SSL Report:
stagingalb.hellohaptik.com
(34.120.43.98)
Assessed on: Mon, 02 Feb 2026 02:59:27 UTC
| Clear cache
Summary
0
20
40
60
80
100
Certificate
Protocol Support
Key Exchange
Cipher Strength
Visit our documentation page
for more information, configuration guides, and books. Known issues are documented
here.
Server sent invalid/disabled HSTS policy. See below for further information. MORE INFO »
This server supports TLS 1.3. MORE INFO »
Certificate #1: RSA 2048 bits (SHA256withRSA)
|
Server Key and Certificate #1
|
|
| Subject |
*.hellohaptik.com
Fingerprint SHA256: e7de8839d26945139db971940e14ea597a531cafa8083bca47eb6eb377cc3dcd Pin SHA256: wnsTuya9WDZ1gX4EfPRVVz50HIwC/AQQ9O/lwKWqA+w= |
| Common names | *.hellohaptik.com |
| Alternative names | *.hellohaptik.com hellohaptik.com |
| Serial Number | 0086852c7fba7d2e70 |
| Valid from | Thu, 30 Oct 2025 10:30:49 UTC |
| Valid until | Fri, 30 Oct 2026 10:30:49 UTC (expires in 8 months and 28 days) |
| Key | RSA 2048 bits (e 65537) |
| Weak key (Debian) | No |
| Issuer | Go Daddy Secure Certificate Authority - G2
AIA: http://certificates.godaddy.com/repository/gdig2.crt |
| Signature algorithm | SHA256withRSA |
| Extended Validation | No |
| Certificate Transparency | Yes (certificate) |
| OCSP Must Staple | No |
| Revocation information |
CRL, OCSP CRL: http://crl.godaddy.com/gdig2s1-67097.crl OCSP: http://ocsp.godaddy.com/ |
| Revocation status | Good (not revoked) |
| DNS CAA | No (more info) |
| Trusted | Yes
Mozilla Apple Android Java Windows |
|
|
Configuration
| Protocols | |
| TLS 1.3 | Yes |
| TLS 1.2 | Yes |
| TLS 1.1 | No |
| TLS 1.0 | No |
| SSL 3 | No |
| SSL 2 | No |
| Cipher Suites | ||
|
# TLS 1.3 (server has no preference)
|
||
TLS_AES_128_GCM_SHA256 (0x1301)
ECDH x25519 (eq. 3072 bits RSA) FS
|
128 | |
TLS_AES_256_GCM_SHA384 (0x1302)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_CHACHA20_POLY1305_SHA256 (0x1303)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
|
# TLS 1.2 (suites in server-preferred order)
|
||
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (0xcca8)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f)
ECDH x25519 (eq. 3072 bits RSA) FS
|
128 | |
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030)
ECDH x25519 (eq. 3072 bits RSA) FS
|
256 | |
| Handshake Simulation | |||
| Android 4.4.2 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 5.0.0 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 6.0 | RSA 2048 (SHA256) | TLS 1.2 > http/1.1 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Android 7.0 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| Android 8.0 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| Android 8.1 | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| Android 9.0 | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| BingPreview Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Chrome 49 / XP SP3 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Chrome 69 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Chrome 70 / Win 10 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS |
| Chrome 80 / Win 10 R | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS |
| Firefox 31.3.0 ESR / Win 7 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Firefox 47 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Firefox 49 / XP SP3 | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Firefox 62 / Win 7 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Firefox 73 / Win 10 R | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH x25519 FS |
| Googlebot Feb 2018 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| IE 11 / Win 7 R |
Server sent fatal alert: handshake_failure |
||
| IE 11 / Win 8.1 R |
Server sent fatal alert: handshake_failure |
||
| IE 11 / Win Phone 8.1 R |
Server sent fatal alert: handshake_failure |
||
| IE 11 / Win Phone 8.1 Update R |
Server sent fatal alert: handshake_failure |
||
| IE 11 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Edge 15 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 16 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 18 / Win 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH x25519 FS |
| Edge 13 / Win Phone 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Java 8u161 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Java 11.0.3 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Java 12.0.1 | - | TLS 1.3 | TLS_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| OpenSSL 1.0.1l R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| OpenSSL 1.0.2s R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| OpenSSL 1.1.0k R | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| OpenSSL 1.1.1c R | - | TLS 1.3 | TLS_AES_256_GCM_SHA384 ECDH x25519 FS |
| Safari 6 / iOS 6.0.1 |
Server sent fatal alert: handshake_failure |
||
| Safari 7 / iOS 7.1 R |
Server sent fatal alert: handshake_failure |
||
| Safari 7 / OS X 10.9 R |
Server sent fatal alert: handshake_failure |
||
| Safari 8 / iOS 8.4 R |
Server sent fatal alert: handshake_failure |
||
| Safari 8 / OS X 10.10 R |
Server sent fatal alert: handshake_failure |
||
| Safari 9 / iOS 9 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 9 / OS X 10.11 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 10 / iOS 10 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 10 / OS X 10.12 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Safari 12.1.2 / MacOS 10.14.6 Beta R | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| Safari 12.1.1 / iOS 12.3.1 R | - | TLS 1.3 | TLS_CHACHA20_POLY1305_SHA256 ECDH x25519 FS |
| Apple ATS 9 / iOS 9 R | RSA 2048 (SHA256) | TLS 1.2 > h2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| Yahoo Slurp Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
| YandexBot Jan 2015 | RSA 2048 (SHA256) | TLS 1.2 | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDH secp256r1 FS |
|
# Not simulated clients (Protocol mismatch)
|
|||
| Android 2.3.7 No SNI 2 |
Protocol mismatch (not simulated) |
||
| Android 4.0.4 |
Protocol mismatch (not simulated) |
||
| Android 4.1.1 |
Protocol mismatch (not simulated) |
||
| Android 4.2.2 |
Protocol mismatch (not simulated) |
||
| Android 4.3 |
Protocol mismatch (not simulated) |
||
| Baidu Jan 2015 |
Protocol mismatch (not simulated) |
||
| IE 6 / XP No FS 1 No SNI 2 |
Protocol mismatch (not simulated) |
||
| IE 7 / Vista |
Protocol mismatch (not simulated) |
||
| IE 8 / XP No FS 1 No SNI 2 |
Protocol mismatch (not simulated) |
||
| IE 8-10 / Win 7 R |
Protocol mismatch (not simulated) |
||
| IE 10 / Win Phone 8.0 |
Protocol mismatch (not simulated) |
||
| Java 6u45 No SNI 2 |
Protocol mismatch (not simulated) |
||
| Java 7u25 |
Protocol mismatch (not simulated) |
||
| OpenSSL 0.9.8y |
Protocol mismatch (not simulated) |
||
| Safari 5.1.9 / OS X 10.6.8 |
Protocol mismatch (not simulated) |
||
| Safari 6.0.4 / OS X 10.8.4 R |
Protocol mismatch (not simulated) |
||
| (1) Clients that do not support Forward Secrecy (FS) are excluded when determining support for it. | |||
| (2) No support for virtual SSL hosting (SNI). Connects to the default site if the server uses SNI. | |||
| (3) Only first connection attempt simulated. Browsers sometimes retry with a lower protocol version. | |||
| (R) Denotes a reference browser or client, with which we expect better effective security. | |||
| (All) We use defaults, but some platforms do not use their best protocols and features (e.g., Java 6 & 7, older IE). | |||
| (All) Certificate trust is not checked in handshake simulation, we only perform TLS handshake. | |||
| Protocol Details | |
| Secure Renegotiation | Supported |
| Secure Client-Initiated Renegotiation | No |
| Insecure Client-Initiated Renegotiation | No |
| BEAST attack | Mitigated server-side (more info) |
| POODLE (SSLv3) | No, SSL 3 not supported (more info) |
| POODLE (TLS) | No (more info) |
| Zombie POODLE | No (more info) |
| GOLDENDOODLE | No (more info) |
| OpenSSL 0-Length | No (more info) |
| Sleeping POODLE | No (more info) |
| Downgrade attack prevention | Yes, TLS_FALLBACK_SCSV supported (more info) |
| SSL/TLS compression | No |
| RC4 | No |
| Heartbeat (extension) | No |
| Heartbleed (vulnerability) | No (more info) |
| Ticketbleed (vulnerability) | No (more info) |
| OpenSSL CCS vuln. (CVE-2014-0224) | No (more info) |
| OpenSSL Padding Oracle vuln. (CVE-2016-2107) |
No (more info) |
| ROBOT (vulnerability) | No (more info) |
| Forward Secrecy | Yes (with most browsers) ROBUST (more info) |
| ALPN | Yes h2 http/1.1 |
| NPN | Yes grpc-exp h2 http/1.1 http/1.0 |
| Session resumption (caching) | No (IDs empty) |
| Session resumption (tickets) | Yes |
| OCSP stapling | No |
| Strict Transport Security (HSTS) | Invalid
Server provided more than one HSTS header
|
| HSTS Preloading | Not in: Chrome Edge Firefox IE |
| Public Key Pinning (HPKP) | No (more info) |
| Public Key Pinning Report-Only | No |
| Public Key Pinning (Static) | No (more info) |
| Long handshake intolerance | No |
| TLS extension intolerance | No |
| TLS version intolerance | No |
| Incorrect SNI alerts | No |
| Uses common DH primes | No, DHE suites not supported |
| DH public server param (Ys) reuse | No, DHE suites not supported |
| ECDH public server param reuse | No |
| Supported Named Groups | x25519, secp256r1 (server preferred order) |
| SSL 2 handshake compatibility | No |
| 0-RTT enabled | No |
|
|
|
1 https://stagingalb.hellohaptik.com/
(HTTP/1.1 301 Moved Permanently)
| 1 | |
| Date | Mon, 02 Feb 2026 02:58:50 GMT | |
| Content-Type | text/html; charset=utf-8 | |
| Content-Length | 0 | |
| Location | home/ | |
| Vary | Cookie, Origin | |
| Strict-Transport-Security | max-age=31536000; includeSubDomains; preload | |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload | |
| X-XSS-Protection | 1; mode=block | |
| X-XSS-Protection | 1; mode=block | |
| Server | You Should Not Know | |
| X-Frame-Options | SAMEORIGIN | |
| X-Content-Type-Options | nosniff | |
| Content-Security-Policy | upgrade-insecure-requests; default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.hotjar.com *.doubleclick.net *.sentry.io *.google-analytics.com *.googletagmanager.com *.twilio.com *.userpilot.io *.cloudfront.net *.s3.amazonaws.com *.gstatic.com *.google.com *.google.co.in *.google.co.id *.google.ca *.google.ae *.google.co.za *.shopify.com *.imagekit.io *.wikia.nocookie.net *.wp.com *.postimg.cc *.content-cdn.io *.s3.ap-south-1.amazonaws.com *.s3.ap-southeast-1.amazonaws.com *.me-central-1.amazonaws.com *.facebook.com *.tools-cdn.s3.ap-south-1.amazonaws.com metrics.hotjar.io vc.hotjar.io content.hotjar.io maps.googleapis.com jiomart-staging.haptikapi.net https://image-store-haptik.s3.amazonaws.com/ https://dev.godrejproperties.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.hotjar.com *.doubleclick.net *.sentry.io *.google-analytics.com *.googletagmanager.com *.twilio.com *.userpilot.io *.cloudfront.net ajax.googleapis.com cdn.jsdelivr.net cdn.datatables.net code.jquery.com cdn.shopify.com unpkg.com maxcdn.bootstrapcdn.com gitcdn.github.io cdnjs.cloudflare.com js-agent.newrelic.com bam.nr-data.net connect.facebook.net graph.facebook.com static.xx.fbcdn.net www.facebook.com web.facebook.com api.mixpanel.com app.getbeamer.com backend.getbeamer.com develop.talasi.com docs.haptik.ai haptikproxy6f2461135ffd1b6a80db296ec15ab.onrender.com servicedesk.alliancebroadband.in wakefit-co.s3.ap-south-1.amazonaws.com external-gateway.ideopay.in external-gateway.test.ideopay.in media.twiliocdn.com iss.adanielectricity.com adanidotcom.azureedge.net hellohaptik.github.io d17dxpmzfsk3gn.cloudfront.net jioprodwanotification.blob.core.windows.net maps.googleapis.com tools-cdn.s3.ap-south-1.amazonaws.com; font-src 'self' data: fonts.googleapis.com fonts.gstatic.com toolassets.haptikapi.com maxcdn.bootstrapcdn.com unpkg.com cdnjs.cloudflare.com; img-src 'self' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.gstatic.com *.google.com *.google.co.in *.google.co.id *.google.ca *.google.ae *.google.co.za *.googletagmanager.com *.google-analytics.com *.cloudfront.net *.shopify.com *.imagekit.io *.wikia.nocookie.net *.wp.com *.postimg.cc *.content-cdn.io *.s3.amazonaws.com *.s3.ap-south-1.amazonaws.com *.s3.ap-southeast-1.amazonaws.com *.me-central-1.amazonaws.com expert-dashboard.s3.amazonaws.com haptikdev.s3.amazonaws.com haptikappimg.s3.amazonaws.com jio-haptikappimg.s3.amazonaws.com https://borosil-haptik.s3.amazonaws.com/ jio-expert-bucket.s3.amazonaws.com healthhub-sit-haptik.s3.amazonaws.com originserver-static1-uat.pvrcinemas.com iflbucket.s3.amazonaws.com https://image-store-haptik.s3.amazonaws.com/ nsdc-haptikappimg.s3.amazonaws.com images.sg.content-cdn.io storage.sg.content-cdn.io media.twiliocdn.com olacabs-customer-invoice-stage.s3.ap-southeast-1.amazonaws.com dam.alfuttaim.com thumbor.prod.raenabeauty.com static.suzuyagroup.com sidomuncul.kemanastaging.com www.sidomunculstore.com cdn.tirabeauty.com product.indiashoppe.com cdnjs.cloudflare.com www.google.com www.jio.com www.koltepatil.com www.mahindratractor.com www.haldinfoods.com www.whirlpoolindia.com www.extra.com www.rummycircle.com www.godrejproperties.com s2.googleusercontent.com i.ibb.co cdn.dribbble.com maps.googleapis.com https://dev.godrejproperties.com/ https://iflbucket.s3.amazonaws.com https://iflbucket.s3.ap-south-1.amazonaws.com; media-src 'self' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.s3.amazonaws.com *.cloudfront.net haptikappimg.s3.amazonaws.com jio-haptikappimg.s3.amazonaws.com haptikappimg-v1.s3.amazonaws.com pb-vendor-chatbot-data.s3.amazonaws.com healthhub-sit-haptik.s3.amazonaws.com code.jquery.com cdn.datatables.net upload.wikimedia.org media.twiliocdn.com www.youtube.com www.google.com www.extra.com ssl.google-analytics.com cdnjs.cloudflare.com ik.imagekit.io dev.buzzo.ai tools-cdn.s3.ap-south-1.amazonaws.com; connect-src 'self' blob: data: wss: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.hotjar.com *.facebook.com *.twilio.com *.userpilot.io api.mixpanel.com backend.getbeamer.com app.getbeamer.com js-agent.newrelic.com bam.nr-data.net connect.facebook.net mqtt.haptik.me mqtt-emqx.haptik.me mqtt.haptikpreprod.com uat-emqx-pub.betalaunch.in haptik-du-emqx.hellohaptik.com:1443 voice-js.roaming.twilio.com eventgw.us1.twilio.com media.twiliocdn.com www.google-analytics.com hellohaptik.github.io haptikappimg.s3.amazonaws.com jio-haptikappimg.s3.amazonaws.com content.hotjar.io metrics.hotjar.io vc.hotjar.io maps.googleapis.com jiomart-staging.haptikapi.net https://image-store-haptik.s3.amazonaws.com/ https://iflbucket.s3.amazonaws.com https://iflbucket.s3.ap-south-1.amazonaws.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com cdn.jsdelivr.net *.haptikapi.com app.getbeamer.com ajax.googleapis.com gitcdn.github.io cdn.datatables.net maxcdn.bootstrapcdn.com; manifest-src 'self' 'unsafe-inline' www.google-analytics.com *.haptikapi.com; report-uri https://o225877.ingest.us.sentry.io/api/6581570/security/?sentry_key=331680aa3537425293f5266d36391ab9; frame-ancestors 'self' https://mycallgenie.ai | |
| Via | 1.1 google | |
| Alt-Svc | h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 | |
| Connection | close | |
|
2 https://stagingalb.hellohaptik.com/home/
(HTTP/1.1 302 Found)
| 2 | |
| Date | Mon, 02 Feb 2026 02:58:51 GMT | |
| Content-Type | text/html; charset=utf-8 | |
| Content-Length | 0 | |
| Location | /login/?next=/home/ | |
| Vary | Cookie, Origin | |
| Strict-Transport-Security | max-age=31536000; includeSubDomains; preload | |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload | |
| X-XSS-Protection | 1; mode=block | |
| X-XSS-Protection | 1; mode=block | |
| Server | You Should Not Know | |
| X-Frame-Options | SAMEORIGIN | |
| X-Content-Type-Options | nosniff | |
| Content-Security-Policy | upgrade-insecure-requests; default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.hotjar.com *.doubleclick.net *.sentry.io *.google-analytics.com *.googletagmanager.com *.twilio.com *.userpilot.io *.cloudfront.net *.s3.amazonaws.com *.gstatic.com *.google.com *.google.co.in *.google.co.id *.google.ca *.google.ae *.google.co.za *.shopify.com *.imagekit.io *.wikia.nocookie.net *.wp.com *.postimg.cc *.content-cdn.io *.s3.ap-south-1.amazonaws.com *.s3.ap-southeast-1.amazonaws.com *.me-central-1.amazonaws.com *.facebook.com *.tools-cdn.s3.ap-south-1.amazonaws.com metrics.hotjar.io vc.hotjar.io content.hotjar.io maps.googleapis.com jiomart-staging.haptikapi.net https://image-store-haptik.s3.amazonaws.com/ https://dev.godrejproperties.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.hotjar.com *.doubleclick.net *.sentry.io *.google-analytics.com *.googletagmanager.com *.twilio.com *.userpilot.io *.cloudfront.net ajax.googleapis.com cdn.jsdelivr.net cdn.datatables.net code.jquery.com cdn.shopify.com unpkg.com maxcdn.bootstrapcdn.com gitcdn.github.io cdnjs.cloudflare.com js-agent.newrelic.com bam.nr-data.net connect.facebook.net graph.facebook.com static.xx.fbcdn.net www.facebook.com web.facebook.com api.mixpanel.com app.getbeamer.com backend.getbeamer.com develop.talasi.com docs.haptik.ai haptikproxy6f2461135ffd1b6a80db296ec15ab.onrender.com servicedesk.alliancebroadband.in wakefit-co.s3.ap-south-1.amazonaws.com external-gateway.ideopay.in external-gateway.test.ideopay.in media.twiliocdn.com iss.adanielectricity.com adanidotcom.azureedge.net hellohaptik.github.io d17dxpmzfsk3gn.cloudfront.net jioprodwanotification.blob.core.windows.net maps.googleapis.com tools-cdn.s3.ap-south-1.amazonaws.com; font-src 'self' data: fonts.googleapis.com fonts.gstatic.com toolassets.haptikapi.com maxcdn.bootstrapcdn.com unpkg.com cdnjs.cloudflare.com; img-src 'self' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.gstatic.com *.google.com *.google.co.in *.google.co.id *.google.ca *.google.ae *.google.co.za *.googletagmanager.com *.google-analytics.com *.cloudfront.net *.shopify.com *.imagekit.io *.wikia.nocookie.net *.wp.com *.postimg.cc *.content-cdn.io *.s3.amazonaws.com *.s3.ap-south-1.amazonaws.com *.s3.ap-southeast-1.amazonaws.com *.me-central-1.amazonaws.com expert-dashboard.s3.amazonaws.com haptikdev.s3.amazonaws.com haptikappimg.s3.amazonaws.com jio-haptikappimg.s3.amazonaws.com https://borosil-haptik.s3.amazonaws.com/ jio-expert-bucket.s3.amazonaws.com healthhub-sit-haptik.s3.amazonaws.com originserver-static1-uat.pvrcinemas.com iflbucket.s3.amazonaws.com https://image-store-haptik.s3.amazonaws.com/ nsdc-haptikappimg.s3.amazonaws.com images.sg.content-cdn.io storage.sg.content-cdn.io media.twiliocdn.com olacabs-customer-invoice-stage.s3.ap-southeast-1.amazonaws.com dam.alfuttaim.com thumbor.prod.raenabeauty.com static.suzuyagroup.com sidomuncul.kemanastaging.com www.sidomunculstore.com cdn.tirabeauty.com product.indiashoppe.com cdnjs.cloudflare.com www.google.com www.jio.com www.koltepatil.com www.mahindratractor.com www.haldinfoods.com www.whirlpoolindia.com www.extra.com www.rummycircle.com www.godrejproperties.com s2.googleusercontent.com i.ibb.co cdn.dribbble.com maps.googleapis.com https://dev.godrejproperties.com/ https://iflbucket.s3.amazonaws.com https://iflbucket.s3.ap-south-1.amazonaws.com; media-src 'self' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.s3.amazonaws.com *.cloudfront.net haptikappimg.s3.amazonaws.com jio-haptikappimg.s3.amazonaws.com haptikappimg-v1.s3.amazonaws.com pb-vendor-chatbot-data.s3.amazonaws.com healthhub-sit-haptik.s3.amazonaws.com code.jquery.com cdn.datatables.net upload.wikimedia.org media.twiliocdn.com www.youtube.com www.google.com www.extra.com ssl.google-analytics.com cdnjs.cloudflare.com ik.imagekit.io dev.buzzo.ai tools-cdn.s3.ap-south-1.amazonaws.com; connect-src 'self' blob: data: wss: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.hotjar.com *.facebook.com *.twilio.com *.userpilot.io api.mixpanel.com backend.getbeamer.com app.getbeamer.com js-agent.newrelic.com bam.nr-data.net connect.facebook.net mqtt.haptik.me mqtt-emqx.haptik.me mqtt.haptikpreprod.com uat-emqx-pub.betalaunch.in haptik-du-emqx.hellohaptik.com:1443 voice-js.roaming.twilio.com eventgw.us1.twilio.com media.twiliocdn.com www.google-analytics.com hellohaptik.github.io haptikappimg.s3.amazonaws.com jio-haptikappimg.s3.amazonaws.com content.hotjar.io metrics.hotjar.io vc.hotjar.io maps.googleapis.com jiomart-staging.haptikapi.net https://image-store-haptik.s3.amazonaws.com/ https://iflbucket.s3.amazonaws.com https://iflbucket.s3.ap-south-1.amazonaws.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com cdn.jsdelivr.net *.haptikapi.com app.getbeamer.com ajax.googleapis.com gitcdn.github.io cdn.datatables.net maxcdn.bootstrapcdn.com; manifest-src 'self' 'unsafe-inline' www.google-analytics.com *.haptikapi.com; report-uri https://o225877.ingest.us.sentry.io/api/6581570/security/?sentry_key=331680aa3537425293f5266d36391ab9; frame-ancestors 'self' https://mycallgenie.ai | |
| Via | 1.1 google | |
| Alt-Svc | h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 | |
| Connection | close | |
|
3 https://stagingalb.hellohaptik.com/login/?next=/home/
(HTTP/1.1 302 Found)
| 3 | |
| Date | Mon, 02 Feb 2026 02:58:51 GMT | |
| Content-Type | text/html; charset=utf-8 | |
| Content-Length | 0 | |
| Location | https://identity.hellohaptik.com/auth/realms/haptik_api/protocol/openid-connect/auth?response_type=code&scope=openid+email+profile&client_id=haptik&redirect_uri=https%3A%2F%2Fstagingalb.hellohaptik.com%2Foidc_callback%2F%3Fnext%3D%2Fhome%2F&state=D7khqeRMX0HHKBAiQYVnU7LGiz1cvn | |
| Vary | Cookie, Origin | |
| Strict-Transport-Security | max-age=31536000; includeSubDomains; preload | |
| Strict-Transport-Security | max-age=31536000; includeSubdomains; preload | |
| X-XSS-Protection | 1; mode=block | |
| X-XSS-Protection | 1; mode=block | |
| Set-Cookie | sessionid=lkp1qu54qgjgh0fjt9kt38t545a70hia; expires=Tue, 03 Feb 2026 02:58:51 GMT; HttpOnly; Max-Age=86400; Path=/; SameSite=Lax; Secure | |
| Server | You Should Not Know | |
| X-Frame-Options | SAMEORIGIN | |
| X-Content-Type-Options | nosniff | |
| Content-Security-Policy | upgrade-insecure-requests; default-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.hotjar.com *.doubleclick.net *.sentry.io *.google-analytics.com *.googletagmanager.com *.twilio.com *.userpilot.io *.cloudfront.net *.s3.amazonaws.com *.gstatic.com *.google.com *.google.co.in *.google.co.id *.google.ca *.google.ae *.google.co.za *.shopify.com *.imagekit.io *.wikia.nocookie.net *.wp.com *.postimg.cc *.content-cdn.io *.s3.ap-south-1.amazonaws.com *.s3.ap-southeast-1.amazonaws.com *.me-central-1.amazonaws.com *.facebook.com *.tools-cdn.s3.ap-south-1.amazonaws.com metrics.hotjar.io vc.hotjar.io content.hotjar.io maps.googleapis.com jiomart-staging.haptikapi.net https://image-store-haptik.s3.amazonaws.com/ https://dev.godrejproperties.com/; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.hotjar.com *.doubleclick.net *.sentry.io *.google-analytics.com *.googletagmanager.com *.twilio.com *.userpilot.io *.cloudfront.net ajax.googleapis.com cdn.jsdelivr.net cdn.datatables.net code.jquery.com cdn.shopify.com unpkg.com maxcdn.bootstrapcdn.com gitcdn.github.io cdnjs.cloudflare.com js-agent.newrelic.com bam.nr-data.net connect.facebook.net graph.facebook.com static.xx.fbcdn.net www.facebook.com web.facebook.com api.mixpanel.com app.getbeamer.com backend.getbeamer.com develop.talasi.com docs.haptik.ai haptikproxy6f2461135ffd1b6a80db296ec15ab.onrender.com servicedesk.alliancebroadband.in wakefit-co.s3.ap-south-1.amazonaws.com external-gateway.ideopay.in external-gateway.test.ideopay.in media.twiliocdn.com iss.adanielectricity.com adanidotcom.azureedge.net hellohaptik.github.io d17dxpmzfsk3gn.cloudfront.net jioprodwanotification.blob.core.windows.net maps.googleapis.com tools-cdn.s3.ap-south-1.amazonaws.com; font-src 'self' data: fonts.googleapis.com fonts.gstatic.com toolassets.haptikapi.com maxcdn.bootstrapcdn.com unpkg.com cdnjs.cloudflare.com; img-src 'self' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.gstatic.com *.google.com *.google.co.in *.google.co.id *.google.ca *.google.ae *.google.co.za *.googletagmanager.com *.google-analytics.com *.cloudfront.net *.shopify.com *.imagekit.io *.wikia.nocookie.net *.wp.com *.postimg.cc *.content-cdn.io *.s3.amazonaws.com *.s3.ap-south-1.amazonaws.com *.s3.ap-southeast-1.amazonaws.com *.me-central-1.amazonaws.com expert-dashboard.s3.amazonaws.com haptikdev.s3.amazonaws.com haptikappimg.s3.amazonaws.com jio-haptikappimg.s3.amazonaws.com https://borosil-haptik.s3.amazonaws.com/ jio-expert-bucket.s3.amazonaws.com healthhub-sit-haptik.s3.amazonaws.com originserver-static1-uat.pvrcinemas.com iflbucket.s3.amazonaws.com https://image-store-haptik.s3.amazonaws.com/ nsdc-haptikappimg.s3.amazonaws.com images.sg.content-cdn.io storage.sg.content-cdn.io media.twiliocdn.com olacabs-customer-invoice-stage.s3.ap-southeast-1.amazonaws.com dam.alfuttaim.com thumbor.prod.raenabeauty.com static.suzuyagroup.com sidomuncul.kemanastaging.com www.sidomunculstore.com cdn.tirabeauty.com product.indiashoppe.com cdnjs.cloudflare.com www.google.com www.jio.com www.koltepatil.com www.mahindratractor.com www.haldinfoods.com www.whirlpoolindia.com www.extra.com www.rummycircle.com www.godrejproperties.com s2.googleusercontent.com i.ibb.co cdn.dribbble.com maps.googleapis.com https://dev.godrejproperties.com/ https://iflbucket.s3.amazonaws.com https://iflbucket.s3.ap-south-1.amazonaws.com; media-src 'self' blob: data: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.s3.amazonaws.com *.cloudfront.net haptikappimg.s3.amazonaws.com jio-haptikappimg.s3.amazonaws.com haptikappimg-v1.s3.amazonaws.com pb-vendor-chatbot-data.s3.amazonaws.com healthhub-sit-haptik.s3.amazonaws.com code.jquery.com cdn.datatables.net upload.wikimedia.org media.twiliocdn.com www.youtube.com www.google.com www.extra.com ssl.google-analytics.com cdnjs.cloudflare.com ik.imagekit.io dev.buzzo.ai tools-cdn.s3.ap-south-1.amazonaws.com; connect-src 'self' blob: data: wss: *.hellohaptik.com *.haptikapi.com *.haptikprod.com *.hotjar.com *.facebook.com *.twilio.com *.userpilot.io api.mixpanel.com backend.getbeamer.com app.getbeamer.com js-agent.newrelic.com bam.nr-data.net connect.facebook.net mqtt.haptik.me mqtt-emqx.haptik.me mqtt.haptikpreprod.com uat-emqx-pub.betalaunch.in haptik-du-emqx.hellohaptik.com:1443 voice-js.roaming.twilio.com eventgw.us1.twilio.com media.twiliocdn.com www.google-analytics.com hellohaptik.github.io haptikappimg.s3.amazonaws.com jio-haptikappimg.s3.amazonaws.com content.hotjar.io metrics.hotjar.io vc.hotjar.io maps.googleapis.com jiomart-staging.haptikapi.net https://image-store-haptik.s3.amazonaws.com/ https://iflbucket.s3.amazonaws.com https://iflbucket.s3.ap-south-1.amazonaws.com; style-src 'self' 'unsafe-inline' fonts.googleapis.com cdnjs.cloudflare.com cdn.jsdelivr.net *.haptikapi.com app.getbeamer.com ajax.googleapis.com gitcdn.github.io cdn.datatables.net maxcdn.bootstrapcdn.com; manifest-src 'self' 'unsafe-inline' www.google-analytics.com *.haptikapi.com; report-uri https://o225877.ingest.us.sentry.io/api/6581570/security/?sentry_key=331680aa3537425293f5266d36391ab9; frame-ancestors 'self' https://mycallgenie.ai | |
| Via | 1.1 google | |
| Alt-Svc | h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 | |
| Connection | close | |
| Miscellaneous | |
| Test date | Mon, 02 Feb 2026 02:58:43 UTC |
| Test duration | 44.398 seconds |
| HTTP status code | 302 |
| HTTP forwarding | https://identity.hellohaptik.com |
| HTTP server signature | You Should Not Know |
| Server hostname | 98.43.120.34.bc.googleusercontent.com |
SSL Report v2.4.1
