Policy and restrictions
Ordinary research is restricted to owned accounts. Privacy violations, destruction, disruption and unauthorized disclosure are prohibited; automation is limited. Local-root scenarios, accepted design limitations and unsupported-impact reports are excluded.
Eligibility and submission status
First valid reports receive precedence; related findings may share one bounty. Payment restrictions include sanctions/employer eligibility and guardian handling for minors.
Official support describes a public ongoing program and confirms the December 2024 migration from Bugcrowd to HackerOne.
Advertised rewards
Standard advertised tiers span $50–$30,000. The exceptional USD 1,000,000 ceiling applies only to the designated cryptographic challenge’s complete required proof; partial/theoretical claims do not qualify. That challenge now belongs to this same program, without separate invitation.
Advertised schedules and exceptional ceilings are not individual award evidence.
Published scope snapshot
Captured 2026-10-03. Check the current policy for changes before participating.
| Asset | Type | Group / eligibility |
|---|---|---|
http://--your-own-1password-account--.1password.com | URL | Bounty eligible: Yes |
<Your own 1Password account> —> Latest stable, beta, or nightly Command Line Interface (CLI) | OTHER | Bounty eligible: Yes |
<Your own 1Password account> —> Latest stable, beta, or nightly Browser Extension (Chrome, Brave, Firefox, Edge, and Safari) | OTHER | Bounty eligible: Yes |
https://events.1password.com/api/ | API | Bounty eligible: Yes |
| Asset | Type | Group / eligibility |
|---|---|---|
*.agilebits.com | WILDCARD | Bounty eligible: No |
https://support.1password.com | URL | Bounty eligible: No |
https://www.1password.com/ | URL | Bounty eligible: No |
All other domains, subdomains, and 1Password Accounts that are not owned by you, including accounts where you are a user but not the owner, are out of scope. | OTHER | Bounty eligible: No |
Review limitations
- Current policy and restrictions were read in the browser; static retrieval returned a JavaScript shell.
- The normalized maximum is the exceptional challenge ceiling, not the ordinary reward cap. Normalized minimum is null to avoid conflating schedules.
- The scope page has stricter ownership language than general permission wording; this summary preserves the stricter restriction.
- Policy displayed September 25, 2026 update. Older separate-program challenge descriptions are superseded by current policy.
Sources and provenance
- 1Password bounty policy 1Password / HackerOne · reviewed 2026-10-02
- 1Password program restrictions 1Password / HackerOne · reviewed 2026-10-02
- 1Password security assessments 1Password · reviewed 2026-10-02
- HackerOne vulnerability disclosure guidelines HackerOne · reviewed 2026-10-02
- Published HackerOne structured scope 1Password · reviewed 2026-10-03
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.