vulns.co
/
GKData.io MCP

Okta · 4 min read

Okta Bug Bounty

Okta · Bugcrowd. Policy reviewed 2026-10-02. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Selected identity, device and access-management products are covered. Okta Classic and Okta Personal are marked out of scope. No automated scanners, denial-of-service, customer-instance access, customer-data effects, social engineering or post-compromise pivoting. Reports need meaningful human analysis. Disclosure needs written approval.

Eligibility and submission status

A Bugcrowd account and designated researcher environments are required. Employees and relatives are excluded. Platform reward eligibility includes first valid reporting and applicable adulthood requirements. Supplemental terms impose legal and sanctions eligibility.

The official brief displays In progress, an ongoing period and a Submit report link. This does not establish any particular researcher’s eligibility.

Advertised rewards

Ordinary product/severity schedules advertise $100–$75,000, with discretionary awards. A displayed October 7, 2025 notice advertises a limited-time bonus up to $500,000; its current applicability was not established and is excluded from the ordinary maximum. No individual award is claimed.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 21 published rows
AssetTypeGroup / eligibility
bugcrowd-pam-###.oktapreview.comwebsiteOkta Privileged Access
bugcrowd-pam-###.pam.oktapreview.comwebsiteOkta Privileged Access
https://bugcrowd-pam-###.workflows.oktapreview.comwebsiteOkta Workflows
Desktop MFA for WindowsotherOkta Device Access
Desktop MFA for macOSotherOkta Device Access
Password Sync for macOSotherOkta Device Access
support.okta.comPublished location: https://support.okta.comwebsiteOkta Support Portal (support.okta.com)
https://bugcrowd-pam-###.at.oktapreview.comwebsiteAtSpoke (Okta Access Requests) (New)
https://bugcrowd-pam-###.oktapreview.comwebsiteOkta (OIE) In-Scope Targets (New)
Okta Verify FastpassPublished location: https://www.okta.com/fastpass/otherOkta (OIE) In-Scope Targets (New)
https://bugcrowd-pam-###-admin.oktapreview.comwebsiteOkta (OIE) In-Scope Targets (New)
Advanced Server Access (ASA) / (ScaleFT)Published location: https://www.okta.com/products/advanced-server-access/websiteAdvanced Server Access
http://app.scaleft.com/websiteAdvanced Server Access
Advanced Server Access Client / AgentsPublished location: https://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htmotherAdvanced Server Access
Okta Verify (iOS)Published location: https://apps.apple.com/us/app/okta-verify/id490179405iosOther In-Scope Targets
Okta Verify (Android)Published location: https://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=USandroidOther In-Scope Targets
Okta Verify (Mac OS)Published location: https://apps.apple.com/us/app/okta-verify/id490179405otherOther In-Scope Targets
Okta Verify (Windows)otherOther In-Scope Targets
Okta On-Prem Agents ( AD, LDAP, RDP, IWA )otherOther In-Scope Targets
Okta Agent WindowsPublished location: https://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htmotherOther In-Scope Targets
Okta Browser Plugin (IE / Firefox / Chrome)Published location: https://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htmotherOther In-Scope Targets
Out of scope · 18 published rows
AssetTypeGroup / eligibility
personal.trexcloud.comwebsiteOkta Personal
bugcrowd-%username%-1.oktapreview.comwebsiteOkta (Classic) In-Scope Targets
bugcrowd-%username%-2.oktapreview.comwebsiteOkta (Classic) In-Scope Targets
*.okta.comwebsiteOut of Scope Targets
*.trexcloud.comwebsiteOut of Scope Targets
login.okta.comwebsiteOut of Scope Targets
pages.okta.comwebsiteOut of Scope Targets
developer.okta.comwebsiteOut of Scope Targets
trust.okta.comwebsiteOut of Scope Targets
www.okta.com (static site)websiteOut of Scope Targets
https://scaleft.comwebsiteOut of Scope Targets
https://app.scaleft.com/p/signupwebsiteOut of Scope Targets
https://github.com/oktadevwebsiteOut of Scope Targets
Backend Okta non-app infrastructureotherOut of Scope Targets
Network layer issuesotherOut of Scope Targets
AtSpoke - Okta Workflows actions in access requestswebsiteOut of Scope Targets
AtSpoke - Entitlement bundles as a resource in access requestswebsiteOut of Scope Targets
Anything not explicitly called out above as in-scopeotherOut of Scope Targets

Review limitations

  • Brief displays May 22, 2026 as its update date. Older embedded announcements are not proof of current scope or bonus eligibility.
  • USD normalization uses Bugcrowd accounting documentation; the brief itself displays dollar signs.
  • The linked primary Vulnerability Disclosure Policy PDF could not be retrieved by the text tool. Supplemental terms were read and display July 22, 2019. Review is not a complete legal-terms audit.
  • No authenticated submission was attempted. Product-specific setup details and asset inventories are deliberately omitted; live terms prevail.
  • Linked announcement and change-log archives were not separately read; announcement facts above come from notices displayed within the reviewed brief.

Sources and provenance

  1. Okta public program brief Okta / Bugcrowd · reviewed 2026-10-02
  2. Bugcrowd Organization Accounting Bugcrowd · reviewed 2026-10-02
  3. Bugcrowd Standard Disclosure Terms Bugcrowd · reviewed 2026-10-02
  4. Okta Vulnerability Disclosure Policy Supplemental Terms Okta · reviewed 2026-10-02
  5. Published Bugcrowd scope groups Okta · reviewed 2026-10-03

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software