okta

BugcrowdView on Bugcrowd
RawAI Enhanced
22
In Scope
17
Out of Scope
In-Scope Assets (22)
AssetCategoryBountyQuick Links
Desktop MFA for WindowsOTHERYes-
Desktop MFA for macOSOTHERYes-
Okta On-Prem Agents ( AD, LDAP, RDP, IWA )OTHERYes-
Okta Verify (Windows)OTHERYes-
Password Sync for macOSOTHERYes-
bugcrowd-pam-###.oktapreview.comURLYes
bugcrowd-pam-###.pam.oktapreview.comURLYes
http://app.scaleft.com/URLYes
https://apps.apple.com/us/app/okta-verify/id490179405IOSYes-
https://apps.apple.com/us/app/okta-verify/id490179405OTHERYes-
https://bugcrowd-pam-###-admin.oktapreview.comURLYes
https://bugcrowd-pam-###.at.oktapreview.comURLYes
https://bugcrowd-pam-###.oktapreview.comURLYes
https://bugcrowd-pam-###.workflows.oktapreview.comURLYes
https://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htmOTHERYes-
https://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htmOTHERYes-
https://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htmOTHERYes-
https://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=USANDROIDYes
https://support.okta.comURLYes
https://www.okta.com/fastpass/OTHERYes-
https://www.okta.com/products/advanced-server-access/URLYes
personal.trexcloud.comURLYes
Out-of-Scope Assets (17)
AssetCategoryBounty
*.okta.comURLYes
*.trexcloud.comURLYes
Anything not explicitly called out above as in-scopeOTHERYes
AtSpoke - Entitlement bundles as a resource in access requestsURLYes
AtSpoke - Okta Workflows actions in access requestsURLYes
Backend Okta non-app infrastructureOTHERYes
Network layer issuesOTHERYes
bugcrowd-%username%-1.oktapreview.comURLYes
bugcrowd-%username%-2.oktapreview.comURLYes
developer.okta.comURLYes
https://app.scaleft.com/p/signupURLYes
https://github.com/oktadevURLYes
https://scaleft.comURLYes
login.okta.comURLYes
pages.okta.comURLYes
trust.okta.comURLYes
www.okta.com (static site)URLYes
Scope Changes (196)
Mar 5, 2026
ChangeAssetCategoryScopeTime
Addedhttps://scaleft.comURLOut of Scope22:25
Addedanything not explicitly called out above as in-scopeOTHEROut of Scope22:25
Addednetwork layer issuesOTHEROut of Scope22:25
Addedanything not explicitly called out above as in-scopeOTHEROut of Scope22:25
Addedpersonal.trexcloud.comURLIn Scope22:25
Addedhttps://bugcrowd-pam-#%23%23.at.oktapreview.comURLIn Scope22:25
Addedhttps://bugcrowd-pam-#%23%23.oktapreview.comURLIn Scope22:25
Addedhttps://www.okta.com/products/advanced-server-accessURLIn Scope22:25
Addedhttps://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htmOTHERIn Scope22:25
Addedhttps://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htmOTHERIn Scope22:25
Addedhttps://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htmOTHERIn Scope22:25
Addedhttps://github.com/oktadevURLOut of Scope22:25
Addeddesktop mfa for windowsOTHERIn Scope22:25
Addedhttps://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=USANDROIDIn Scope22:25
Addedbugcrowd-%username%-1.oktapreview.comURLOut of Scope22:25
Addedtrust.okta.comURLOut of Scope22:25
Addedatspoke - okta workflows actions in access requestsURLOut of Scope22:25
Addedatspoke - entitlement bundles as a resource in access requestsURLOut of Scope22:25
Addedhttps://bugcrowd-pam-#%23%23.workflows.oktapreview.comURLIn Scope22:25
Addedpassword sync for macosOTHERIn Scope22:25
Addedhttps://apps.apple.com/us/app/okta-verify/id490179405IOSIn Scope22:25
Addedbugcrowd-%username%-2.oktapreview.comURLOut of Scope22:25
Added*.okta.comWILDCARDOut of Scope22:25
Addedbackend okta non-app infrastructureOTHEROut of Scope22:25
Addedbugcrowd-pam-###.oktapreview.comURLIn Scope22:25
Addeddesktop mfa for macosOTHERIn Scope22:25
Addedhttps://bugcrowd-pam-#%23%23-admin.oktapreview.comURLIn Scope22:25
Added*.trexcloud.comWILDCARDOut of Scope22:25
Addedbugcrowd-pam-###.pam.oktapreview.comURLIn Scope22:25
Addedhttps://support.okta.comURLIn Scope22:25
Addedhttps://www.okta.com/fastpassURLIn Scope22:25
Addedhttps://apps.apple.com/us/app/okta-verify/id490179405IOSIn Scope22:25
Addeddeveloper.okta.comURLOut of Scope22:25
Addedokta on-prem agents ( ad, ldap, rdp, iwa )OTHERIn Scope22:25
Addedpages.okta.comURLOut of Scope22:25
Addedwww.okta.com (static site)URLOut of Scope22:25
Addedhttp://app.scaleft.com/URLIn Scope22:25
Addedhttps://app.scaleft.com/p/signupURLOut of Scope22:25
Addedokta verify (windows)OTHERIn Scope22:25
Addedlogin.okta.comURLOut of Scope22:25
Addedpersonal.trexcloud.comURLIn Scope22:25
Addedbugcrowd-pam-###.oktapreview.comURLIn Scope22:25
Addedbugcrowd-pam-###.pam.oktapreview.comURLIn Scope22:25
Addedhttps://bugcrowd-pam-#%23%23.workflows.oktapreview.comURLIn Scope22:25
Addeddesktop mfa for windowsOTHERIn Scope22:25
Addeddesktop mfa for macosOTHERIn Scope22:25
Addedpassword sync for macosOTHERIn Scope22:25
Addedhttps://support.okta.comURLIn Scope22:25
Addedhttps://bugcrowd-pam-#%23%23.at.oktapreview.comURLIn Scope22:25
Addedhttps://bugcrowd-pam-#%23%23.oktapreview.comURLIn Scope22:25
Addedhttps://www.okta.com/fastpassOTHERIn Scope22:25
Addedhttps://bugcrowd-pam-#%23%23-admin.oktapreview.comURLIn Scope22:25
Addedhttps://www.okta.com/products/advanced-server-accessURLIn Scope22:25
Addedhttp://app.scaleft.com/URLIn Scope22:25
Addedhttps://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htmOTHERIn Scope22:25
Addedhttps://apps.apple.com/us/app/okta-verify/id490179405IOSIn Scope22:25
Addedhttps://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=USANDROIDIn Scope22:25
Addedhttps://apps.apple.com/us/app/okta-verify/id490179405OTHERIn Scope22:25
Addedokta verify (windows)OTHERIn Scope22:25
Addedokta on-prem agents ( ad, ldap, rdp, iwa )OTHERIn Scope22:25
Addedhttps://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htmOTHERIn Scope22:25
Addedhttps://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htmOTHERIn Scope22:25
Addedbugcrowd-%username%-1.oktapreview.comURLOut of Scope22:25
Addedbugcrowd-%username%-2.oktapreview.comURLOut of Scope22:25
Added*.okta.comURLOut of Scope22:25
Added*.trexcloud.comURLOut of Scope22:25
Addedlogin.okta.comURLOut of Scope22:25
Addedpages.okta.comURLOut of Scope22:25
Addeddeveloper.okta.comURLOut of Scope22:25
Addedtrust.okta.comURLOut of Scope22:25
Addedwww.okta.com (static site)URLOut of Scope22:25
Addedhttps://scaleft.comURLOut of Scope22:25
Addedhttps://app.scaleft.com/p/signupURLOut of Scope22:25
Addedhttps://github.com/oktadevURLOut of Scope22:25
Addedbackend okta non-app infrastructureOTHEROut of Scope22:25
Addednetwork layer issuesOTHEROut of Scope22:25
Addedatspoke - okta workflows actions in access requestsURLOut of Scope22:25
Addedatspoke - entitlement bundles as a resource in access requestsURLOut of Scope22:25
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedatspoke - okta workflows actions in access requestsURLOut of Scope19:08
Addedbugcrowd-pam-###.pam.oktapreview.comURLIn Scope19:08
Addeddesktop mfa for windowsOTHERIn Scope19:08
Addedhttps://bugcrowd-pam-#%23%23.at.oktapreview.comURLIn Scope19:08
Addedhttps://apps.apple.com/us/app/okta-verify/id490179405IOSIn Scope19:08
Addedhttps://apps.apple.com/us/app/okta-verify/id490179405IOSIn Scope19:08
Addedbugcrowd-%username%-2.oktapreview.comURLOut of Scope19:08
Addedhttps://scaleft.comURLOut of Scope19:08
Addedpersonal.trexcloud.comURLIn Scope19:08
Addedhttps://bugcrowd-pam-#%23%23.workflows.oktapreview.comURLIn Scope19:08
Addedhttps://support.okta.comURLIn Scope19:08
Addedhttps://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=USANDROIDIn Scope19:08
Addedlogin.okta.comURLOut of Scope19:08
Addedhttps://app.scaleft.com/p/signupURLOut of Scope19:08
Addednetwork layer issuesOTHEROut of Scope19:08
Addedpassword sync for macosOTHERIn Scope19:08
Addedhttp://app.scaleft.com/URLIn Scope19:08
Added*.okta.comWILDCARDOut of Scope19:08
Addedpages.okta.comURLOut of Scope19:08
Addedatspoke - entitlement bundles as a resource in access requestsURLOut of Scope19:08
Addedhttps://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htmOTHERIn Scope19:08
Addedokta on-prem agents ( ad, ldap, rdp, iwa )OTHERIn Scope19:08
Addedanything not explicitly called out above as in-scopeOTHEROut of Scope19:08
Addedhttps://bugcrowd-pam-#%23%23-admin.oktapreview.comURLIn Scope19:08
Added*.trexcloud.comWILDCARDOut of Scope19:08
Addedtrust.okta.comURLOut of Scope19:08
Addedhttps://bugcrowd-pam-#%23%23.oktapreview.comURLIn Scope19:08
Addedhttps://www.okta.com/products/advanced-server-accessURLIn Scope19:08
Addedhttps://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htmOTHERIn Scope19:08
Addedhttps://github.com/oktadevURLOut of Scope19:08
Addedbackend okta non-app infrastructureOTHEROut of Scope19:08
Addeddesktop mfa for macosOTHERIn Scope19:08
Addedhttps://www.okta.com/fastpassURLIn Scope19:08
Addedokta verify (windows)OTHERIn Scope19:08
Addedhttps://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htmOTHERIn Scope19:08
Addedbugcrowd-%username%-1.oktapreview.comURLOut of Scope19:08
Addeddeveloper.okta.comURLOut of Scope19:08
Addedwww.okta.com (static site)URLOut of Scope19:08
Addedbugcrowd-pam-###.oktapreview.comURLIn Scope19:08
Program Removed17:22
Addedpersonal.trexcloud.comURLIn Scope16:58
Addedbugcrowd-pam-###.oktapreview.comURLIn Scope16:58
Addedbugcrowd-pam-###.pam.oktapreview.comURLIn Scope16:58
Addedhttps://bugcrowd-pam-#%23%23.workflows.oktapreview.comURLIn Scope16:58
Addeddesktop mfa for windowsOTHERIn Scope16:58
Addedpassword sync for macosOTHERIn Scope16:58
Addedhttps://support.okta.comURLIn Scope16:58
Addedhttps://bugcrowd-pam-#%23%23.at.oktapreview.comURLIn Scope16:58
Addedhttps://bugcrowd-pam-#%23%23.oktapreview.comURLIn Scope16:58
Addedhttps://www.okta.com/fastpassOTHERIn Scope16:58
Addedhttps://bugcrowd-pam-#%23%23-admin.oktapreview.comURLIn Scope16:58
Addedhttps://www.okta.com/products/advanced-server-accessURLIn Scope16:58
Addedhttp://app.scaleft.com/URLIn Scope16:58
Addedhttps://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htmOTHERIn Scope16:58
Addedhttps://apps.apple.com/us/app/okta-verify/id490179405IOSIn Scope16:58
Addedhttps://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=USANDROIDIn Scope16:58
Addedhttps://apps.apple.com/us/app/okta-verify/id490179405OTHERIn Scope16:58
Addedokta verify (windows)OTHERIn Scope16:58
Addedokta on-prem agents ( ad, ldap, rdp, iwa )OTHERIn Scope16:58
Addedhttps://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htmOTHERIn Scope16:58
Addedhttps://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htmOTHERIn Scope16:58
Addedbugcrowd-%username%-1.oktapreview.comURLOut of Scope16:58
Addedbugcrowd-%username%-2.oktapreview.comURLOut of Scope16:58
Added*.okta.comURLOut of Scope16:58
Added*.trexcloud.comURLOut of Scope16:58
Addedlogin.okta.comURLOut of Scope16:58
Addedpages.okta.comURLOut of Scope16:58
Addeddeveloper.okta.comURLOut of Scope16:58
Addedtrust.okta.comURLOut of Scope16:58
Addedwww.okta.com (static site)URLOut of Scope16:58
Addedhttps://scaleft.comURLOut of Scope16:58
Addedhttps://app.scaleft.com/p/signupURLOut of Scope16:58
Addedhttps://github.com/oktadevURLOut of Scope16:58
Addedbackend okta non-app infrastructureOTHEROut of Scope16:58
Addednetwork layer issuesOTHEROut of Scope16:58
Addedatspoke - okta workflows actions in access requestsURLOut of Scope16:58
Addedatspoke - entitlement bundles as a resource in access requestsURLOut of Scope16:58
Addedanything not explicitly called out above as in-scopeOTHEROut of Scope16:58
Addedbackend okta non-app infrastructureOTHEROut of Scope16:58
Addedatspoke - entitlement bundles as a resource in access requestsOTHEROut of Scope16:58
Addedpersonal.trexcloud.comURLIn Scope16:58
Addedbugcrowd-pam-###.pam.oktapreview.comURLIn Scope16:58
Addeddesktop mfa for macosOTHERIn Scope16:58
Addedhttps://www.okta.com/fastpassURLIn Scope16:58
Addedokta on-prem agents ( ad, ldap, rdp, iwa )OTHERIn Scope16:58
Addedbugcrowd-%username%-2.oktapreview.comURLOut of Scope16:58
Addedtrust.okta.comURLOut of Scope16:58
Addedpassword sync for macosOTHERIn Scope16:58
Addedhttps://bugcrowd-pam-#%23%23-admin.oktapreview.comURLIn Scope16:58
Addedhttps://www.okta.com/products/advanced-server-accessURLIn Scope16:58
Addedokta verify (windows)OTHERIn Scope16:58
Addedpages.okta.comURLOut of Scope16:58
Addedbugcrowd-pam-###.oktapreview.comURLIn Scope16:58
Addeddesktop mfa for windowsOTHERIn Scope16:58
Addedhttps://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=USANDROIDIn Scope16:58
Addedhttps://apps.apple.com/us/app/okta-verify/id490179405IOSIn Scope16:58
Addedhttps://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htmURLIn Scope16:58
Addedhttps://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htmURLIn Scope16:58
Addedbugcrowd-%username%-1.oktapreview.comURLOut of Scope16:58
Addedlogin.okta.comURLOut of Scope16:58
Addedhttps://bugcrowd-pam-#%23%23.at.oktapreview.comURLIn Scope16:58
Addedhttp://app.scaleft.com/URLIn Scope16:58
Added*.okta.comWILDCARDOut of Scope16:58
Added*.trexcloud.comWILDCARDOut of Scope16:58
Addedhttps://scaleft.comURLOut of Scope16:58
Addednetwork layer issuesOTHEROut of Scope16:58
Addedatspoke - okta workflows actions in access requestsOTHEROut of Scope16:58
Addedanything not explicitly called out above as in-scopeOTHEROut of Scope16:58
Addedhttps://bugcrowd-pam-#%23%23.workflows.oktapreview.comURLIn Scope16:58
Addedhttps://support.okta.comURLIn Scope16:58
Addedhttps://bugcrowd-pam-#%23%23.oktapreview.comURLIn Scope16:58
Addedhttps://apps.apple.com/us/app/okta-verify/id490179405IOSIn Scope16:58
Addedwww.okta.com (static site)URLOut of Scope16:58
Addedhttps://app.scaleft.com/p/signupURLOut of Scope16:58
Addeddeveloper.okta.comURLOut of Scope16:58
Addedhttps://github.com/oktadevURLOut of Scope16:58
Addedhttps://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htmURLIn Scope16:58
Addeddesktop mfa for macosOTHERIn Scope16:58