1/SubscriptionsHistory
GET /api/v1/SubscriptionsHistory/{subscriptionRenewId}
GET /api/v1/Users/NotificationsSetting
GET /api/v1/Users/Privacy
GET /api/v1/Users/Profile
GET /api/v1/Users/Settings
GET /api/v1/Users/Terms
GET /api/v1/Vehicles
PATCH /api/v1/Vehicles/UpdateAnprAutoPayment/{vehicleId}
POST /api/v1/Auth/AcceptTerms
POST /api/v1/Auth/Initialize
POST /api/v1/Auth/RequestPasswordReset
POST /api/v1/Auth/ResendOtp
POST /api/v1/Auth/SetPassword
POST /api/v1/Auth/Token/FaToken
POST /api/v1/Auth/Token/Password
POST /api/v1/Auth/Token/SMS
POST /api/v1/Auth/Token/SmsPasswordReset
POST /api/v1/Benefits/ClaimAvinor
POST /api/v1/Benefits/ClaimCPS
POST /api/v1/Benefits/ClaimContract/{contractId}
POST /api/v1/Benefits/ClaimFeide
POST /api/v1/Benefits/ClaimGeneric/{claimId}
POST /api/v1/Benefits/ClaimHc/{code}
POST /api/v1/Benefits/ClaimSubscription/{subscriptionId}
POST /api/v1/Benefits/ClaimVoucher/{voucherCode}
POST /api/v1/Benefits/OpenDoor/{doorId}
POST /api/v1/Corporates/Apply
POST /api/v1/PaymentMethods/FinalizeNmiPaymentSubscription
POST /api/v1/PaymentMethods/FinalizePaymentSubscription
POST /api/v1/PaymentMethods/SetDefault/{id}
POST /api/v1/PaymentMethods/StartNetsPaymentSubscription
POST /api/v1/PaymentMethods/StartStripePaymentSubscription
POST /api/v1/PaymentMethods/StartVippsPaymentSubscription
POST /api/v1/Payments/FinalizeOneTimeNetsPayment/{externalId}
POST /api/v1/Payments/OneTimeNetsPaymentForSession/{sessionId}
POST /api/v1/Payments/OneTimeStripePaymentForSession/{sessionId}
POST /api/v1/Payments/OneTimeVippsPaymentForSession/{sessionId}
POST /api/v1/Payments/PayForSession/{sessionId}
POST /api/v1/Payments/PayForSubscription/{subscriptionRenewId}
POST /api/v1/Sessions/StartCharging
POST /api/v1/Sessions/StartParking
POST /api/v1/Sessions/StopCharging/{sessionId}
POST /api/v1/Sessions/StopParking/{sessionId}
POST /api/v1/Sessions/UpdateParkingDuration
POST /api/v1/Users/AcceptTerms
POST /api/v1/Users/UpsertUserDevice
POST /api/v1/Vehicles/Create
POST /ngrok/register
PUT /api/v1/Benefits/UpdateLicensePlates/{claimId}
PUT /api/v1/Benefits/UpdatePaymentMethod/{claimId}
PUT /api/v1/Users/AddOrRefreshPushToken
PUT /api/v1/Users/UpdateAutoPaymentLimitSetting
PUT /api/v1/Users/UpdateEmail
PUT /api/v1/Users/UpdateLanguage
PUT /api/v1/Users/UpdateName
PUT /api/v1/Users/UpdateNotificationsSetting
PUT /api/v1/Vehicles/UpdateDescription/{vehicleId}
PUT /api/v1/Vehicles/UpdateValidity/{vehicleId}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549a63423627ed9590b8b541ce006b312fff49c6ae5
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/v1/Benefits/CancelSubscription/{claimId}
DELETE /api/v1/PaymentMethods/{id}
DELETE /api/v1/Rfids/{id}
DELETE /api/v1/Users/CloseAccount
DELETE /api/v1/Vehicles/{id}
GET /api/v1/Benefits
GET /api/v1/Benefits/AvailableContractDetails/{contractId}
GET /api/v1/Benefits/AvailableContracts/{spaceId}
GET /api/v1/Benefits/AvailableSubscriptionDetails/{subscriptionId}
GET /api/v1/Benefits/Avinor
GET /api/v1/Benefits/Feide
GET /api/v1/Benefits/Feide/{claimId}
GET /api/v1/Benefits/GetAvinorEmployerOptions/{airportIcaoCode}
GET /api/v1/Benefits/Hc
GET /api/v1/Benefits/Invitation/{id}
GET /api/v1/Benefits/Voucher/{voucherCode}
GET /api/v1/Benefits/{claimId}
GET /api/v1/Benefits/{grantingBenefitId}/AvailableSubscriptions
GET /api/v1/Corporates
GET /api/v1/Corporates/Vehicles
GET /api/v1/EvChargers/{spaceId}
GET /api/v1/PaymentMethods
GET /api/v1/PaymentMethods/StartNmiPaymentSubscription
GET /api/v1/Prices
GET /api/v1/Prices/LengthOfStayPresets
GET /api/v1/Prices/UpdatedPrice
GET /api/v1/Receipts/Download/{receiptId}
GET /api/v1/Rfids
GET /api/v1/Search
GET /api/v1/Search/SearchContractSpaces
GET /api/v1/Sessions
GET /api/v1/SessionsHistory
GET /api/v1/SessionsHistory/Anonymous
GET /api/v1/SessionsHistory/Anonymous/Batch/{sessionIds}
GET /api/v1/SessionsHistory/Anonymous/{sessionId}
GET /api/v1/SessionsHistory/{sessionId}
GET /api/v1/Spaces/GetByBoundingBox
GET /api/v1/Spaces/{spaceId}
GET /api/v1/SubscriptionsHistory
GET /api/v1/SubscriptionsHistory/{subscriptionRenewId}
GET /api/v1/Users/NotificationsSetting
GET /api/v1/Users/Privacy
GET /api/v1/Users/Profile
GET /api/v1/Users/Settings
GET /api/v1/Users/Terms
GET /api/v1/Vehicles
PATCH /api/v1/Vehicles/UpdateAnprAutoPayment/{vehicleId}
POST /api/v1/Auth/AcceptTerms
POST /api/v1/Auth/Initialize
POST /api/v1/Auth/RequestPasswordReset
POST /api/v1/Auth/ResendOtp
POST /api/v1/Auth/SetPassword
POST /api/v1/Auth/Token/FaToken
POST /api/v1/Auth/Token/Password
POST /api/v1/Auth/Token/SMS
POST /api/v1/Auth/Token/SmsPasswordReset
POST /api/v1/Benefits/ClaimAvinor
POST /api/v1/Benefits/ClaimContract/{contractId}
POST /api/v1/Benefits/ClaimFeide
POST /api/v1/Benefits/ClaimGeneric/{claimId}
POST /api/v1/Benefits/ClaimHc/{code}
POST /api/v1/Benefits/ClaimSubscription/{subscriptionId}
POST /api/v1/Benefits/ClaimVoucher/{voucherCode}
POST /api/v1/Benefits/OpenDoor/{doorId}
POST /api/v1/Corporates/Apply
POST /api/v1/PaymentMethods/FinalizeNmiPaymentSubscription
POST /api/v1/PaymentMethods/FinalizePaymentSubscription
POST /api/v1/PaymentMethods/SetDefault/{id}
POST /api/v1/PaymentMethods/StartNetsPaymentSubscription
POST /api/v1/PaymentMethods/StartStripePaymentSubscription
POST /api/v1/PaymentMethods/StartVippsPaymentSubscription
POST /api/v1/Payments/FinalizeOneTimeNetsPayment/{externalId}
POST /api/v1/Payments/OneTimeNetsPaymentForSession/{sessionId}
POST /api/v1/Payments/OneTimeStripePaymentForSession/{sessionId}
POST /api/v1/Payments/OneTimeVippsPaymentForSession/{sessionId}
POST /api/v1/Payments/PayForSession/{sessionId}
POST /api/v1/Payments/PayForSubscription/{subscriptionRenewId}
POST /api/v1/Sessions/StartCharging
POST /api/v1/Sessions/StartParking
POST /api/v1/Sessions/StopCharging/{sessionId}
POST /api/v1/Sessions/StopParking/{sessionId}
POST /api/v1/Sessions/UpdateParkingDuration
POST /api/v1/Users/AcceptTerms
POST /api/v1/Users/UpsertUserDevice
POST /api/v1/Vehicles/Create
POST /ngrok/register
PUT /api/v1/Benefits/UpdateLicensePlates/{claimId}
PUT /api/v1/Benefits/UpdatePaymentMethod/{claimId}
PUT /api/v1/Users/AddOrRefreshPushToken
PUT /api/v1/Users/UpdateAutoPaymentLimitSetting
PUT /api/v1/Users/UpdateEmail
PUT /api/v1/Users/UpdateLanguage
PUT /api/v1/Users/UpdateName
PUT /api/v1/Users/UpdateNotificationsSetting
PUT /api/v1/Vehicles/UpdateDescription/{vehicleId}
PUT /api/v1/Vehicles/UpdateValidity/{vehicleId}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549a63423627ed9590b8b541ce006b312ff0ac40277
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/v1/Benefits/CancelSubscription/{claimId}
DELETE /api/v1/PaymentMethods/{id}
DELETE /api/v1/Rfids/{id}
DELETE /api/v1/Users/CloseAccount
DELETE /api/v1/Vehicles/{id}
GET /api/v1/Benefits
GET /api/v1/Benefits/AvailableContractDetails/{contractId}
GET /api/v1/Benefits/AvailableContracts/{spaceId}
GET /api/v1/Benefits/AvailableSubscriptionDetails/{subscriptionId}
GET /api/v1/Benefits/Avinor
GET /api/v1/Benefits/Feide
GET /api/v1/Benefits/Feide/{claimId}
GET /api/v1/Benefits/GetAvinorEmployerOptions/{airportIcaoCode}
GET /api/v1/Benefits/Hc
GET /api/v1/Benefits/Invitation/{id}
GET /api/v1/Benefits/Voucher/{voucherCode}
GET /api/v1/Benefits/{claimId}
GET /api/v1/Benefits/{grantingBenefitId}/AvailableSubscriptions
GET /api/v1/Corporates
GET /api/v1/Corporates/Vehicles
GET /api/v1/EvChargers/{spaceId}
GET /api/v1/PaymentMethods
GET /api/v1/PaymentMethods/StartNmiPaymentSubscription
GET /api/v1/Prices
GET /api/v1/Prices/LengthOfStayPresets
GET /api/v1/Prices/UpdatedPrice
GET /api/v1/Receipts/Download/{receiptId}
GET /api/v1/Rfids
GET /api/v1/Search
GET /api/v1/Search/SearchContractSpaces
GET /api/v1/Sessions
GET /api/v1/SessionsHistory
GET /api/v1/SessionsHistory/Anonymous
GET /api/v1/SessionsHistory/Anonymous/Batch/{sessionIds}
GET /api/v1/SessionsHistory/Anonymous/{sessionId}
GET /api/v1/SessionsHistory/{sessionId}
GET /api/v1/Spaces/GetByBoundingBox
GET /api/v1/Spaces/{spaceId}
GET /api/v1/SubscriptionsHistory
GET /api/v1/SubscriptionsHistory/{subscriptionRenewId}
GET /api/v1/Users/NotificationsSetting
GET /api/v1/Users/Privacy
GET /api/v1/Users/Profile
GET /api/v1/Users/Settings
GET /api/v1/Users/Terms
GET /api/v1/Vehicles
PATCH /api/v1/Vehicles/UpdateAnprAutoPayment/{vehicleId}
POST /api/v1/Auth/AcceptTerms
POST /api/v1/Auth/Initialize
POST /api/v1/Auth/RequestPasswordReset
POST /api/v1/Auth/ResendOtp
POST /api/v1/Auth/SetPassword
POST /api/v1/Auth/Token/FaToken
POST /api/v1/Auth/Token/Password
POST /api/v1/Auth/Token/SMS
POST /api/v1/Auth/Token/SmsPasswordReset
POST /api/v1/Benefits/ClaimAvinor
POST /api/v1/Benefits/ClaimContract/{contractId}
POST /api/v1/Benefits/ClaimFeide
POST /api/v1/Benefits/ClaimGeneric/{claimId}
POST /api/v1/Benefits/ClaimHc/{code}
POST /api/v1/Benefits/ClaimSubscription/{subscriptionId}
POST /api/v1/Benefits/ClaimVoucher/{voucherCode}
POST /api/v1/Benefits/OpenDoor/{doorId}
POST /api/v1/Corporates/Apply
POST /api/v1/PaymentMethods/FinalizeNmiPaymentSubscription
POST /api/v1/PaymentMethods/FinalizePaymentSubscription
POST /api/v1/PaymentMethods/SetDefault/{id}
POST /api/v1/PaymentMethods/StartNetsPaymentSubscription
POST /api/v1/PaymentMethods/StartStripePaymentSubscription
POST /api/v1/PaymentMethods/StartVippsPaymentSubscription
POST /api/v1/Payments/FinalizeOneTimeNetsPayment/{externalId}
POST /api/v1/Payments/OneTimeNetsPaymentForSession/{sessionId}
POST /api/v1/Payments/OneTimeStripePaymentForSession/{sessionId}
POST /api/v1/Payments/OneTimeVippsPaymentForSession/{sessionId}
POST /api/v1/Payments/PayForSession/{sessionId}
POST /api/v1/Payments/PayForSubscription/{subscriptionRenewId}
POST /api/v1/Sessions/StartCharging
POST /api/v1/Sessions/StartParking
POST /api/v1/Sessions/StopCharging/{sessionId}
POST /api/v1/Sessions/StopParking
POST /api/v1/Sessions/StopParking/{sessionId}
POST /api/v1/Sessions/UpdateParkingDuration
POST /api/v1/Users/AcceptTerms
POST /api/v1/Users/UpsertUserDevice
POST /api/v1/Vehicles/Create
POST /ngrok/register
PUT /api/v1/Benefits/UpdateLicensePlates/{claimId}
PUT /api/v1/Benefits/UpdatePaymentMethod/{claimId}
PUT /api/v1/Users/AddOrRefreshPushToken
PUT /api/v1/Users/UpdateAutoPaymentLimitSetting
PUT /api/v1/Users/UpdateEmail
PUT /api/v1/Users/UpdateLanguage
PUT /api/v1/Users/UpdateName
PUT /api/v1/Users/UpdateNotificationsSetting
PUT /api/v1/Vehicles/UpdateDescription/{vehicleId}
PUT /api/v1/Vehicles/UpdateValidity/{vehicleId}
Open service 20.105.224.17:443 ยท flownextbff.dev.nucleus.valuespaces.io
2026-01-22 23:25
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Thu, 22 Jan 2026 23:26:14 GMT Server: Kestrel Set-Cookie: TiPMix=95.0039926075659; path=/; HttpOnly; Domain=flownextbff.dev.nucleus.valuespaces.io; Max-Age=3600; Secure; SameSite=None Set-Cookie: x-ms-routing-name=self; path=/; HttpOnly; Domain=flownextbff.dev.nucleus.valuespaces.io; Max-Age=3600; Secure; SameSite=None Request-Context: appId=cid-v1:7b7fd5f2-c6fc-4183-8515-da73395f3a1a X-TRACE-ID: 253fc0ec55d04f3ebe639f65d4ace9a2