vulns.co
/
GKData.io MCP

HackerOne · 2 min read

Spotify

Paid Bounty

Open current program Scope capture

What this record establishes

Scope capture

Published asset rows were captured. The full policy and eligibility were not individually reviewed.

Directory row 403; Active program checkbox checked; Bounties minimum displayed $250. Positive displayed minimum supports paid bounty listing. Policy and live submission availability unverified.

Published asset scope

Snapshot captured 2026-10-03. Scope status: Captured.

In scope · 45 published rows
AssetTypeGroup / eligibility
*.spotify.comWILDCARDBounty eligible: Yes
*.spotify.netWILDCARDBounty eligible: Yes
*.withspotify.comWILDCARDBounty eligible: Yes
*.byspotify.comWILDCARDBounty eligible: Yes
*.atspotify.comWILDCARDBounty eligible: Yes
*.avecspotify.comWILDCARDBounty eligible: Yes
*.enspotify.comWILDCARDBounty eligible: Yes
*.forspotify.comWILDCARDBounty eligible: Yes
*.fromspotify.comWILDCARDBounty eligible: Yes
*.tospotify.comWILDCARDBounty eligible: Yes
assets.spotify.comURLBounty eligible: Yes
api.spotify.comURLBounty eligible: Yes
https://www.whosampled.com/URLBounty eligible: Yes
backstage.ioURLBounty eligible: Yes
Spotify SDKsSOURCE_CODEBounty eligible: Yes
iOS SDKSOURCE_CODEBounty eligible: Yes
Android SDKSOURCE_CODEBounty eligible: Yes
Web Playback SDKSOURCE_CODEBounty eligible: Yes
Core Backstage source codeSOURCE_CODEBounty eligible: Yes
https://github.com/backstage/backstageSOURCE_CODEBounty eligible: Yes
Other Spotify websitesOTHERBounty eligible: Yes
AnchorOTHERBounty eligible: Yes
MegaphoneOTHERBounty eligible: Yes
PodsightsOTHERBounty eligible: Yes
SonanticOTHERBounty eligible: Yes
Core AssetsOTHERBounty eligible: Yes
Non-Core AssetsOTHERBounty eligible: Yes
GHEOTHERBounty eligible: Yes
JiraOTHERBounty eligible: Yes
OktaOTHERBounty eligible: Yes
VPNOTHERBounty eligible: Yes
WrappedOTHERBounty eligible: Yes
DRM (Digital Rights Management) SystemOTHERBounty eligible: Yes
com.spotify.tv.androidGOOGLE_PLAY_APP_IDBounty eligible: Yes
com.spotify.s4aGOOGLE_PLAY_APP_IDBounty eligible: Yes
com.spotify.musicGOOGLE_PLAY_APP_IDBounty eligible: Yes
com.spotify.kidsGOOGLE_PLAY_APP_IDBounty eligible: Yes
fm.anchor.androidGOOGLE_PLAY_APP_IDBounty eligible: Yes
Spotify desktop application (Windows and Mac)DOWNLOADABLE_EXECUTABLESBounty eligible: Yes
Save to Spotify CLIDOWNLOADABLE_EXECUTABLESBounty eligible: Yes
com.spotify.clientAPPLE_STORE_APP_IDBounty eligible: Yes
com.spotify.s4aAPPLE_STORE_APP_IDBounty eligible: Yes
com.spotify.kidsAPPLE_STORE_APP_IDBounty eligible: Yes
com.anchorfminc.AnchorAPPLE_STORE_APP_IDBounty eligible: Yes
api-partner.spotify.comAPIBounty eligible: Yes
Out of scope · 9 published rows
AssetTypeGroup / eligibility
example.comURLBounty eligible: No
everynoise.comURLBounty eligible: No
PreactOTHERBounty eligible: No
SoundtrapOTHERBounty eligible: No
The RingerOTHERBounty eligible: No
FindawayOTHERBounty eligible: No
Confidence DomainsOTHERBounty eligible: No
com.soundtrap.studioappGOOGLE_PLAY_APP_IDBounty eligible: No
com.soundtrap.studioappAPPLE_STORE_APP_IDBounty eligible: No

Capture limits

  • Only the published asset table was captured; program rules and eligibility still require individual review.

Live policy and platform eligibility still require review.

Sources and collection identity

  1. Official program page Primary source · reviewed 2026-10-03
  2. Published scope source Primary source · reviewed 2026-10-03

Appears in Discovery, Bounty. No identity match is inferred from a shared company name.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software