Paga · Domain Security

Paga Domain Security

Domain security

Domain security posture for Paga, probed live across 4 host(s) and 0 registrable domain(s). 4 host(s) serve HTTPS; 0 advertise HSTS.

PaymentsMobile MoneyFintechCollectionNigeria

Transport & Host Security

www.paga.com
HTTPS: yes · HSTS: no · cert expires: Dec 12 13:07:15 2026 GMT
developer-docs.paga.com
HTTPS: yes · HSTS: no · cert expires: Oct 2 11:33:03 2026 GMT
collect.paga.com
HTTPS: yes · HSTS: no · cert expires: Dec 12 13:07:15 2026 GMT
www.mypaga.com
HTTPS: yes · HSTS: no · cert expires: Sep 29 12:13:50 2026 GMT

Domain (DNS/Email) Security

Source

Domain Security

Raw ↑
generated: '2026-07-17'
method: probed
source: live TLS/HTTP probes of apis.yml + OpenAPI hosts (2026-07-17)
hosts:
- host: www.paga.com
  https: true
  http_status: 302
  tls_verified: true
  cert_expires: Dec 12 13:07:15 2026 GMT
- host: developer-docs.paga.com
  https: true
  http_status: 302
  tls_verified: true
  cert_expires: Oct  2 11:33:03 2026 GMT
- host: collect.paga.com
  https: true
  http_status: 403
  tls_verified: true
  cert_expires: Dec 12 13:07:15 2026 GMT
  notes: Collect API host; 403 to unauthenticated browser GET is expected (API POST endpoints only).
- host: www.mypaga.com
  https: true
  http_status: 200
  tls_verified: true
  cert_expires: Sep 29 12:13:50 2026 GMT
  notes: Business API host (path /paga-webservices/business-rest/secured).
transport:
- All documented endpoints are HTTPS only.
- Business API additionally requires caller IP whitelisting before access is granted.
- Per-request payload integrity is enforced by a SHA-512 hash header over ordered request parameters plus the account hash key.
notes: >-
  All four in-scope hosts terminate valid TLS certificates. Region hosts are
  Nigeria-oriented (mypaga.com for the Business API, collect.paga.com for
  Collect and Direct Debit). No formal Paga security.txt was confirmed at probe
  time; report vulnerabilities to Paga support.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/paga-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.