spotify

HackerOneView on HackerOne
RawAI Enhanced
43
In Scope
8
Out of Scope

In-Scope Assets (43)

AssetCategoryBountyQuick Links
*.atspotify.comWILDCARDYes
*.avecspotify.comWILDCARDYes
*.byspotify.comWILDCARDYes
*.enspotify.comWILDCARDYes
*.forspotify.comWILDCARDYes
*.fromspotify.comWILDCARDYes
*.spotify.comWILDCARDYes
*.spotify.netWILDCARDYes
*.tospotify.comWILDCARDYes
*.withspotify.comWILDCARDYes
AnchorOTHERYes-
Android SDKCODEYes-
Core AssetsOTHERYes-
Core Backstage source codeCODEYes-
GHEOTHERYes-
JiraOTHERYes-
MegaphoneOTHERYes-
Non-Core AssetsOTHERYes-
OktaOTHERYes-
Other Spotify websitesOTHERYes-
PodsightsOTHERYes-
SonanticOTHERYes-
Spotify SDKsCODEYes-
Spotify desktop application (Windows and Mac)BINARYYes-
VPNOTHERYes-
Web Playback SDKCODEYes-
WrappedOTHERYes-
api-partner.spotify.comURLYes
api.spotify.comURLYes
assets.spotify.comURLYes
backstage.ioURLYes
com.anchorfminc.AnchorIOSYes-
com.spotify.clientIOSYes-
com.spotify.kidsANDROIDYes
com.spotify.kidsIOSYes-
com.spotify.musicANDROIDYes
com.spotify.s4aIOSYes-
com.spotify.s4aANDROIDYes
com.spotify.tv.androidANDROIDYes
fm.anchor.androidANDROIDYes
https://github.com/backstage/backstageCODEYes-
https://www.whosampled.com/URLYes
iOS SDKCODEYes-
Out-of-Scope Assets (8)
AssetCategoryBounty
FindawayOTHERNo
PreactOTHERNo
SoundtrapOTHERNo
The RingerOTHERNo
com.soundtrap.studioappANDROIDNo
com.soundtrap.studioappIOSNo
everynoise.comURLNo
example.comURLNo