Heroku
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bce42db947c37314315ebc104a4c55fc6ffca5392
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /document/{id}
DELETE /envelope/{envelopeId}/documents/{documentId}/recipient/{recipientId}
GET /documents
GET /documents/documentCards
GET /documents/generatedDocument/{documentId}
GET /documents/{documentId}
GET /documents/{hubId}/template/{templateId}/object/{objectId}
GET /email-template
GET /envelope
GET /envelope/envelopeCards
GET /envelope/getCode/test
GET /envelope/getFile/test
GET /envelope/{envelopeId}/documents
GET /envelope/{envelopeId}/documents/recipient
GET /envelope/{envelopeId}/documents/{documentId}
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/completed-fields
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/getAll
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/{envelopeDocumentFieldId}
GET /envelope/{envelopeId}/documents/{documentId}/generatePDF
GET /envelope/{envelopeId}/recipients
GET /envelope/{envelopeId}/recipients/{recipientId}/validate
GET /envelope/{envelopeId}/{envelopeDocumentId}/auditTrail
GET /envelope/{id}
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig/{id}
GET /help/category
GET /help/category/{id}
GET /help/knowledgeArticle
GET /help/video
GET /help/{id}
GET /sender/copyRecipientSignerLink/{envelopeId}/{recipientMailId}
GET /ssign/envelop
GET /ssign/envelop/{id}
GET /ssign/v1/envelop
PATCH /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/inputfield
PATCH /envelope/{envelopeId}/documents/{documentId}/recipients
PATCH /sender/{id}/submitEnvelop
PATCH /ssign/save
PATCH /ssign/submit
POST /authenticate
POST /document
POST /document/invite/validate
POST /document/user/verifyOTP
POST /encryptedKey
POST /envelope/create
POST /envelope/multi
POST /envelope/send/test
POST /envelope/workflow/create
POST /envelope/{envelopeId}/documents/multiple
POST /envelope/{envelopeId}/documents/uploadFile
POST /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField
POST /envelope/{envelopeId}/documents/{documentId}/recipient
POST /envelope/{envelopeId}/recipients/submit
POST /sender/email
POST /sender/envelop
POST /sender/inviteUser
POST /sender/resendEnvelope
POST /sender/userInvite
POST /sender/workflow/notification
POST /ssign/init
POST /ssign/initializeSession
POST /ssign/send2FACode
POST /ssign/submitConsent
POST /ssign/verify2FA
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bce42db947c37314315ebc104a4c55fc6692ed80d
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /document/{id}
DELETE /envelope/{envelopeId}/documents/{documentId}/recipient/{recipientId}
GET /documents
GET /documents/documentCards
GET /documents/{documentId}
GET /documents/{hubId}/template/{templateId}/object/{objectId}
GET /email-template
GET /envelope
GET /envelope/envelopeCards
GET /envelope/getCode/test
GET /envelope/getFile/test
GET /envelope/{envelopeId}/documents
GET /envelope/{envelopeId}/documents/recipient
GET /envelope/{envelopeId}/documents/{documentId}
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/completed-fields
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/getAll
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/{envelopeDocumentFieldId}
GET /envelope/{envelopeId}/documents/{documentId}/generatePDF
GET /envelope/{envelopeId}/recipients
GET /envelope/{envelopeId}/recipients/{recipientId}/validate
GET /envelope/{envelopeId}/{envelopeDocumentId}/auditTrail
GET /envelope/{id}
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig/{id}
GET /help/category
GET /help/category/{id}
GET /help/knowledgeArticle
GET /help/video
GET /help/{id}
GET /sender/copyRecipientSignerLink/{envelopeId}/{recipientMailId}
GET /ssign/envelop
GET /ssign/envelop/{id}
GET /ssign/v1/envelop
PATCH /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/inputfield
PATCH /envelope/{envelopeId}/documents/{documentId}/recipients
PATCH /sender/{id}/submitEnvelop
PATCH /ssign/save
PATCH /ssign/submit
POST /authenticate
POST /document
POST /document/invite/validate
POST /document/user/verifyOTP
POST /encryptedKey
POST /envelope/create
POST /envelope/multi
POST /envelope/send/test
POST /envelope/workflow/create
POST /envelope/{envelopeId}/documents/multiple
POST /envelope/{envelopeId}/documents/uploadFile
POST /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField
POST /envelope/{envelopeId}/documents/{documentId}/recipient
POST /envelope/{envelopeId}/recipients/submit
POST /sender/email
POST /sender/envelop
POST /sender/inviteUser
POST /sender/resendEnvelope
POST /sender/userInvite
POST /sender/workflow/notification
POST /ssign/init
POST /ssign/initializeSession
POST /ssign/send2FACode
POST /ssign/submitConsent
POST /ssign/verify2FA
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bce42db947c37314315ebc104a4c55fc6ffca5392
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /document/{id}
DELETE /envelope/{envelopeId}/documents/{documentId}/recipient/{recipientId}
GET /documents
GET /documents/documentCards
GET /documents/generatedDocument/{documentId}
GET /documents/{documentId}
GET /documents/{hubId}/template/{templateId}/object/{objectId}
GET /email-template
GET /envelope
GET /envelope/envelopeCards
GET /envelope/getCode/test
GET /envelope/getFile/test
GET /envelope/{envelopeId}/documents
GET /envelope/{envelopeId}/documents/recipient
GET /envelope/{envelopeId}/documents/{documentId}
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/completed-fields
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/getAll
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/{envelopeDocumentFieldId}
GET /envelope/{envelopeId}/documents/{documentId}/generatePDF
GET /envelope/{envelopeId}/recipients
GET /envelope/{envelopeId}/recipients/{recipientId}/validate
GET /envelope/{envelopeId}/{envelopeDocumentId}/auditTrail
GET /envelope/{id}
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig/{id}
GET /help/category
GET /help/category/{id}
GET /help/knowledgeArticle
GET /help/video
GET /help/{id}
GET /sender/copyRecipientSignerLink/{envelopeId}/{recipientMailId}
GET /ssign/envelop
GET /ssign/envelop/{id}
GET /ssign/v1/envelop
PATCH /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/inputfield
PATCH /envelope/{envelopeId}/documents/{documentId}/recipients
PATCH /sender/{id}/submitEnvelop
PATCH /ssign/save
PATCH /ssign/submit
POST /authenticate
POST /document
POST /document/invite/validate
POST /document/user/verifyOTP
POST /encryptedKey
POST /envelope/create
POST /envelope/multi
POST /envelope/send/test
POST /envelope/workflow/create
POST /envelope/{envelopeId}/documents/multiple
POST /envelope/{envelopeId}/documents/uploadFile
POST /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField
POST /envelope/{envelopeId}/documents/{documentId}/recipient
POST /envelope/{envelopeId}/recipients/submit
POST /sender/email
POST /sender/envelop
POST /sender/inviteUser
POST /sender/resendEnvelope
POST /sender/userInvite
POST /sender/workflow/notification
POST /ssign/init
POST /ssign/initializeSession
POST /ssign/send2FACode
POST /ssign/submitConsent
POST /ssign/verify2FA
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4bce42db947c37314315ebc104a4c55fc6692ed80d
Public Swagger UI/API detected at path: /v3/api-docs - sample paths:
DELETE /document/{id}
DELETE /envelope/{envelopeId}/documents/{documentId}/recipient/{recipientId}
GET /documents
GET /documents/documentCards
GET /documents/{documentId}
GET /documents/{hubId}/template/{templateId}/object/{objectId}
GET /email-template
GET /envelope
GET /envelope/envelopeCards
GET /envelope/getCode/test
GET /envelope/getFile/test
GET /envelope/{envelopeId}/documents
GET /envelope/{envelopeId}/documents/recipient
GET /envelope/{envelopeId}/documents/{documentId}
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/completed-fields
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/getAll
GET /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/{envelopeDocumentFieldId}
GET /envelope/{envelopeId}/documents/{documentId}/generatePDF
GET /envelope/{envelopeId}/recipients
GET /envelope/{envelopeId}/recipients/{recipientId}/validate
GET /envelope/{envelopeId}/{envelopeDocumentId}/auditTrail
GET /envelope/{id}
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig
GET /envelopeDocument/{envelopeDocumentId}/fieldConfig/{id}
GET /help/category
GET /help/category/{id}
GET /help/knowledgeArticle
GET /help/video
GET /help/{id}
GET /sender/copyRecipientSignerLink/{envelopeId}/{recipientMailId}
GET /ssign/envelop
GET /ssign/envelop/{id}
GET /ssign/v1/envelop
PATCH /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField/inputfield
PATCH /envelope/{envelopeId}/documents/{documentId}/recipients
PATCH /sender/{id}/submitEnvelop
PATCH /ssign/save
PATCH /ssign/submit
POST /authenticate
POST /document
POST /document/invite/validate
POST /document/user/verifyOTP
POST /encryptedKey
POST /envelope/create
POST /envelope/multi
POST /envelope/send/test
POST /envelope/workflow/create
POST /envelope/{envelopeId}/documents/multiple
POST /envelope/{envelopeId}/documents/uploadFile
POST /envelope/{envelopeId}/documents/{documentId}/envelopeDocumentField
POST /envelope/{envelopeId}/documents/{documentId}/recipient
POST /envelope/{envelopeId}/recipients/submit
POST /sender/email
POST /sender/envelop
POST /sender/inviteUser
POST /sender/resendEnvelope
POST /sender/userInvite
POST /sender/workflow/notification
POST /ssign/init
POST /ssign/initializeSession
POST /ssign/send2FACode
POST /ssign/submitConsent
POST /ssign/verify2FA
Open service 76.223.57.73:80 · ssign.api.test.sdocs.com
2026-01-09 06:43
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 09 Jan 2026 06:44:35 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=R24ijAfZRqOWivbhyv3oGYyTnmtIXhB95fm5oz32vQE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767941075"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=R24ijAfZRqOWivbhyv3oGYyTnmtIXhB95fm5oz32vQE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767941075"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 3.33.241.96:443 · ssign.api.test.sdocs.com
2026-01-09 02:15
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 09 Jan 2026 02:15:55 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=nAuUpEouXkcGrRai%2BoRLziCJWQuU%2Bt6IupHnLs05wMs%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767924955"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=nAuUpEouXkcGrRai%2BoRLziCJWQuU%2Bt6IupHnLs05wMs%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767924955"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 3.33.241.96:443 · ssign.api.test.sdocs.com
2026-01-02 19:21
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 19:21:53 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=cSD%2Bar4ECCiAKltrGQES8EunYoNaph2cev7OKuYnhXw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767381714"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=cSD%2Bar4ECCiAKltrGQES8EunYoNaph2cev7OKuYnhXw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767381714"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 13.248.213.92:80 · ssign.api.test.sdocs.com
2026-01-02 19:21
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 19:21:57 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=faHvh9ExZ8zPolQXXcJTYReL3wW10IRbWDuBzhz0C0k%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767381717"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=faHvh9ExZ8zPolQXXcJTYReL3wW10IRbWDuBzhz0C0k%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767381717"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 76.223.57.73:443 · ssign.api.test.sdocs.com
2026-01-02 19:21
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 19:21:53 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=cSD%2Bar4ECCiAKltrGQES8EunYoNaph2cev7OKuYnhXw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767381714"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=cSD%2Bar4ECCiAKltrGQES8EunYoNaph2cev7OKuYnhXw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767381714"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 15.197.149.68:80 · ssign.api.test.sdocs.com
2026-01-02 19:21
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 19:21:57 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=faHvh9ExZ8zPolQXXcJTYReL3wW10IRbWDuBzhz0C0k%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767381717"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=faHvh9ExZ8zPolQXXcJTYReL3wW10IRbWDuBzhz0C0k%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767381717"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 13.248.213.92:443 · ssign.api.test.sdocs.com
2026-01-02 19:21
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 19:21:53 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=cSD%2Bar4ECCiAKltrGQES8EunYoNaph2cev7OKuYnhXw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767381714"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=cSD%2Bar4ECCiAKltrGQES8EunYoNaph2cev7OKuYnhXw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767381714"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 76.223.57.73:80 · ssign.api.test.sdocs.com
2026-01-02 19:21
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 19:21:56 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=faHvh9ExZ8zPolQXXcJTYReL3wW10IRbWDuBzhz0C0k%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767381717"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=faHvh9ExZ8zPolQXXcJTYReL3wW10IRbWDuBzhz0C0k%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767381717"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 15.197.149.68:443 · ssign.api.test.sdocs.com
2026-01-02 19:21
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 19:21:53 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=cSD%2Bar4ECCiAKltrGQES8EunYoNaph2cev7OKuYnhXw%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767381714"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=cSD%2Bar4ECCiAKltrGQES8EunYoNaph2cev7OKuYnhXw%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767381714"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 76.223.57.73:80 · ssign.api.test.sdocs.com
2026-01-02 02:36
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 02:36:42 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=sWnPrKGI9mgynxlcuWbnhSGv9PTJbnP5U1FAYmCzsXs%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767321403"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=sWnPrKGI9mgynxlcuWbnhSGv9PTJbnP5U1FAYmCzsXs%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767321403"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 3.33.241.96:443 · ssign.api.test.sdocs.com
2026-01-02 02:36
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 02 Jan 2026 02:36:39 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=KT8IHMSG1oynNot3fB6g5QLBlohwmPTZCe2uZSc6wek%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767321399"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=KT8IHMSG1oynNot3fB6g5QLBlohwmPTZCe2uZSc6wek%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767321399"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 76.223.57.73:80 · ssign.api.test.sdocs.com
2025-12-23 07:49
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Tue, 23 Dec 2025 07:49:47 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Y0XTZVAqf7kQcx%2FutS3XofTlqDYu8ZyrmDZBLEg8tpE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766476187"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Y0XTZVAqf7kQcx%2FutS3XofTlqDYu8ZyrmDZBLEg8tpE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766476187"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 3.33.241.96:443 · ssign.api.test.sdocs.com
2025-12-22 18:08
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Mon, 22 Dec 2025 18:08:11 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2FdKEiW4Xzs%2BjN8XiJ5rK55AeoKFs2naSYEW%2FV1BW8xY%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766426892"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2FdKEiW4Xzs%2BjN8XiJ5rK55AeoKFs2naSYEW%2FV1BW8xY%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766426892"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 76.223.57.73:80 · ssign.api.test.sdocs.com
2025-12-20 23:04
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Sat, 20 Dec 2025 23:04:26 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=oJacpSzUh8qGQmx5y0rPuNSaFg1Uj%2Bono3qHvqCMO74%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766271866"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=oJacpSzUh8qGQmx5y0rPuNSaFg1Uj%2Bono3qHvqCMO74%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766271866"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 3.33.241.96:443 · ssign.api.test.sdocs.com
2025-12-20 20:27
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Sat, 20 Dec 2025 20:27:38 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=o3r9oP2SRO491vdbLljzqixfUvITYa0untcV9cXOO5c%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766262458"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=o3r9oP2SRO491vdbLljzqixfUvITYa0untcV9cXOO5c%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766262458"
Server: Heroku
Strict-Transport-Security: max-age=31536000 ; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close
Open service 76.223.57.73:80 · ssign.api.test.sdocs.com
2025-12-19 01:01
HTTP/1.1 403 Forbidden
Access-Control-Allow-Credentials: true
Access-Control-Allow-Headers: Content-Type, Authorization
Access-Control-Allow-Methods: GET, POST, PATCH, PUT, DELETE, OPTIONS
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Length: 0
Date: Fri, 19 Dec 2025 01:01:25 GMT
Expires: 0
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Pragma: no-cache
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=rUv170L4sVSCyMSd9%2FeWak4kyXatXuUOK7As%2BtqWCFM%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766106085"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=rUv170L4sVSCyMSd9%2FeWak4kyXatXuUOK7As%2BtqWCFM%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766106085"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-Xss-Protection: 0
Connection: close