Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354959d91597c679b180052c7c722d427aaa44c4d36a
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/About/Version
GET /v1/Configuration/check-licenses
GET /v1/Integrations
GET /v1/Integrations/$count
GET /v1/Integrations/Elastic.Integrations.API.EnableSharePoint
GET /v1/Integrations/Elastic.Integrations.API.EnableSharePointCallback
GET /v1/Integrations/EnableSharePoint
GET /v1/Integrations/EnableSharePointCallback
GET /v1/{organizationId}/GoogleCloud/GetConfiguration
GET /v1/{organizationId}/GoogleDrive/Search
POST /v1/AI/Buddy
POST /v1/AI/Chat
POST /v1/AI/GenerateImage
POST /v1/AI/IdentifyNotAllowedContent
POST /v1/AI/SendPageBlocksToLLM
POST /v1/Integrations/DisableAirly
POST /v1/Integrations/DisableAzureMaps
POST /v1/Integrations/DisableDarkSky
POST /v1/Integrations/DisablePexels
POST /v1/Integrations/DisableSharePoint
POST /v1/Integrations/EnableAirly
POST /v1/Integrations/EnableAzureMaps
POST /v1/Integrations/EnableDarkSky
POST /v1/Integrations/EnablePexels
POST /v1/{organizationId}/GoogleCloud/UploadConfiguration
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354959d91597722fd07d6377bd5326241a40a44281eb
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/About/Version
GET /v1/Integrations
GET /v1/Integrations/$count
GET /v1/Integrations/Elastic.Integrations.API.EnableSharePoint
GET /v1/Integrations/Elastic.Integrations.API.EnableSharePointCallback
GET /v1/Integrations/EnableSharePoint
GET /v1/Integrations/EnableSharePointCallback
GET /v1/{organizationId}/GoogleCloud/GetConfiguration
GET /v1/{organizationId}/GoogleDrive/Search
POST /v1/AI/Buddy
POST /v1/AI/Chat
POST /v1/AI/GenerateImage
POST /v1/AI/IdentifyNotAllowedContent
POST /v1/AI/SendPageBlocksToLLM
POST /v1/Integrations/DisableAirly
POST /v1/Integrations/DisableAzureMaps
POST /v1/Integrations/DisableDarkSky
POST /v1/Integrations/DisablePexels
POST /v1/Integrations/DisableSharePoint
POST /v1/Integrations/EnableAirly
POST /v1/Integrations/EnableAzureMaps
POST /v1/Integrations/EnableDarkSky
POST /v1/Integrations/EnablePexels
POST /v1/{organizationId}/GoogleCloud/UploadConfiguration
Open service 20.105.224.45:443 · integrations.dev.workai.cloud
2026-01-23 02:12
HTTP/1.1 200 OK Connection: close Content-Type: text/plain; charset=utf-8 Date: Fri, 23 Jan 2026 02:13:20 GMT Set-Cookie: ARRAffinity=ffbca59b025949de884b4d868d5979b22329f43e038fd0828f4548a11a1dec35;Path=/;HttpOnly;Secure;Domain=integrations.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=ffbca59b025949de884b4d868d5979b22329f43e038fd0828f4548a11a1dec35;Path=/;HttpOnly;SameSite=None;Secure;Domain=integrations.dev.workai.cloud Transfer-Encoding: chunked Strict-Transport-Security: max-age=2592000 x-trace-id: 2b493a13578ec043134637219a4269c1 healthy
Open service 20.105.224.45:443 · integrations.dev.workai.cloud
2026-01-10 02:34
HTTP/1.1 200 OK Connection: close Content-Type: text/plain; charset=utf-8 Date: Sat, 10 Jan 2026 02:35:56 GMT Set-Cookie: ARRAffinity=e8c3b4220b9f97cf537feeb7ca8d7ede0c132f0c307819c4775a3815213a81d8;Path=/;HttpOnly;Secure;Domain=integrations.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=e8c3b4220b9f97cf537feeb7ca8d7ede0c132f0c307819c4775a3815213a81d8;Path=/;HttpOnly;SameSite=None;Secure;Domain=integrations.dev.workai.cloud Transfer-Encoding: chunked Strict-Transport-Security: max-age=2592000 x-trace-id: e35fe6dbbb339255f7e8c64791a4f97f healthy
Open service 20.105.224.45:443 · integrations.dev.workai.cloud
2026-01-02 22:50
HTTP/1.1 200 OK Connection: close Content-Type: text/plain; charset=utf-8 Date: Fri, 02 Jan 2026 22:50:58 GMT Set-Cookie: ARRAffinity=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;Secure;Domain=integrations.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;SameSite=None;Secure;Domain=integrations.dev.workai.cloud Transfer-Encoding: chunked Strict-Transport-Security: max-age=2592000 x-trace-id: 87c9b21b9acec9ff1cf6dc3e7d97b59d healthy
Open service 20.105.224.45:443 · integrations.dev.workai.cloud
2025-12-22 17:36
HTTP/1.1 200 OK Connection: close Content-Type: text/plain; charset=utf-8 Date: Mon, 22 Dec 2025 17:36:02 GMT Set-Cookie: ARRAffinity=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;Secure;Domain=integrations.dev.workai.cloud Set-Cookie: ARRAffinitySameSite=c543959e5077d0986f050d1a42deca797651565c18ae97e0cfa9d81d8544de3d;Path=/;HttpOnly;SameSite=None;Secure;Domain=integrations.dev.workai.cloud Transfer-Encoding: chunked Strict-Transport-Security: max-age=2592000 x-trace-id: 96d605a2604eb436700935279c77518d healthy