Policy and restrictions
Selected identity, device and access-management products are covered. Okta Classic and Okta Personal are marked out of scope. No automated scanners, denial-of-service, customer-instance access, customer-data effects, social engineering or post-compromise pivoting. Reports need meaningful human analysis. Disclosure needs written approval.
Eligibility and submission status
A Bugcrowd account and designated researcher environments are required. Employees and relatives are excluded. Platform reward eligibility includes first valid reporting and applicable adulthood requirements. Supplemental terms impose legal and sanctions eligibility.
The official brief displays In progress, an ongoing period and a Submit report link. This does not establish any particular researcher’s eligibility.
Advertised rewards
Ordinary product/severity schedules advertise $100–$75,000, with discretionary awards. A displayed October 7, 2025 notice advertises a limited-time bonus up to $500,000; its current applicability was not established and is excluded from the ordinary maximum. No individual award is claimed.
Advertised schedules and exceptional ceilings are not individual award evidence.
Published scope snapshot
Captured 2026-10-03. Check the current policy for changes before participating.
| Asset | Type | Group / eligibility |
|---|---|---|
bugcrowd-pam-###.oktapreview.com | website | Okta Privileged Access |
bugcrowd-pam-###.pam.oktapreview.com | website | Okta Privileged Access |
https://bugcrowd-pam-###.workflows.oktapreview.com | website | Okta Workflows |
Desktop MFA for Windows | other | Okta Device Access |
Desktop MFA for macOS | other | Okta Device Access |
Password Sync for macOS | other | Okta Device Access |
support.okta.comPublished location: https://support.okta.com | website | Okta Support Portal (support.okta.com) |
https://bugcrowd-pam-###.at.oktapreview.com | website | AtSpoke (Okta Access Requests) (New) |
https://bugcrowd-pam-###.oktapreview.com | website | Okta (OIE) In-Scope Targets (New) |
Okta Verify FastpassPublished location: https://www.okta.com/fastpass/ | other | Okta (OIE) In-Scope Targets (New) |
https://bugcrowd-pam-###-admin.oktapreview.com | website | Okta (OIE) In-Scope Targets (New) |
Advanced Server Access (ASA) / (ScaleFT)Published location: https://www.okta.com/products/advanced-server-access/ | website | Advanced Server Access |
http://app.scaleft.com/ | website | Advanced Server Access |
Advanced Server Access Client / AgentsPublished location: https://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htm | other | Advanced Server Access |
Okta Verify (iOS)Published location: https://apps.apple.com/us/app/okta-verify/id490179405 | ios | Other In-Scope Targets |
Okta Verify (Android)Published location: https://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=US | android | Other In-Scope Targets |
Okta Verify (Mac OS)Published location: https://apps.apple.com/us/app/okta-verify/id490179405 | other | Other In-Scope Targets |
Okta Verify (Windows) | other | Other In-Scope Targets |
Okta On-Prem Agents ( AD, LDAP, RDP, IWA ) | other | Other In-Scope Targets |
Okta Agent WindowsPublished location: https://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htm | other | Other In-Scope Targets |
Okta Browser Plugin (IE / Firefox / Chrome)Published location: https://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htm | other | Other In-Scope Targets |
| Asset | Type | Group / eligibility |
|---|---|---|
personal.trexcloud.com | website | Okta Personal |
bugcrowd-%username%-1.oktapreview.com | website | Okta (Classic) In-Scope Targets |
bugcrowd-%username%-2.oktapreview.com | website | Okta (Classic) In-Scope Targets |
*.okta.com | website | Out of Scope Targets |
*.trexcloud.com | website | Out of Scope Targets |
login.okta.com | website | Out of Scope Targets |
pages.okta.com | website | Out of Scope Targets |
developer.okta.com | website | Out of Scope Targets |
trust.okta.com | website | Out of Scope Targets |
www.okta.com (static site) | website | Out of Scope Targets |
https://scaleft.com | website | Out of Scope Targets |
https://app.scaleft.com/p/signup | website | Out of Scope Targets |
https://github.com/oktadev | website | Out of Scope Targets |
Backend Okta non-app infrastructure | other | Out of Scope Targets |
Network layer issues | other | Out of Scope Targets |
AtSpoke - Okta Workflows actions in access requests | website | Out of Scope Targets |
AtSpoke - Entitlement bundles as a resource in access requests | website | Out of Scope Targets |
Anything not explicitly called out above as in-scope | other | Out of Scope Targets |
Review limitations
- Brief displays May 22, 2026 as its update date. Older embedded announcements are not proof of current scope or bonus eligibility.
- USD normalization uses Bugcrowd accounting documentation; the brief itself displays dollar signs.
- The linked primary Vulnerability Disclosure Policy PDF could not be retrieved by the text tool. Supplemental terms were read and display July 22, 2019. Review is not a complete legal-terms audit.
- No authenticated submission was attempted. Product-specific setup details and asset inventories are deliberately omitted; live terms prevail.
- Linked announcement and change-log archives were not separately read; announcement facts above come from notices displayed within the reviewed brief.
Sources and provenance
- Okta public program brief Okta / Bugcrowd · reviewed 2026-10-02
- Bugcrowd Organization Accounting Bugcrowd · reviewed 2026-10-02
- Bugcrowd Standard Disclosure Terms Bugcrowd · reviewed 2026-10-02
- Okta Vulnerability Disclosure Policy Supplemental Terms Okta · reviewed 2026-10-02
- Published Bugcrowd scope groups Okta · reviewed 2026-10-03
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.