cloudflare
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d6097be6cde90adffdfb4c1456c5b31190a5fc48c83
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths:
GET /AdminAccess/settings
GET /AdminAccess/user/{userId}
GET /AdminAccess/users
GET /AppConfiguration
GET /HealthCheck
GET /UserActivity/{userSteamId64}
GET /UserSessions/{userSteamId64}
GET /Users
GET /Users/details
GET /Users/get-referer
GET /connect/authorize
GET /connect/logout
POST /AdminAccess/user
POST /Users/activate
POST /Users/creator-role
POST /Users/deactivate
POST /Users/delete-creator-role/{userId}
POST /Users/delete-user/{userId}
POST /Users/mark-to-be-created-as-creator
POST /Users/set-referer
POST /Users/support-account
POST /Users/support-roles
POST /connect/token
PUT /AppConfiguration/force-refresh
Open service 104.21.66.20:443 · identity.dev.pirate-staging.com
2026-01-10 00:58
HTTP/1.1 404 Not Found
Date: Sat, 10 Jan 2026 00:58:37 GMT
Content-Length: 0
Connection: close
Set-Cookie: AWSALB=rG9gEluRYZAzp4WGq+9TP7qeyvvrKiSNlQLs3GFcdRBCS/eC1GQ94VpSi2mIuBHDUXqvtpMd1ksAI1trMvtmHSq5FU842abQKzeUhLsLDj+Ef0NzNslW0CkcVesw; Expires=Sat, 17 Jan 2026 00:58:37 GMT; Path=/
Set-Cookie: AWSALBCORS=rG9gEluRYZAzp4WGq+9TP7qeyvvrKiSNlQLs3GFcdRBCS/eC1GQ94VpSi2mIuBHDUXqvtpMd1ksAI1trMvtmHSq5FU842abQKzeUhLsLDj+Ef0NzNslW0CkcVesw; Expires=Sat, 17 Jan 2026 00:58:37 GMT; Path=/; SameSite=None; Secure
Server: cloudflare
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=FGHRoIOL3JbIHkj4O2GJ1chD%2BeSIcmDPLILjy1GklPymcYEOLLQPiuiCYqGi0NoTXSs0oSop9V6KogYwGwXdkIRCk9XYKqeTv5b4tWPU4EV%2B28I8RW2fXN6kaVIUu6Y%3D"}]}
CF-RAY: 9bb83a1e5f2baac8-YYZ
alt-svc: h3=":443"; ma=86400
Open service 104.21.66.20:443 · identity.dev.pirate-staging.com
2026-01-02 19:22
HTTP/1.1 404 Not Found
Date: Fri, 02 Jan 2026 19:22:32 GMT
Content-Length: 0
Connection: close
Set-Cookie: AWSALB=0rPOIw8dW7xVIT9VldFMG8IhWPvTAO58DqGX8MscHKp2yH6nArZJ3LJWvFpFwV7wU6zFuR4L8KQqHcDKyRYz/fh3T+mC5wcmkeBFTWS+l5tq6VEpsEQO1yE1pNRx; Expires=Fri, 09 Jan 2026 19:22:31 GMT; Path=/
Set-Cookie: AWSALBCORS=0rPOIw8dW7xVIT9VldFMG8IhWPvTAO58DqGX8MscHKp2yH6nArZJ3LJWvFpFwV7wU6zFuR4L8KQqHcDKyRYz/fh3T+mC5wcmkeBFTWS+l5tq6VEpsEQO1yE1pNRx; Expires=Fri, 09 Jan 2026 19:22:31 GMT; Path=/; SameSite=None; Secure
Server: cloudflare
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=1ydSIC%2B0UFpTcLmZdQIJF7zYrR5gb80gQ7LWf5D1uwRApyl07Jig7X8nIt34qUWT2%2FGGvDvEcTXjVkoq8AtvmSrYTlTA6bV7rfe0HMkgDtAKioGyOUxANOzSk009SKc%3D"}]}
CF-RAY: 9b7ca02b1bccfd26-SIN
alt-svc: h3=":443"; ma=86400
Open service 104.21.66.20:443 · identity.dev.pirate-staging.com
2025-12-22 21:07
HTTP/1.1 404 Not Found
Date: Mon, 22 Dec 2025 21:07:42 GMT
Content-Length: 0
Connection: close
Set-Cookie: AWSALB=oTpSeUDHpxjy5oET97PEcS6V3mbsz2B5CXkJD+ftHxNWAlUHsETBykHk90IOJ1puuNnAJ4Gj5L+oPbSV8Lf4Kuc60wtlZHp0ODTPSvSS+hd/SXh79lpjWK4idZ1D; Expires=Mon, 29 Dec 2025 21:07:42 GMT; Path=/
Set-Cookie: AWSALBCORS=oTpSeUDHpxjy5oET97PEcS6V3mbsz2B5CXkJD+ftHxNWAlUHsETBykHk90IOJ1puuNnAJ4Gj5L+oPbSV8Lf4Kuc60wtlZHp0ODTPSvSS+hd/SXh79lpjWK4idZ1D; Expires=Mon, 29 Dec 2025 21:07:42 GMT; Path=/; SameSite=None; Secure
Server: cloudflare
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=18,cfOrigin;dur=471
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=euPOvEDjBy5nAafQU3YAGHGC9WCRCxs1uAVornM96iVv07gbUgWwzQP2iLdq7lHFcc1f6mTocKXdoKbmkCwvTLX0bfaOXGDoWYdkaX%2B4caTd6F5doiSBgoBh6ivXJFw%3D"}]}
CF-RAY: 9b22971a989d67dd-SJC
alt-svc: h3=":443"; ma=86400
Open service 104.21.66.20:443 · identity.dev.pirate-staging.com
2025-12-20 21:48
HTTP/1.1 404 Not Found
Date: Sat, 20 Dec 2025 21:48:43 GMT
Content-Length: 0
Connection: close
Set-Cookie: AWSALB=sslFOgnNJuxIj0J4cG4B6lSr71E+Ef8j4GSnKSOPFtTkn4Pnegb/UnMCLFvPYwH5pfc8fkPwoQWacmb+bdoW50NqtHl/pGf8Aqd5SuCamRge7aoAm8v7L9gSWKwy; Expires=Sat, 27 Dec 2025 21:48:43 GMT; Path=/
Set-Cookie: AWSALBCORS=sslFOgnNJuxIj0J4cG4B6lSr71E+Ef8j4GSnKSOPFtTkn4Pnegb/UnMCLFvPYwH5pfc8fkPwoQWacmb+bdoW50NqtHl/pGf8Aqd5SuCamRge7aoAm8v7L9gSWKwy; Expires=Sat, 27 Dec 2025 21:48:43 GMT; Path=/; SameSite=None; Secure
Server: cloudflare
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=11,cfOrigin;dur=374
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=pUi6FA%2BsUMQizwlBD6qMYlE1Jtu0Y4a%2FMIt6EqX4HjUCTrEooddZeWQXvusFnckXL7sv2E58W%2F2CjEj4B%2BRzB2I6H909RpMA2YNOkxadbgKyUdyuv%2BXrfdFMyLkO9kw%3D"}]}
CF-RAY: 9b12586fae720028-BOM
alt-svc: h3=":443"; ma=86400