Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bce42db947c37314315ebc104a4c55fc6ffca5392
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /document/{id}
DELETE /envelope/{envelopeId}/documents/{documentId}/recipient/{recipientId}
GET /documents
GET /documents/documentCards
GET /documents/generatedDocument/{documentId}
GET /documents/{documentId}
GET /documents/{hubId}/template/{templateId}/object/{objectId}
GET /email-template
GET /envelope
GET /envelope/envelopeCards
GET /envelope/getCode/test
GET /envelope/getFile/test
GET /envelope/{envelopeId}/documents
GET /envelope/{envelopeId}/documents/recipient
GET /envelope/{envelopeId}/documents/{documentId}
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/completed-fields
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/getAll
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/{envelopeDocumentFieldId}
GET /envelope/{envelopeId}/documents/{documentId}/generatePDF
GET /envelope/{envelopeId}/recipients
GET /envelope/{envelopeId}/recipients/{recipientId}/validate
GET /envelope/{envelopeId}/{envelopeDocumentId}/auditTrail
GET /envelope/{id}
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig/{id}
GET /help/category
GET /help/category/{id}
GET /help/knowledgeArticle
GET /help/video
GET /help/{id}
GET /sender/copyRecipientSignerLink/{envelopeId}/{recipientMailId}
GET /ssign/envelop
GET /ssign/envelop/{id}
GET /ssign/v1/envelop
PATCH /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/inputfield
PATCH /envelope/{envelopeId}/documents/{documentId}/recipients
PATCH /sender/{id}/submitEnvelop
PATCH /ssign/save
PATCH /ssign/submit
POST /authenticate
POST /document
POST /document/invite/validate
POST /document/user/verifyOTP
POST /encryptedKey
POST /envelope/create
POST /envelope/multi
POST /envelope/send/test
POST /envelope/workflow/create
POST /envelope/{envelopeId}/documents/multiple
POST /envelope/{envelopeId}/documents/uploadFile
POST /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField
POST /envelope/{envelopeId}/documents/{documentId}/recipient
POST /envelope/{envelopeId}/recipients/submit
POST /sender/email
POST /sender/envelop
POST /sender/inviteUser
POST /sender/resendEnvelope
POST /sender/userInvite
POST /sender/workflow/notification
POST /ssign/init
POST /ssign/initializeSession
POST /ssign/send2FACode
POST /ssign/submitConsent
POST /ssign/verify2FA
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bce42db947c37314315ebc104a4c55fc6692ed80d
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /document/{id}
DELETE /envelope/{envelopeId}/documents/{documentId}/recipient/{recipientId}
GET /documents
GET /documents/documentCards
GET /documents/{documentId}
GET /documents/{hubId}/template/{templateId}/object/{objectId}
GET /email-template
GET /envelope
GET /envelope/envelopeCards
GET /envelope/getCode/test
GET /envelope/getFile/test
GET /envelope/{envelopeId}/documents
GET /envelope/{envelopeId}/documents/recipient
GET /envelope/{envelopeId}/documents/{documentId}
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/completed-fields
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/getAll
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/{envelopeDocumentFieldId}
GET /envelope/{envelopeId}/documents/{documentId}/generatePDF
GET /envelope/{envelopeId}/recipients
GET /envelope/{envelopeId}/recipients/{recipientId}/validate
GET /envelope/{envelopeId}/{envelopeDocumentId}/auditTrail
GET /envelope/{id}
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig/{id}
GET /help/category
GET /help/category/{id}
GET /help/knowledgeArticle
GET /help/video
GET /help/{id}
GET /sender/copyRecipientSignerLink/{envelopeId}/{recipientMailId}
GET /ssign/envelop
GET /ssign/envelop/{id}
GET /ssign/v1/envelop
PATCH /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/inputfield
PATCH /envelope/{envelopeId}/documents/{documentId}/recipients
PATCH /sender/{id}/submitEnvelop
PATCH /ssign/save
PATCH /ssign/submit
POST /authenticate
POST /document
POST /document/invite/validate
POST /document/user/verifyOTP
POST /encryptedKey
POST /envelope/create
POST /envelope/multi
POST /envelope/send/test
POST /envelope/workflow/create
POST /envelope/{envelopeId}/documents/multiple
POST /envelope/{envelopeId}/documents/uploadFile
POST /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField
POST /envelope/{envelopeId}/documents/{documentId}/recipient
POST /envelope/{envelopeId}/recipients/submit
POST /sender/email
POST /sender/envelop
POST /sender/inviteUser
POST /sender/resendEnvelope
POST /sender/userInvite
POST /sender/workflow/notification
POST /ssign/init
POST /ssign/initializeSession
POST /ssign/send2FACode
POST /ssign/submitConsent
POST /ssign/verify2FA
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bce42db947c37314315ebc104a4c55fc6ffca5392
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /document/{id}
DELETE /envelope/{envelopeId}/documents/{documentId}/recipient/{recipientId}
GET /documents
GET /documents/documentCards
GET /documents/generatedDocument/{documentId}
GET /documents/{documentId}
GET /documents/{hubId}/template/{templateId}/object/{objectId}
GET /email-template
GET /envelope
GET /envelope/envelopeCards
GET /envelope/getCode/test
GET /envelope/getFile/test
GET /envelope/{envelopeId}/documents
GET /envelope/{envelopeId}/documents/recipient
GET /envelope/{envelopeId}/documents/{documentId}
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/completed-fields
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/getAll
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/{envelopeDocumentFieldId}
GET /envelope/{envelopeId}/documents/{documentId}/generatePDF
GET /envelope/{envelopeId}/recipients
GET /envelope/{envelopeId}/recipients/{recipientId}/validate
GET /envelope/{envelopeId}/{envelopeDocumentId}/auditTrail
GET /envelope/{id}
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig/{id}
GET /help/category
GET /help/category/{id}
GET /help/knowledgeArticle
GET /help/video
GET /help/{id}
GET /sender/copyRecipientSignerLink/{envelopeId}/{recipientMailId}
GET /ssign/envelop
GET /ssign/envelop/{id}
GET /ssign/v1/envelop
PATCH /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/inputfield
PATCH /envelope/{envelopeId}/documents/{documentId}/recipients
PATCH /sender/{id}/submitEnvelop
PATCH /ssign/save
PATCH /ssign/submit
POST /authenticate
POST /document
POST /document/invite/validate
POST /document/user/verifyOTP
POST /encryptedKey
POST /envelope/create
POST /envelope/multi
POST /envelope/send/test
POST /envelope/workflow/create
POST /envelope/{envelopeId}/documents/multiple
POST /envelope/{envelopeId}/documents/uploadFile
POST /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField
POST /envelope/{envelopeId}/documents/{documentId}/recipient
POST /envelope/{envelopeId}/recipients/submit
POST /sender/email
POST /sender/envelop
POST /sender/inviteUser
POST /sender/resendEnvelope
POST /sender/userInvite
POST /sender/workflow/notification
POST /ssign/init
POST /ssign/initializeSession
POST /ssign/send2FACode
POST /ssign/submitConsent
POST /ssign/verify2FA
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bce42db947c37314315ebc104a4c55fc6692ed80d
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /document/{id}
DELETE /envelope/{envelopeId}/documents/{documentId}/recipient/{recipientId}
GET /documents
GET /documents/documentCards
GET /documents/{documentId}
GET /documents/{hubId}/template/{templateId}/object/{objectId}
GET /email-template
GET /envelope
GET /envelope/envelopeCards
GET /envelope/getCode/test
GET /envelope/getFile/test
GET /envelope/{envelopeId}/documents
GET /envelope/{envelopeId}/documents/recipient
GET /envelope/{envelopeId}/documents/{documentId}
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/completed-fields
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/getAll
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/{envelopeDocumentFieldId}
GET /envelope/{envelopeId}/documents/{documentId}/generatePDF
GET /envelope/{envelopeId}/recipients
GET /envelope/{envelopeId}/recipients/{recipientId}/validate
GET /envelope/{envelopeId}/{envelopeDocumentId}/auditTrail
GET /envelope/{id}
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig/{id}
GET /help/category
GET /help/category/{id}
GET /help/knowledgeArticle
GET /help/video
GET /help/{id}
GET /sender/copyRecipientSignerLink/{envelopeId}/{recipientMailId}
GET /ssign/envelop
GET /ssign/envelop/{id}
GET /ssign/v1/envelop
PATCH /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/inputfield
PATCH /envelope/{envelopeId}/documents/{documentId}/recipients
PATCH /sender/{id}/submitEnvelop
PATCH /ssign/save
PATCH /ssign/submit
POST /authenticate
POST /document
POST /document/invite/validate
POST /document/user/verifyOTP
POST /encryptedKey
POST /envelope/create
POST /envelope/multi
POST /envelope/send/test
POST /envelope/workflow/create
POST /envelope/{envelopeId}/documents/multiple
POST /envelope/{envelopeId}/documents/uploadFile
POST /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField
POST /envelope/{envelopeId}/documents/{documentId}/recipient
POST /envelope/{envelopeId}/recipients/submit
POST /sender/email
POST /sender/envelop
POST /sender/inviteUser
POST /sender/resendEnvelope
POST /sender/userInvite
POST /sender/workflow/notification
POST /ssign/init
POST /ssign/initializeSession
POST /ssign/send2FACode
POST /ssign/submitConsent
POST /ssign/verify2FA
Open service 99.83.151.71:80 · ssign.api.dev.sdocs.com
2026-01-09 16:03
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 09 Jan 2026 16:04:37 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=lG814%2BjSRPhlHx2hdcET%2FDjZe5dd4M7xjRyhUZgFSHA%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767974677"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=lG814%2BjSRPhlHx2hdcET%2FDjZe5dd4M7xjRyhUZgFSHA%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767974677"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.97.79:443 · ssign.api.dev.sdocs.com
2026-01-08 19:01
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Thu, 08 Jan 2026 19:01:22 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=kTeMNRBP0Oidw0AFZHaRp3gxwoKAe0KCnUwSI7AqU0U%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767898882"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=kTeMNRBP0Oidw0AFZHaRp3gxwoKAe0KCnUwSI7AqU0U%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767898882"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 99.83.151.71:80 · ssign.api.dev.sdocs.com
2026-01-02 22:18
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 22:19:02 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=OEe1L3d7QDTmi04Uz4RdZUDaKE2Xzvf6GVp0UeJJh%2B0%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767392342"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=OEe1L3d7QDTmi04Uz4RdZUDaKE2Xzvf6GVp0UeJJh%2B0%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767392342"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.97.79:443 · ssign.api.dev.sdocs.com
2026-01-01 19:53
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Thu, 01 Jan 2026 19:53:27 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=LyuFKI2XWFRjW6g9SvqXbPpCSLas7hAhIzNKv71zryw%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1767297207"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=LyuFKI2XWFRjW6g9SvqXbPpCSLas7hAhIzNKv71zryw%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1767297207"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.97.79:443 · ssign.api.dev.sdocs.com
2025-12-23 09:19
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Tue, 23 Dec 2025 09:19:02 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=gbi5zim%2FhXeAityI5lRkUOm2GLLbW%2BXZWA1VSz7%2F2GA%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766481543"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=gbi5zim%2FhXeAityI5lRkUOm2GLLbW%2BXZWA1VSz7%2F2GA%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766481543"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 99.83.151.71:80 · ssign.api.dev.sdocs.com
2025-12-23 04:34
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Tue, 23 Dec 2025 04:34:19 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=T%2B9tKpjdMC%2B3s7TXEZrbA%2Fpab44stC3RLNM477BvnjQ%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766464459"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=T%2B9tKpjdMC%2B3s7TXEZrbA%2Fpab44stC3RLNM477BvnjQ%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766464459"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.97.79:443 · ssign.api.dev.sdocs.com
2025-12-21 05:40
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Sun, 21 Dec 2025 05:40:23 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=dFd2F9wtjRLlsymBpOfcQqWz8dVNrAKYPLRd0Sqk%2BKo%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766295623"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=dFd2F9wtjRLlsymBpOfcQqWz8dVNrAKYPLRd0Sqk%2BKo%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766295623"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 99.83.151.71:80 · ssign.api.dev.sdocs.com
2025-12-21 02:22
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Sun, 21 Dec 2025 02:22:17 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=gLoUrxO9Aa2CTSJBNFOnmnGoYi4VbQ6NBAmTgkoioUE%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766283737"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=gLoUrxO9Aa2CTSJBNFOnmnGoYi4VbQ6NBAmTgkoioUE%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766283737"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 75.2.97.79:443 · ssign.api.dev.sdocs.com
2025-12-19 07:43
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 19 Dec 2025 07:43:28 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=wVZEW3PbpbJBWmDr5AVnpijFm7i2ForcvcPudR7m%2BjI%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766130208"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=wVZEW3PbpbJBWmDr5AVnpijFm7i2ForcvcPudR7m%2BjI%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766130208"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 99.83.151.71:80 · ssign.api.dev.sdocs.com
2025-12-19 01:36
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 19 Dec 2025 01:36:30 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=bUMKJHifa7KxGxbSdSKHvi3A93FcatXeqCajbsEWwcQ%3D\u0026sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add\u0026ts=1766108191"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=bUMKJHifa7KxGxbSdSKHvi3A93FcatXeqCajbsEWwcQ%3D&sid=c46efe9b-d3d2-4a0c-8c76-bfafa16c5add&ts=1766108191"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close