The split
That way a dashboard or monitoring system can hold the read token without also being able to stop a
vendor.
An unset token answers 404, not 401
Absent configuration disables the endpoint rather than leaving it open. A wrong token gets the same404 rather than a 401, so a caller cannot tell whether there is something here to find a
token for.
It is deliberately not under /secure
That prefix is authenticated with messaging credentials, which belong to customers. Queue depths,
vendor names and bind state are gateway-wide, so publishing them there would hand every customer who
can send an SMS a view of the whole gateway.
The management port carries its own token instead — and a messaging credential does not open it.
Keep the port off the public network
Keep 9000 on an admin network and do not publish it. The token is a second line, not the first.
Absent is not zero
This rule runs through every field on/ops/health, and reading it wrong produces confident wrong
conclusions:
cdr.failed is lost billing data
A failed batch is never retried and those records are gone. It is not a transient.
Alert on any non-zero value. This is revenue you cannot invoice, and nothing else will tell you.
A substring search is not an identity check
q=ACME on the sessions endpoint also returns ACMEINTL.
Anything acting on a result — disconnecting a login’s binds, say — must compare system_id
exactly rather than trusting the match.
Related
The management port
Every endpoint and its token.
Live health
Reading the payload those tokens unlock.