Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035498780cf41e8d03a00437a45e5437a45e5437a45e5
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /v1/Webhook
POST /v1/Webhook/Bulk
PUT /v1/Webhook/Cancel/{webhookId}
Open service 23.50.131.154:443 · webhook.safrapay.com.br
2026-01-23 04:40
HTTP/1.1 404 Not Found Content-Length: 0 x-dt-tracestate: 985d1479-c51e8ec5@dt traceresponse: 00-513eedfa37106bc0707e664f3c083e4f-ba0007e5419eaf59-01 traceKey: e694e475-fd62-4f29-a314-04e60d8f2a41 Referrer-Policy: strict-origin-when-cross-origin Date: Fri, 23 Jan 2026 04:40:29 GMT Connection: close Set-Cookie: _abck=9ECD523FA8F1F3CED21EC2577DDB5258~-1~YAAQHRczFx4tsNebAQAAr1wn6Q/eCxKMQqIKAA6x0nMUS6gi6xcpytmH9c9uAbB9iD0UmD4LQGCeZEdRvOrRK9tUN7oFDOnrzFgfNioPXIW1rbqnOh/f0gCGYEByPQrwH9f9fsU+QY/bHFAY+Bq737MuwFGdCqPAU1rGz0/R/Mo6HrdVoozbJCYO2D0jZBJTrT06wGGyFRvnyY45PRAE7+O3FrvEAib8ixXgoOhULpxMFyCI8YVYVQxF05QTWbFFcXhD2nnGaEm4Qad9H41BFiI0JfsKydKPVr9a9n/4IOIKHX0z9ByLQX1pl6sRxBVBHBbb4AeAovSq3fsgTaCeq/ho00fa93xuUxGH3yGJx2iEtitnPns+6k/k2pkuNYLzV3sZYIZTi0+HKSlc/dhf/lW5oG7nv0JqlHOoCAZ4tMaav2/2qyt1im/8cnFV2iLBkddx/Wzi7HOAhQ==~-1~-1~-1~-1~-1; Domain=.safrapay.com.br; Path=/; Expires=Sat, 23 Jan 2027 04:40:29 GMT; Max-Age=31536000; Secure Set-Cookie: bm_sz=D819E60700F4776ACC175F3DEC4FC5D5~YAAQHRczFx8tsNebAQAAr1wn6R4UF8ww9mx9RtiwBEF2SJBh8vqgSwjKiU+UOrVD/yYRm73dLzP2rvO1HpfbF0QGVV3uW+fW2+rrHzHVFo7sr3XEbWWvV+pZUfUsZOwU85vUuAwIHY7lFa0Ko17hD0A/95NWygsEnxZHWyY+/SqfZ3+tDmwhTguej40aPg1KqIbz7RDKylDKBCGRaUo1VcHVvxCEJuENHoWcLBREVVOv8nNUztCElZ8sN1WOYGYNJbRplgX7/nSuJO87gG5UT09fTDCiSwX9+547zKiUM0oRKyK+/12ja+64lAIuxe5LdTi8zlIo+bGLMGWf7As0bXIOJtT8sj8cgeHw/bKvfYjJQ5s=~4534323~3748419; Domain=.safrapay.com.br; Path=/; Expires=Fri, 23 Jan 2026 08:40:29 GMT; Max-Age=14400
Open service 23.50.131.154:443 · webhook.safrapay.com.br
2026-01-09 20:37
HTTP/1.1 404 Not Found Content-Length: 0 x-dt-tracestate: 985d1479-c51e8ec5@dt traceresponse: 00-a9afff8128c507f9eb2542e87bbacef0-24fe3e3f24795324-01 traceKey: 04a23ace-c787-4e39-8e57-dc6dfffde8d0 Referrer-Policy: strict-origin-when-cross-origin Date: Fri, 09 Jan 2026 20:37:34 GMT Connection: close Set-Cookie: _abck=7B1E745EC999FC7EAD4947367C4E37A2~-1~YAAQHRczF94iY22bAQAA7496pA/lCi7UAAwdCJYLXxkPH78GVvvSkt4Wlm1M3TrvXEhvHyxUdKASG95sk0NZvTdJ/olsKeiJtcBFBdE8ARNfAMKthmbR+pEQ91zDodt9G7hOCm2ydbRRd1yVaTn8VLskYQ88M1TVv6OcKxbZ5+f6ZN8LeZYRgWa2Vs96iWmjpwsNGS2bavI6uo2KL+MzfoUkr+ts/uKr/kfPn6jIN5Z0w5J92Vu3U3+GLNNVhbGfNtO0qJtr/+HdQivVl5HkiiWCvK91vH3h0cN+s2qH7+eXg9XEYkeAA+lcfPXxdKsQgLsJzdctS1tLAGDJPaP62rvjYmIQB082jFQRyq5Wt5O1hd/PFUtRvv0AuxDc5JKR+hGZDvIiC64dqDxJxQTuYlxz2b/cweS9Dg1PN6KJiK5E5w1aHs3W8cBX0kdkuvz0PXQHcuIV35/xxw==~-1~-1~-1~-1~-1; Domain=.safrapay.com.br; Path=/; Expires=Sat, 09 Jan 2027 20:37:34 GMT; Max-Age=31536000; Secure Set-Cookie: bm_sz=46D064F1CF1909AECC8B6BAB58C070CC~YAAQHRczF98iY22bAQAA8I96pB5vN1VqKcaTsl0nyIpO+YzTO1CQFRMLwRu6yzZSOai2Z0elDVJOLMXeolr6u5H40lsDbYGp01fR48FHT+oZfeFEnKgYN5pN3B9swaxtfpLFgR+zx+3ThT0tSouGFbWqWQRiWtuLvNVa1jWMKidTEZ9YnuL3BNnwOaXHFtRXzv6muvDKSkA7Ap0TNHN+qW0WzXyp5yEveR9ME7NPQGPdfjUQOUB+SszFR8IQFexsDNR5WOk2Tcc/VKBulB0sAYXmN13MSwWGuZvPpeeYPzBCR2vQepjSrvpLDHEf5GLJcARKvwPezPAriM1HI6l4u4KaIpV1s+FN4Iq8+At7eqfoJllP~4404787~4407622; Domain=.safrapay.com.br; Path=/; Expires=Sat, 10 Jan 2026 00:37:34 GMT; Max-Age=14400
Open service 23.50.131.154:443 · webhook.safrapay.com.br
2026-01-03 00:30
HTTP/1.1 404 Not Found Content-Length: 0 x-dt-tracestate: 985d1479-c51e8ec5@dt traceresponse: 00-9bed813a1e2743999c17afb6b5c728ec-41ac58ba8057307e-01 traceKey: 3433d49c-0a58-44be-866d-fb53b6199d02 Referrer-Policy: strict-origin-when-cross-origin Date: Sat, 03 Jan 2026 00:30:04 GMT Connection: close Set-Cookie: _abck=20CF002E12F01FD0616E23B19A654AF7~-1~YAAQHRczF/sWZGibAQAAd+lCgQ8qsHJvYni/En+nqwr/R/Cr+guX6Ef16sdu7QZHWlNJ7t1Gc/vRq2mBov0gXhFuubPvr4mEy3hltUyorK9daEgIN+OWxPVBslbfWlPdnLeUZ2x+xEoY87T1XraI5Jgk0aJ9uDCv8WewYsCXCL91MPiOY8EjUFIJJoGfn9wIBHvk2CJwyekXQgPtKSnb1o2LBbkQuA+BFPiwj13Wd9kGNjSV3h38mHcgUp0pgRzrlx0DKEeH/6ONMibaWUzeTCGFGjAIpzbf28Z88e/sWt9XfRpf0++eTpIDeYELh0rXyEPT6RZ5WFRTPaOpPAX3aqabiCcB7pX3hyIuZ71Mfq/rsMxGKEXrzgiI9CK3yfOjuk7wfBYc+5SJdJf8+0aiK8S45nfgPtp308pbnuYQQCu9TJ2xiY13/GitiMA3bE7xKJ+9XNsJL3Kvtg==~-1~-1~-1~-1~-1; Domain=.safrapay.com.br; Path=/; Expires=Sun, 03 Jan 2027 00:30:04 GMT; Max-Age=31536000; Secure Set-Cookie: bm_sz=9CBA6D3AC5B1FAB57C6669E8C8961AB2~YAAQHRczF/wWZGibAQAAd+lCgR6uFG2RFXxPAT72UCHJlAZ/Jy1nI3I1a1HkWwkg0BpUXDw9XzasnxlCjQJ+dYUDgp/RJdKQ0i78i90RTZRJ/Un+t7MZc4nc7d0ZYLV7QNWcm4TiB4azFjh682V/yX3Xn0VPv2NCMVkpAWLjYjfD6Ut8Tfyp3LQ4tO72LykQh24ZmiO4qMbBk8KLcG/aj3nS8sAylWK16cf6Jk3Dc1gy1druSfYpGYfmAbHhzaP5fzMrD2rv9hE2WJW45Qf+fhUy7Ul1YRANBh1RBfqm433c18uxX6ByPZHDKuP/iFMQ5EUHVrv/FWnnWMouiDJhgUiOkfVvYy81DfeoRxFzMySzNVPS~3290422~3355458; Domain=.safrapay.com.br; Path=/; Expires=Sat, 03 Jan 2026 04:30:04 GMT; Max-Age=14400
Open service 23.50.131.154:443 · webhook.safrapay.com.br
2025-12-23 07:42
HTTP/1.1 404 Not Found Content-Length: 0 x-dt-tracestate: 985d1479-c51e8ec5@dt traceresponse: 00-dce8ebcaa407a95765e6128fa7e109a4-9e9879c7460ec9ca-01 traceKey: d4abd5d8-f2f6-4077-99e8-bee4fd714be7 Referrer-Policy: strict-origin-when-cross-origin Date: Tue, 23 Dec 2025 07:42:18 GMT Connection: close Set-Cookie: _abck=E606BC41D05181D7A5D8CB91CBB3FC7F~-1~YAAQGhczF+fJCyibAQAACqwoSg8NYZ5o9zw5rzpBlrhfieYkzOpofBHb2hxiVGAjiH8etz7mo4n+r1B9YOD/TjQiJIygn0MKq/MmrEQSoOmDlQA7wM+v+7x/cVWl7KtlVyO5icCGmoQy6Winy3fr5wAd00fIsNADjOL0wzZZ/rkraxctaZGOAGmkhzDtVSrWOM8qyeL+jJXe46whBfeNXnvYjZ6yDB8ywYm8qT8bPwpz24yCFJ+KamkHpk07Lsa3dHAx+9Cq608rqijfMh3ujMKrr4ODAqUlwUmdQO68MImCmV6XaRtt97qN1nKrqhOtdfrY06lxMX9AzW4z8v/9JtI4tZFUoK2RaeDo9hoLOS03tjf6pZdadDjA3EUz6FfSpIsUBVGUXc5bmxeHox0190ldq2/OIga39cJ6JgavprihX1ZbtFRjS8LMkWm64wbT5bu2N1tJDe7DIA==~-1~-1~-1~-1~-1; Domain=.safrapay.com.br; Path=/; Expires=Wed, 23 Dec 2026 07:42:18 GMT; Max-Age=31536000; Secure Set-Cookie: bm_sz=17A07D16C41234EC3EA67F626997A875~YAAQGhczF+jJCyibAQAAC6woSh4F1xaVx+gB/B4bbPh2i5hZqWBxKYclmOzv/wEFt5qlpXWdVatRwEtcvuWrko0QJMi2xXujEECz+YPDBlMB4gG/PkPsvoxtilL6OmCqBB9GvE/M95DexOuuVt3dQxkAn/3DebKicUVnWdrbHHdg0r0PfaaEa6J06n268xWxlVDkLEf11aUpafE9/1aizb3c3Fj7Jz5o/eSICCjCexjj6QcmiauZXVcGtAkBdtu+k5Lh1zCWdshW5wzCKy9OzMLrLotMItDS7GPBNk7ZilZgTTlI2wBrbpOmKAA1xRjCewQuTplpGLIzIqxP6N9Qw6UU2rxi6iHdhya9U+2brhR/zUYE~3749940~3622209; Domain=.safrapay.com.br; Path=/; Expires=Tue, 23 Dec 2025 11:42:17 GMT; Max-Age=14399