PentestingHere
Log in Join

Spotify

Spotify on HackerOne · HackerOne Active

Official page

Scope

At a glance

  • Bounties: Yes
  • Swag: No
  • Managed by the platform: Yes
  • Average first response: 4.4 days
  • Average time to resolution: 55.2 days

In scope

  • *.atspotify.com
  • *.avecspotify.com
  • *.byspotify.com
  • *.enspotify.com
  • *.forspotify.com
  • *.fromspotify.com
  • *.spotify.com
  • *.spotify.net
  • *.tospotify.com
  • *.withspotify.com
  • Anchor
  • Android SDK
  • Core Assets
  • Core Backstage source code
  • DRM (Digital Rights Management) System
  • GHE
  • Jira
  • Megaphone
  • Non-Core Assets
  • Okta
  • Other Spotify websites
  • Podsights
  • Save to Spotify CLI
  • Sonantic
  • Spotify SDKs
  • Spotify desktop application (Windows and Mac)
  • VPN
  • Web Playback SDK
  • Wrapped
  • api-partner.spotify.com
  • api.spotify.com
  • assets.spotify.com
  • backstage.io
  • com.anchorfminc.Anchor
  • com.spotify.client
  • com.spotify.kids
  • com.spotify.music
  • com.spotify.s4a
  • com.spotify.tv.android
  • fm.anchor.android

3 more assets on the official page.

Out of scope

  • Findaway
  • Preact
  • Soundtrap
  • The Ringer
  • com.soundtrap.studioapp
  • everynoise.com
  • example.com

Imported from the public directory. Always confirm scope on the official program page before testing.

Is it worth your time?

Read the community feedback

0 reviews rating communication, triage, payouts and whether it suits beginners.

Open feedback