What this record establishes
Reviewed policy
An individually reviewed public policy is linked to this program page.
Read the reviewed policy profile →
Official directory card labeled Bug Bounty. Monetary reward displayed. Program policy and submission status not reviewed.
Published asset scope
Snapshot captured 2026-10-03. Scope status: Captured.
| Asset | Type | Group / eligibility |
|---|---|---|
bugcrowd-pam-###.oktapreview.com | website | Okta Privileged Access |
bugcrowd-pam-###.pam.oktapreview.com | website | Okta Privileged Access |
https://bugcrowd-pam-###.workflows.oktapreview.com | website | Okta Workflows |
Desktop MFA for Windows | other | Okta Device Access |
Desktop MFA for macOS | other | Okta Device Access |
Password Sync for macOS | other | Okta Device Access |
support.okta.comPublished location: https://support.okta.com | website | Okta Support Portal (support.okta.com) |
https://bugcrowd-pam-###.at.oktapreview.com | website | AtSpoke (Okta Access Requests) (New) |
https://bugcrowd-pam-###.oktapreview.com | website | Okta (OIE) In-Scope Targets (New) |
Okta Verify FastpassPublished location: https://www.okta.com/fastpass/ | other | Okta (OIE) In-Scope Targets (New) |
https://bugcrowd-pam-###-admin.oktapreview.com | website | Okta (OIE) In-Scope Targets (New) |
Advanced Server Access (ASA) / (ScaleFT)Published location: https://www.okta.com/products/advanced-server-access/ | website | Advanced Server Access |
http://app.scaleft.com/ | website | Advanced Server Access |
Advanced Server Access Client / AgentsPublished location: https://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htm | other | Advanced Server Access |
Okta Verify (iOS)Published location: https://apps.apple.com/us/app/okta-verify/id490179405 | ios | Other In-Scope Targets |
Okta Verify (Android)Published location: https://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=US | android | Other In-Scope Targets |
Okta Verify (Mac OS)Published location: https://apps.apple.com/us/app/okta-verify/id490179405 | other | Other In-Scope Targets |
Okta Verify (Windows) | other | Other In-Scope Targets |
Okta On-Prem Agents ( AD, LDAP, RDP, IWA ) | other | Other In-Scope Targets |
Okta Agent WindowsPublished location: https://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htm | other | Other In-Scope Targets |
Okta Browser Plugin (IE / Firefox / Chrome)Published location: https://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htm | other | Other In-Scope Targets |
| Asset | Type | Group / eligibility |
|---|---|---|
personal.trexcloud.com | website | Okta Personal |
bugcrowd-%username%-1.oktapreview.com | website | Okta (Classic) In-Scope Targets |
bugcrowd-%username%-2.oktapreview.com | website | Okta (Classic) In-Scope Targets |
*.okta.com | website | Out of Scope Targets |
*.trexcloud.com | website | Out of Scope Targets |
login.okta.com | website | Out of Scope Targets |
pages.okta.com | website | Out of Scope Targets |
developer.okta.com | website | Out of Scope Targets |
trust.okta.com | website | Out of Scope Targets |
www.okta.com (static site) | website | Out of Scope Targets |
https://scaleft.com | website | Out of Scope Targets |
https://app.scaleft.com/p/signup | website | Out of Scope Targets |
https://github.com/oktadev | website | Out of Scope Targets |
Backend Okta non-app infrastructure | other | Out of Scope Targets |
Network layer issues | other | Out of Scope Targets |
AtSpoke - Okta Workflows actions in access requests | website | Out of Scope Targets |
AtSpoke - Entitlement bundles as a resource in access requests | website | Out of Scope Targets |
Anything not explicitly called out above as in-scope | other | Out of Scope Targets |
Capture limits
- Brief displays May 22, 2026 as its update date. Older embedded announcements are not proof of current scope or bonus eligibility.
- USD normalization uses Bugcrowd accounting documentation; the brief itself displays dollar signs.
- The linked primary Vulnerability Disclosure Policy PDF could not be retrieved by the text tool. Supplemental terms were read and display July 22, 2019. Review is not a complete legal-terms audit.
- No authenticated submission was attempted. Product-specific setup details and asset inventories are deliberately omitted; live terms prevail.
- Linked announcement and change-log archives were not separately read; announcement facts above come from notices displayed within the reviewed brief.
- Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research.
Live policy and platform eligibility still require review.
Sources and collection identity
- Official program page Primary source · reviewed 2026-10-03
- Published scope source Primary source · reviewed 2026-10-03
Appears in Discovery, Bounty, Bugcrowd, Profile. No identity match is inferred from a shared company name.