What this record establishes
Scope capture
Published asset rows were captured. The full policy and eligibility were not individually reviewed.
Official directory card labeled Bug Bounty. Monetary reward displayed. Program policy and submission status not reviewed.
Published asset scope
Snapshot captured 2026-10-03. Scope status: Captured.
| Asset | Type | Group / eligibility |
|---|---|---|
config.cic-bug-bounty.auth0app.com | website | Tier 1 Targets |
manage.cic-bug-bounty.auth0app.com (Management Dashboard)Published location: https://manage.cic-bug-bounty.auth0app.com/ | website | Tier 1 Targets |
*.cic-bug-bounty.auth0app.com | website | Tier 1 Targets |
Auth0 Guardian AndroidPublished location: https://play.google.com/store/apps/details?id=com.auth0.guardian&hl=en_US&gl=US | android | Tier 1 Targets |
Auth0 Guardian IoSPublished location: https://apps.apple.com/us/app/auth0-guardian/id1093447833 | ios | Tier 1 Targets |
marketplace.auth0.com (Auth0 Marketplace)Published location: https://marketplace.auth0.com | website | Tier 1 Targets |
MFA Integrations | other | Tier 1 Targets |
https://dashboard.fga.dev/ | website | Tier 1 Targets |
https://api.us1.fga.dev/ | api | Tier 1 Targets |
https://customers.us1.fga.dev/ | api | Tier 1 Targets |
https://play.fga.dev/ | website | Tier 1 Targets |
Auth0 SDK for Web (Auth0.js)Published location: https://github.com/auth0/auth0.js | other | SDK Targets |
Lock for Web (lock)Published location: https://github.com/auth0/lock | other | SDK Targets |
Auth0 Single Page App SDK (auth0-spa-js)Published location: https://github.com/auth0/auth0-spa-js | other | SDK Targets |
.NET SDK (Auth0.Net)Published location: https://github.com/auth0/Auth0.Net | other | SDK Targets |
Auth0 Next.js SDK (nextjs-auth0)Published location: https://github.com/auth0/nextjs-auth0 | other | SDK Targets |
Auth0 Java SDK (auth0-java)Published location: https://github.com/auth0/auth0-java | other | SDK Targets |
Auth0 React Native SDK (react-native-auth0)Published location: https://github.com/auth0/react-native-auth0 | other | SDK Targets |
Auth0 PHP SDK (auth0-php)Published location: https://github.com/auth0/auth0-php | other | SDK Targets |
auth0.com | website | Tier 2 Targets |
samltool.io | website | Tier 2 Targets |
webauthn.me | website | Tier 2 Targets |
openidconnect.net | website | Tier 2 Targets |
jwt.io | website | Tier 2 Targets |
auth0.net | website | Tier 2 Targets |
| Asset | Type | Group / eligibility |
|---|---|---|
auth0.auth0.com | website | Out of scope targets |
manage.auth0.com | website | Out of scope targets |
accounts.auth0.com | website | Out of scope targets |
webtask.io | website | Out of scope targets |
phenix.rocks | website | Out of scope targets |
Auth0 Docs (including quickstarts) | website | Out of scope targets |
sharelock.io | website | Out of scope targets |
goextend.io | website | Out of scope targets |
https://support.auth0.com/tickets/new | website | Out of scope targets |
support.auth0.com | website | Out of scope targets |
community.auth0.com | website | Out of scope targets |
Auth0 passport-ws-fedPublished location: https://github.com/auth0/passport-wsfed-saml2 | other | Out of scope targets |
Capture limits
- Only the published asset table was captured; program rules and eligibility still require individual review.
Live policy and platform eligibility still require review.
Sources and collection identity
- Official program page Primary source · reviewed 2026-10-03
- Published scope source Primary source · reviewed 2026-10-03
Appears in Discovery, Bounty, Bugcrowd. No identity match is inferred from a shared company name.