When you see a domain like passport-api-sg.hoyoverse.com, the first question is whether it's a legitimate part of the HoYoverse ecosystem or something else. The answer is straightforward: this is a backend API subdomain used for authentication in Singapore. It's not a consumer website, so there's no about page, privacy policy, or contact form to find. That's not a red flag; it's the norm for technical endpoints.
What matters for safety is the infrastructure. The site uses a valid SSL certificate, is served through AWS CloudFront, and has no history on any blacklist or Google Safe Browsing. The parent domain, hoyoverse.com, is a well‑known gaming company with a global presence. The subdomain itself resolves to four CloudFront IPs and loads quickly, even though it returns a 404 when accessed directly in a browser (many APIs do that).
If you're a developer integrating HoYoverse's passport API, this subdomain is the right one. The security signals are strong, and the ownership is clear. There's no evidence of phishing or scam activity. For anyone wondering "is passport-api-sg.hoyoverse.com fake?" the data says no. It's a legitimate piece of infrastructure from a major gaming company.