API Docs

Swagger UI Exposed

The Swagger UI is reachable at `/docs` with a pre-filled bearer token, listing every internal admin endpoint and a try-it-out button.

Spec preview

  

Expected Findings

  • Swagger UI ships a default bearer token for the staging admin user.
  • Spec advertises `/admin/*` endpoints alongside public ones.
  • Internal hostnames appear in the `servers` block.

Signals

Default
bearer.x-default = "Bearer staging-admin-jwt"