Run Audit

Endpoints covered by an active exception are left unticked. Checks each selected endpoint from this browser: reachability, status code, response time, HTTPS and CORS, plus config consistency. The token / auth check (build 6.6) calls each route with no credentials and with invalid ones (both must be refused), then with valid ones, and scores it two ways: Strict (the endpoint itself refuses calls without a token or login) and Practical (Strict, or CORS restricted and IP restricted, so the world can't reach it). Credentials… sets the login per host (e.g. a WordPress username and application password); kept in memory only. Then save the run as one audit record in History. Walk Swagger & audit host also imports the host's back-end interfaces from its SystemConsole; tie them to endpoints on the Interfaces page.
Save this audit
A per-endpoint summary (verdict, status, response time, warnings and failures) is added after your notes.
Problems in this run
Open a trouble ticket for each failing endpoint. One that already has an open ticket gets its incident count raised instead. Re-audit problems re-checks them later and resolves the tickets of the ones that recover.
Open Surveillance Tickets
Browsers only let a page read a response when the target API allows this page's origin (CORS). When it doesn't, the audit can still tell whether the endpoint is up, but not its status code.