Before your first HawkScan against a REST API, get an accurate OpenAPI spec wired in. Preference order: a spec the running app itself serves, then a build step that generates one, then a spec published outside the repo, and only then a hand-derived one. Then resolve-check it: `host + spec-path` must return real routes, not 404s, before you scan. A spider-only scan looks green while missing most of your API surface, and a stale spec is worse: every path 404s and the scan reports nothing because it tested nothing. For SPAs, the same logic applies to the backend API: the Ajax spider can crawl the UI, but the higher-value target is usually the API behind it, scanned with its spec.