We should investigate whether there are any unspecced (and unused) endpoints in Synapse.
See #8177 about some of the admin APIs being exposed under /_matrix/client.
I took a look at some of the federation APIs and client APIs also, will put some results in here tomorrow.
#8154 also has some related info.