Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035490d2e9b32472ceb0b945f78a42afe4927aaaba248
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/v1/fasttrack/bonus/all
GET /api/v1/fasttrack/userconsents/{userId}
GET /api/v1/igamingplatform
GET /health/v1/apiHealth/checkHealth
POST /api/v1/Cloudflare/PurgeDomainCache
POST /api/v1/Mimetic/SourceContentChanged
POST /api/v1/altenar
POST /api/v1/evolution/balance
POST /api/v1/evolution/cancel
POST /api/v1/evolution/check
POST /api/v1/evolution/credit
POST /api/v1/evolution/debit
POST /api/v1/evolution/promo_payout
POST /api/v1/evolution/sid
POST /api/v1/fasttrack/bonus/createclaim
POST /api/v1/fasttrack/bonus/credituser
POST /api/v1/fasttrack/userconsents
POST /api/v1/hub88/transaction/bet
POST /api/v1/hub88/transaction/rollback
POST /api/v1/hub88/transaction/win
POST /api/v1/hub88/user/balance
POST /api/v1/hub88/user/info
POST /api/v1/igamingdeck/player/balance
POST /api/v1/igamingdeck/player/info
POST /api/v1/igamingdeck/transaction/bet
POST /api/v1/igamingdeck/transaction/rollback
POST /api/v1/igamingdeck/transaction/win
POST /api/v1/octoplay/auth
POST /api/v1/octoplay/balance
POST /api/v1/octoplay/bet
POST /api/v1/octoplay/refund
POST /api/v1/octoplay/settlement
POST /api/v1/paymentiq/authorize
POST /api/v1/paymentiq/cancel
POST /api/v1/paymentiq/lookupuser
POST /api/v1/paymentiq/signin
POST /api/v1/paymentiq/transfer
POST /api/v1/paymentiq/verifyuser
POST /api/v1/paymid/webhook
POST /api/v1/playngo/authenticate
POST /api/v1/playngo/balance
POST /api/v1/playngo/cancelreserve
POST /api/v1/playngo/release
POST /api/v1/playngo/reserve
POST /api/v1/pragmatic/adjustment
POST /api/v1/pragmatic/authenticate
POST /api/v1/pragmatic/balance
POST /api/v1/pragmatic/bet
POST /api/v1/pragmatic/bonuswin
POST /api/v1/pragmatic/jackpotwin
POST /api/v1/pragmatic/promowin
POST /api/v1/pragmatic/refund
POST /api/v1/pragmatic/result
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035490d2e9b32472ceb0b945f78a42afe4927aaaba248
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/v1/fasttrack/bonus/all
GET /api/v1/fasttrack/userconsents/{userId}
GET /api/v1/igamingplatform
GET /health/v1/apiHealth/checkHealth
POST /api/v1/Cloudflare/PurgeDomainCache
POST /api/v1/Mimetic/SourceContentChanged
POST /api/v1/altenar
POST /api/v1/evolution/balance
POST /api/v1/evolution/cancel
POST /api/v1/evolution/check
POST /api/v1/evolution/credit
POST /api/v1/evolution/debit
POST /api/v1/evolution/promo_payout
POST /api/v1/evolution/sid
POST /api/v1/fasttrack/bonus/createclaim
POST /api/v1/fasttrack/bonus/credituser
POST /api/v1/fasttrack/userconsents
POST /api/v1/hub88/transaction/bet
POST /api/v1/hub88/transaction/rollback
POST /api/v1/hub88/transaction/win
POST /api/v1/hub88/user/balance
POST /api/v1/hub88/user/info
POST /api/v1/igamingdeck/player/balance
POST /api/v1/igamingdeck/player/info
POST /api/v1/igamingdeck/transaction/bet
POST /api/v1/igamingdeck/transaction/rollback
POST /api/v1/igamingdeck/transaction/win
POST /api/v1/octoplay/auth
POST /api/v1/octoplay/balance
POST /api/v1/octoplay/bet
POST /api/v1/octoplay/refund
POST /api/v1/octoplay/settlement
POST /api/v1/paymentiq/authorize
POST /api/v1/paymentiq/cancel
POST /api/v1/paymentiq/lookupuser
POST /api/v1/paymentiq/signin
POST /api/v1/paymentiq/transfer
POST /api/v1/paymentiq/verifyuser
POST /api/v1/paymid/webhook
POST /api/v1/playngo/authenticate
POST /api/v1/playngo/balance
POST /api/v1/playngo/cancelreserve
POST /api/v1/playngo/release
POST /api/v1/playngo/reserve
POST /api/v1/pragmatic/adjustment
POST /api/v1/pragmatic/authenticate
POST /api/v1/pragmatic/balance
POST /api/v1/pragmatic/bet
POST /api/v1/pragmatic/bonuswin
POST /api/v1/pragmatic/jackpotwin
POST /api/v1/pragmatic/promowin
POST /api/v1/pragmatic/refund
POST /api/v1/pragmatic/result
Open service 13.107.213.45:80 · integrations.geodeedge.com
2026-01-22 23:05
HTTP/1.1 404 Not Found Date: Thu, 22 Jan 2026 23:05:18 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20260122T230517Z-16f45f5c75b9w5llhC1BY1emcw0000000q3000000000d052 X-Cache: CONFIG_NOCACHE
Open service 13.107.213.45:443 · integrations.geodeedge.com
2026-01-22 22:40
HTTP/1.1 404 Not Found Date: Thu, 22 Jan 2026 22:40:48 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20260122T224048Z-17bcc8785fctbxrphC1FRAb0a000000012ag00000000cn5z X-Cache: CONFIG_NOCACHE
Open service 2001:41a8:44:4::4f8c:5f21:443 · integrations.geodeedge.com
2026-01-22 13:42
HTTP/1.1 404 Not Found Content-Length: 0 Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa Expires: Thu, 22 Jan 2026 13:42:17 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 22 Jan 2026 13:42:17 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Akamai-GRN: 0.2d5f8c4f.1769089327.1d4a4758 Akamai-Cache-Status: NotCacheable from child
Open service 2.16.204.91:443 · integrations.geodeedge.com
2026-01-22 13:42
HTTP/1.1 404 Not Found Content-Length: 0 Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa Expires: Thu, 22 Jan 2026 13:42:16 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 22 Jan 2026 13:42:16 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Akamai-GRN: 0.5b1d1002.1769089327.1bcd904e Akamai-Cache-Status: NotCacheable from child
Open service 2.16.204.91:80 · integrations.geodeedge.com
2026-01-22 13:42
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://integrations.geodeedge.com/ Expires: Thu, 22 Jan 2026 13:42:37 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 22 Jan 2026 13:42:37 GMT Connection: close Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Akamai-GRN: 0.5b1d1002.1769089348.1bce4194 Akamai-Cache-Status: NotCacheable from child
Open service 2.16.204.80:443 · integrations.geodeedge.com
2026-01-22 13:42
HTTP/1.1 404 Not Found Content-Length: 0 Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa Expires: Thu, 22 Jan 2026 13:42:17 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 22 Jan 2026 13:42:17 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Akamai-GRN: 0.5b1d1002.1769089327.1bcd93be Akamai-Cache-Status: NotCacheable from child
Open service 2001:41a8:44:4::4f8c:5f31:443 · integrations.geodeedge.com
2026-01-22 13:42
HTTP/1.1 404 Not Found Content-Length: 0 Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa Expires: Thu, 22 Jan 2026 13:42:15 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 22 Jan 2026 13:42:15 GMT Connection: close Alt-Svc: h3=":443"; ma=93600 Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Akamai-GRN: 0.2d5f8c4f.1769089327.1d4a44d0 Akamai-Cache-Status: NotCacheable from child
Open service 2.16.204.80:80 · integrations.geodeedge.com
2026-01-22 13:42
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://integrations.geodeedge.com/ Expires: Thu, 22 Jan 2026 13:42:37 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 22 Jan 2026 13:42:37 GMT Connection: close Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Akamai-GRN: 0.501d1002.1769089348.35827504 Akamai-Cache-Status: NotCacheable from child
Open service 2001:41a8:44:4::4f8c:5f31:80 · integrations.geodeedge.com
2026-01-22 13:42
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://integrations.geodeedge.com/ Expires: Thu, 22 Jan 2026 13:42:41 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 22 Jan 2026 13:42:41 GMT Connection: close Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Akamai-GRN: 0.2d5f8c4f.1769089351.1d4a84ab Akamai-Cache-Status: NotCacheable from child
Open service 2001:41a8:44:4::4f8c:5f21:80 · integrations.geodeedge.com
2026-01-22 13:42
HTTP/1.1 301 Moved Permanently Content-Length: 0 Location: https://integrations.geodeedge.com/ Expires: Thu, 22 Jan 2026 13:42:38 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Thu, 22 Jan 2026 13:42:38 GMT Connection: close Strict-Transport-Security: max-age=31536000; includeSubDomains; preload Akamai-GRN: 0.1d5f8c4f.1769089348.19d525a4 Akamai-Cache-Status: NotCacheable from child
Open service 13.107.213.45:443 · integrations.geodeedge.com
2026-01-10 02:40
HTTP/1.1 404 Not Found Date: Sat, 10 Jan 2026 02:40:37 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20260110T024037Z-17ff644dbb8tdn9jhC1YTO0unw00000005tg0000000068a5 X-Cache: CONFIG_NOCACHE
Open service 13.107.213.45:80 · integrations.geodeedge.com
2026-01-09 23:05
HTTP/1.1 404 Not Found Date: Fri, 09 Jan 2026 23:05:49 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20260109T230549Z-155869f5c8b7spg8hC1AMShvzw0000000f800000000064w6 X-Cache: CONFIG_NOCACHE
Open service 13.107.246.45:80 · integrations.geodeedge.com
2026-01-07 08:57
HTTP/1.1 404 Not Found Date: Wed, 07 Jan 2026 08:57:04 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20260107T085704Z-16596f7fdd9v8kbbhC1BOM176s00000004y000000000gnre X-Cache: CONFIG_NOCACHE
Open service 13.107.213.45:443 · integrations.geodeedge.com
2026-01-07 08:57
HTTP/1.1 404 Not Found Date: Wed, 07 Jan 2026 08:57:04 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20260107T085704Z-16596f7fdd9psbhshC1BOMrvvs0000000570000000002qza X-Cache: CONFIG_NOCACHE
Open service 13.107.246.45:443 · integrations.geodeedge.com
2026-01-07 08:57
HTTP/1.1 404 Not Found Date: Wed, 07 Jan 2026 08:57:03 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20260107T085703Z-15896bfcbb8trddghC1FRAczcg00000018x0000000013p9z X-Cache: CONFIG_NOCACHE
Open service 13.107.213.45:80 · integrations.geodeedge.com
2026-01-07 08:57
HTTP/1.1 404 Not Found Date: Wed, 07 Jan 2026 08:57:03 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20260107T085703Z-155869f5c8b6d6w2hC1AMSuw7g00000004xg00000000ysxu X-Cache: CONFIG_NOCACHE
Open service 13.107.213.45:80 · integrations.geodeedge.com
2026-01-02 04:28
HTTP/1.1 404 Not Found Date: Fri, 02 Jan 2026 04:28:52 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20260102T042852Z-16bdc6b75c9sbw7qhC1SG12pp40000000zp0000000003zaz X-Cache: CONFIG_NOCACHE
Open service 13.107.213.45:443 · integrations.geodeedge.com
2026-01-02 02:00
HTTP/1.1 404 Not Found Date: Fri, 02 Jan 2026 02:00:04 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20260102T020004Z-185d974d66682b4shC1FRA08bg00000002100000000092pd X-Cache: CONFIG_NOCACHE
Open service 13.107.213.45:80 · integrations.geodeedge.com
2025-12-23 09:25
HTTP/1.1 404 Not Found Date: Tue, 23 Dec 2025 09:25:51 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20251223T092551Z-16bdc6b75c9prwgphC1SG14utw0000000fwg00000000p4ak X-Cache: CONFIG_NOCACHE
Open service 13.107.213.45:443 · integrations.geodeedge.com
2025-12-23 09:25
HTTP/1.1 404 Not Found Date: Tue, 23 Dec 2025 09:25:51 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20251223T092550Z-r1d5f7d7665s7zprhC1BOM3z4w0000000kbg00000000khd9 X-Cache: CONFIG_NOCACHE
Open service 13.107.246.45:443 · integrations.geodeedge.com
2025-12-23 09:25
HTTP/1.1 404 Not Found Date: Tue, 23 Dec 2025 09:25:51 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20251223T092550Z-r1b65f586b9sjblmhC1YTOf988000000183g000000001txa X-Cache: CONFIG_NOCACHE
Open service 13.107.246.45:80 · integrations.geodeedge.com
2025-12-23 09:25
HTTP/1.1 404 Not Found Date: Tue, 23 Dec 2025 09:25:50 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20251223T092550Z-15896bfcbb8wcrpphC1FRAyhw80000001ey000000000k2s9 X-Cache: CONFIG_NOCACHE
Open service 13.107.213.45:80 · integrations.geodeedge.com
2025-12-22 23:57
HTTP/1.1 404 Not Found Date: Mon, 22 Dec 2025 23:57:41 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20251222T235741Z-r1ff49d4475t2btchC1AMS6we400000006zg00000000fg8p X-Cache: CONFIG_NOCACHE
Open service 13.107.213.45:443 · integrations.geodeedge.com
2025-12-22 19:48
HTTP/1.1 404 Not Found Date: Mon, 22 Dec 2025 19:48:29 GMT Content-Length: 0 Connection: close Request-Context: appId=cid-v1:94822c0f-b0de-4bc8-b368-492dea613dfa x-azure-ref: 20251222T194828Z-1776d656d4589m6thC1BY15yhw0000000swg00000000ab1p X-Cache: CONFIG_NOCACHE