{"id":"4fd154ee-8a7d-4d42-bab8-2ff1e017c1b2","engagementId":"fda2752f-4388-43e2-b7ca-c4abcb21b1aa","data":{"brief":{"id":"71a7d9c8-7cfb-432d-9b12-b1a509e918fd","name":"Rapyd","tagline":"We provide APIs that help integrate local payments and Fintech capabilities.","description":"\u003ch1\u003eNEW PROMOTION — Rapyd Client Portal: SAML 2.0\u003c/h1\u003e\n\n\u003cp\u003e⏰ May 20, 2026 — June 30, 2026\u003cbr\u003e\n💰 Bonus rewards on top of standard payouts:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eHigh severity: +$400\u003c/li\u003e\n\u003cli\u003eCritical severity: +$900\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e👕 Top contributors will also receive exclusive Rapyd swag\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eRapyd just shipped SAML 2.0 support in the \u003ca href=\"http://dashboard.rapyd.net/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eRapyd Client Portal\u003c/a\u003e and we want fresh eyes on it. From May 20th through the end of June we're running a promotion with bonus rewards for valid High and Critical findings in this area. If SAML is your thing, now's a good time to dig in.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e🔍 ABOUT THE FEATURE\u003c/h2\u003e\n\n\u003cp\u003eMerchants can now configure their own Identity Provider to authenticate users into Rapyd Client Portal  via SAML 2.0.\u003c/p\u003e\n\n\u003cp\u003eSP details:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eACS URL:https://dashboard.rapyd.net/v1/merchants-portal/users/login/sso/callback\u003c/li\u003e\n\u003cli\u003eEntity ID: rapyd_merchants_portal\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e🎯 WHAT TO TEST\u003c/h2\u003e\n\n\u003col\u003e\n\u003cli\u003eAssertion Replay\n\n\u003cul\u003e\n\u003cli\u003eTest whether the SP enforces single-use on assertions — a previously captured SAMLResponse should not be replayable to authenticate again.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSignature Wrapping (XSW)\n\n\u003cul\u003e\n\u003cli\u003eBoth the Response and Assertion are independently signed. Test whether injecting a malicious unsigned assertion alongside the valid signed one can bypass validation.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eInResponseTo Enforcement\n\n\u003cul\u003e\n\u003cli\u003eThe SP issues an AuthnRequest with a unique ID that must match the InResponseTo field in the SAMLResponse. Test whether responses with a missing, modified, or reused InResponseTo value are rejected.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAccount Takeover via NameID / Email Spoofing\n\n\u003cul\u003e\n\u003cli\u003eAuthentication is based on the email value in the NameID field. Test whether an attacker-controlled IdP can spoof another user's email to gain unauthorized access.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eRelayState Open Redirect\n\n\u003cul\u003e\n\u003cli\u003eThe RelayState parameter is used to redirect the user after login. Test whether it can be manipulated to redirect to an arbitrary external URL.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eXXE Injection via SAML Payload\n\n\u003cul\u003e\n\u003cli\u003eThe SAML assertion is not encrypted and is parsed as XML by the SP. Test whether malicious XML entities in the SAMLResponse trigger server-side processing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ePrivilege Escalation via Attribute Manipulation\n\n\u003cul\u003e\n\u003cli\u003eTest whether manipulating SAML attribute statements can elevate a user's permissions within the portal.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eTenant Isolation Bypass\n\n\u003cul\u003e\n\u003cli\u003eTest whether SAML 2.0 login can be used to access another merchant's account or data.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e❌ OUT OF SCOPE\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eDummy or permissive IdPs (e.g. MockSAML or any setup that signs arbitrary assertions without real authentication). The threat model assumes a legitimately configured provider — findings that only work because the IdP accepts everything won't be accepted.\u003c/li\u003e\n\u003cli\u003eAn admin attacking their own SAML 2.0 configuration.\u003c/li\u003e\n\u003cli\u003eWe are aware of the IDOR vulnerability on the idp_id parameter that lead to information disclosure. Please do not submit reports regarding this issue, as it is already known and tracked internally.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e🛠️ SETTING UP YOUR TEST ENVIRONMENT\u003c/h2\u003e\n\n\u003cp\u003eYou'll need a SAML 2.0 Identity Provider. Any of the following will work: Okta, Microsoft Entra ID, Google Workspace.\u003c/p\u003e\n\n\u003cp\u003eIf you want the quickest free option, Okta is the easiest to get running:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eSign up at \u003ca href=\"http://developer.okta.com/signup\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOkta Developer\u003c/a\u003e  — select the Integrator Free Plan, no credit card required\u003c/li\u003e\n\u003cli\u003eGo to Applications \u0026gt; Applications \u0026gt; Create App Integration\u003c/li\u003e\n\u003cli\u003eSelect SAML 2.0 and click Next\u003c/li\u003e\n\u003cli\u003eGive the app any name and click Next\u003c/li\u003e\n\u003cli\u003eSet Single sign-on URL (ACS) to: \u003ca href=\"https://dashboard.rapyd.net/v1/merchants-portal/users/login/sso/callback\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eRapyd Client Portal\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eSet Audience URI (Entity ID) to: rapyd_merchants_portal\u003c/li\u003e\n\u003cli\u003eSet Name ID format to: EmailAddress and Application username to: Email\u003c/li\u003e\n\u003cli\u003eClick Finish, then go to the Sign On tab and copy the IdP SSO URL and Issuer, and download the certificate — Okta saves it as a .cert file, rename it to .crt before uploading as the Rapyd portal does not accept the .cert extension\u003c/li\u003e\n\u003cli\u003eIn the Rapyd Client Portal go to Settings \u0026gt; Team Members \u0026amp; Roles \u0026gt; SSO Configuration\u003c/li\u003e\n\u003cli\u003eClick Enable SSO, paste the IdP SSO URL into the Entry Point field and the Issuer into the Issuer field. If your Issuer URL starts with HTTP, update it to HTTPS. Then upload the renamed certificate file.\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003e📋 SUBMISSION NOTES\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eInclude full reproduction steps with your IdP configuration\u003c/li\u003e\n\u003cli\u003eAttach the raw SAMLRequest and SAMLResponse, base64-decoded\u003c/li\u003e\n\u003cli\u003eOnly test on accounts you own — do not attempt to access other merchants\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eRapyd is focused on helping businesses create great local commerce experiences anywhere. The company develops technology designed to remove the back-end complexities of cross-border commerce while providing local payment expertise. Global eCommerce companies, technology firms, marketplaces, and financial institutions use Rapyds FinTech-as-a-service platforms to seamlessly embed localized FinTech and payment capabilities into their applications. Rapyd is also the developer of the Rapyd Global Payments Network, which enables businesses to access the worlds largest local payment network, with over 900 locally preferred payment methods, including bank transfers, eWallets, and cash in more than 100 countries.\u003cbr\u003e\nWe are looking forward to working with the security community to find vulnerabilities to keep our customers safe. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eMain Guidelines, read closely!\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eEvery request must include the X-Bugcrowd header with Bugcrowd username for e.g: Bugcrowd-\u0026lt;Username\u0026gt;', we created a burp configuration file to include the scope targets \u003cspan class=\"rp-resources__download-link bc-m-0 bc-icon bc-icon--after cc-icon--download\" data-tooltip-id=\"903f7799-ad94-4746-a5f9-1df08635cac6\"\u003e\u003ca href=\"https://bugcrowd.com/engagements/rapyd/attachments/903f7799-ad94-4746-a5f9-1df08635cac6\" download\u003edownload here\u003c/a\u003e\u003c/span\u003e.\u003c/li\u003e\n\u003cli\u003eMust use the Bugcrowd email alias [username]@bugcrowdninja.com to self-sign up to the platform (Dashboard.rapyd.net). \u2028     For more info regarding @bugcrowdninja email addresses \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eread here\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eThe client portal web application (dashboard.rapyd.net) can be tested in two modes, sandbox mode, in which all users are admins, and production mode, in this mode users and permissions can be tested. The production mode is only available to those who sign up and select Iceland as their country. Make sure you are signing up from Iceland to have this option.\u003c/li\u003e\n\u003cli\u003eAutomations against form submissions are not allowed and can lead to a ban from the program.\u003c/li\u003e\n\u003cli\u003eDo not degrade Rapyd's user experience, disrupt production systems, or destroy data during security testing.\u003c/li\u003e\n\u003cli\u003eEvery report must include HTTP request and response.\u003c/li\u003e\n\u003cli\u003e Submissions not within the guidelines will be considered as not eligible.\u003c/li\u003e\n\u003cli\u003e In most of the requests Rapyd provides the operation ID in the response, which is crucial for internal research. In certain cases, you must provide it if requested by the teams.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eAdditional guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen investigating a vulnerability, please only target Only your account and do not attempt to access data from anyone else’s account.\u003c/li\u003e\n\u003cli\u003eStop testing and report the issue immediately if you gain access to any non-public application or non-public credentials.\u003c/li\u003e\n\u003cli\u003eRate limit issues - We enforce a rate limit on our entire Cloud environment (The fact that you can make 50 Requests per minute does not mean that we won't block you if you will try more so just skip this one)\u003c/li\u003e\n\u003cli\u003eDo not access customer or employee personal information, credit card data, and Rapyd confidential information. If you accidentally access any of these, please stop testing and submit the vulnerability.\u003c/li\u003e\n\u003cli\u003eCollect only the information necessary to demonstrate the vulnerability.\u003c/li\u003e\n\u003cli\u003eSubmit any necessary screenshots, screen captures, network requests, reproduction steps, or similar using the Bugcrowd submission form (do not use third-party file-sharing sites).\u003c/li\u003e\n\u003cli\u003eSecurely delete Rapyd information that may have been downloaded, cached, or otherwise stored on the systems used to perform the research.\u003c/li\u003e\n\u003cli\u003eWe may accept reports for out-of-scope vulnerabilities and possibly fix them, but we will not award a bounty regardless.\u003c/li\u003e\n\u003cli\u003ePerform research only within the scope set out below.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOur top submitted vulnerabilities\u003c/h2\u003e\n\n\u003ch4\u003eAt Rapyd we have a long-running bug bounty program, these are our most submitted reports so far:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eSanitization of inputs in various locations - Email template injections\u003c/li\u003e\n\u003cli\u003eRace condition in critical business logic activities - For example, passing multiple refunds\u003c/li\u003e\n\u003cli\u003eBusiness Logic - For example, flows which change wallet balance with an incorrect amount\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eTo encourage responsible disclosure, Rapyd will not bring a lawsuit against you or ask law enforcement to investigate you if we determine that your research and disclosure meet these requirements and guidelines. If you have questions about the responsible disclosure of results for a submission, please reach out to us via the submission page.\u003c/p\u003e\n\n\u003ch2\u003eRewards and Rating Guidelines\u003c/h2\u003e\n\n\u003ch3\u003eRewards for API findings (api.rapyd.net domain)\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe reward for valid critical and high API findings could be increased depending on the impact on Rapyd. \u003c/li\u003e\n\u003cli\u003ePlease only use the sandbox environment for API testing activities.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eRewards for PCI findings\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003ePCI-related findings are vulnerabilities that will result in disclosing credit card data, such as full card number, CVV, etc.\u003c/li\u003e\n\u003cli\u003eThe reward for valid PCI findings could be increased depending on the impact on Rapyd and will have a minimum bonus of ($500), with the severity of the vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eRewards for Privacy findings\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003ePrivacy-related findings are findings that may cause breaches of privacy regulations such as GDPR in the EU or CCPA in the state of California.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut-of-scope vulnerabilities\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eDNS related attacks like: Cache poisoning, DNS flooding, DNS amplification, Fast-flux DNS, Zone Transfer, Missing DNSSEC\u003c/li\u003e\n\u003cli\u003eUDP flood attack \u003c/li\u003e\n\u003cli\u003e Social engineering (e.g. phishing, vishing, smishing) is prohibited.\u003c/li\u003e\n\u003cli\u003eAutomated scanning against any contact/submission form will not be tolerated\u003c/li\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept.\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a vulnerability.\u003c/li\u003e\n\u003cli\u003eMissing best practices in SSL/TLS configuration.\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption of our service (DoS).\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\u003c/li\u003e\n\u003cli\u003eRate limiting or Bruteforce issues on non-authentication endpoints\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy.\u003c/li\u003e\n\u003cli\u003eMissing HttpOnly or Secure flags on cookies\u003c/li\u003e\n\u003cli\u003eMissing email best practices (Invalid, incomplete, or missing SPF/DKIM/DMARC records, etc.)\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors).\u003c/li\u003e\n\u003cli\u003ePublic Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case-by-case basis.\u003c/li\u003e\n\u003cli\u003eTabnabbing\u003c/li\u003e\n\u003cli\u003eOpen redirect - unless an additional security impact can be demonstrated\u003c/li\u003e\n\u003cli\u003eIssues that require unlikely user interaction\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"e5974e05-c84d-4d75-8bd1-b99067b8b8ac","name":"Tier 3 In scope Premium","targets":[{"id":"29554c1e-a4ea-4d01-97d8-2cb655a2bdb9","uri":"","name":"api.rapyd.net","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9390a7fa-ef3b-49c7-81ea-98660a43c5ee","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"29554c1e-a4ea-4d01-97d8-2cb655a2bdb9"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"29554c1e-a4ea-4d01-97d8-2cb655a2bdb9"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"bb718c45-fd80-43cc-8154-f306ad9b7d2c","p1MaxCents":750000,"p1MinCents":500000,"p2MaxCents":450000,"p2MinCents":150000,"p3MaxCents":140000,"p3MinCents":60000,"p4MaxCents":50000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eWe pay the most and want to focus on Rapyd\u0026#39;s API and the core of this program, the reward for valid critical and high API findings could be increased depending on the impact on Rapyd.\u003c/p\u003e\n\n\u003ch2\u003eDocumentation:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWorking with Rapyd, In order to successfully send an API request you need to understand how our signature system is working (or use code samples) GitHub - RapydPayments/rapyd-request-signatures: When you send a request, you calculate the signature and insert the result into the signature header. When the platform receives the request, it performs the same signature calculation. If the resulting values do not match, the request is rejected, \u003ca href=\"https://github.com/RapydPayments/rapyd-request-signatures\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGitHub\u003c/a\u003e. If you\u0026#39;d prefer to start your testing immediately and not to have to implement the signature mechanism by yourself, please proceed by using our publicly available Postman collection, which implements it by default.\u003c/li\u003e\n\u003cli\u003eGetting inspired by our Postman collection of API Samples Rapyd API Collection \u0026amp; Testing with Postman \u003ca href=\"https://docs.rapyd.net/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAPI Documentation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.rapyd.net/build-with-rapyd/docs\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eRapyd documentation website\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.rapyd.net/en/make-your-first-api-call.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ePostman collection\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eNOTE: Only use the sandbox environment for API testing activities.\u003c/h3\u003e","rewardRangeData":{"1":{"min":5000,"max":7500},"2":{"min":1500,"max":4500},"3":{"min":600,"max":1400},"4":{"min":100,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"42e5838f-60c0-48c0-9e74-137894de3f09","name":"Tier 2 In scope","targets":[{"id":"4b4d2737-b0db-4bf1-93d3-175db33b4e13","uri":"https://dashboard.rapyd.net/","name":"dashboard.rapyd.net","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a8055446-9165-4e21-bb10-850286d7cc93","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4b4d2737-b0db-4bf1-93d3-175db33b4e13"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"4b4d2737-b0db-4bf1-93d3-175db33b4e13"}],"recentChangeFlags":null},{"id":"8ba55b05-8c5c-4b1d-a5c2-2e431429841f","uri":"","name":"verify.rapyd.net","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a5579b63-7bf0-4b71-b65b-92711b5d22f3","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"8ba55b05-8c5c-4b1d-a5c2-2e431429841f"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"8ba55b05-8c5c-4b1d-a5c2-2e431429841f"}],"recentChangeFlags":null},{"id":"98ce129d-e1f0-45e4-a731-177c5adea0e3","uri":"","name":"checkout.rapyd.net","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"916cfcc0-0e38-4d30-bb28-bdc9e9ae26c2","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"98ce129d-e1f0-45e4-a731-177c5adea0e3"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"98ce129d-e1f0-45e4-a731-177c5adea0e3"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"b709b22e-a50a-444b-91ad-a65aa5fc8ab5","p1MaxCents":550000,"p1MinCents":280000,"p2MaxCents":250000,"p2MinCents":130000,"p3MaxCents":120000,"p3MinCents":40000,"p4MaxCents":40000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch3\u003eDashboard\u003c/h3\u003e\n\n\u003cp\u003eRapyd\u0026#39;s Dashboard is the place to manage and control your rapyd entities and perform actions such as - generating API keys, checking account balances, managing users, and making transactions.\u003cbr\u003e\nWe have a full sandbox mode environment to simulate every feature supported by the production mode (There\u0026#39;s a little toggle button on the upper right part of the application\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eGo to Rapyd \u003ca href=\"https://dashboard.rapyd.net/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClient Portal\u003c/a\u003e and create your sample user.\u003c/li\u003e\n\u003cli\u003eLink to our Docs - \u003ca href=\"https://docs.rapyd.net/client-portal/docs/client-portal-overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClient Portal Overview\u003c/a\u003e\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch3\u003eCheckout\u003c/h3\u003e\n\n\u003cp\u003eCollecting payments is done by creating a checkout page. follow the instructions to learn how to create one \u003ca href=\"https://docs.rapyd.net/build-with-rapyd/docs/rapyd-checkout-overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCheckout Overview\u003c/a\u003e\u003c/p\u003e\n\n\u003ch3\u003eVerify\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eHow can I Test the Verify application?\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSince Rapyd Verify is a service implemented into other websites (as an iframe) you need to test it as part of a live system, lucky you, we have it implemented in our dashboard application. (dashboard.rapyd.net)\u003c/li\u003e\n\u003cli\u003eYou must create a sample account in the dashboard application and select the UK as the country (this service is only for users who select UK in their business)\u003c/li\u003e\n\u003cli\u003eAfter successfully logging in, select the Activate Account option on the menu\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003ca href=\"https://bugcrowd.com/rapyd-og/attachments/627492e1-9f27-482d-8710-174a392f38c5\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHow to find Rapyd Verify IFrame Video\u003c/a\u003e\u003cbr\u003e\nLink to our Docs - \u003ca href=\"https://docs.rapyd.net/build-with-rapyd/reference/rapyd-verify-1\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eVerify docs\u003c/a\u003e\u003c/p\u003e","rewardRangeData":{"1":{"min":2800,"max":5500},"2":{"min":1300,"max":2500},"3":{"min":400,"max":1200},"4":{"min":100,"max":400},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"dcbee7a6-5c03-4306-ae56-628d50a4fb66","name":"Tier 1 In scope","targets":[{"id":"aaa69db3-163c-4e4a-bc88-12ec04840e05","uri":"","name":"*.rapyd.net","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"be028fd5-e1a3-4c62-900c-7c702bd306e0","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"aaa69db3-163c-4e4a-bc88-12ec04840e05"}],"recentChangeFlags":null},{"id":"c339ceca-3dfc-4e1e-b04b-44683266a3ce","uri":"","name":"*.korta.is","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"732cdef4-3c8f-4523-bf0e-af72a35b26de","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c339ceca-3dfc-4e1e-b04b-44683266a3ce"}],"recentChangeFlags":null},{"id":"b7ceea5e-bfd5-4906-9f18-a9b78fe3c8b3","uri":"https://jointhemoment.net/","name":"jointhemoment.net","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c08224db-3586-49ce-911e-dd76a3579b48","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b7ceea5e-bfd5-4906-9f18-a9b78fe3c8b3"}],"recentChangeFlags":null},{"id":"14851fa7-6f06-4d7a-b67a-38455474ed22","uri":"","name":"*.rapyd.com","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ad0991cc-2c29-40a8-8026-00979a4b19c1","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"14851fa7-6f06-4d7a-b67a-38455474ed22"}],"recentChangeFlags":null},{"id":"08ccfdeb-a079-497f-ae29-1189659c1981","uri":"","name":"*.rapyd.org","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"92ea3691-ad9d-4ede-8ace-4633294caee6","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"08ccfdeb-a079-497f-ae29-1189659c1981"}],"recentChangeFlags":null},{"id":"5e306d69-8f9d-4b53-a2a1-ed8f1745654b","uri":"","name":"*.kortathjonustan.is","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"57d42b6a-adf0-4036-981f-c21fc1a81ff4","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5e306d69-8f9d-4b53-a2a1-ed8f1745654b"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"7425787f-afaf-4cd9-abec-39263710eec1","p1MaxCents":300000,"p1MinCents":125000,"p2MaxCents":120000,"p2MinCents":65000,"p3MaxCents":60000,"p3MinCents":30000,"p4MaxCents":30000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":1250,"max":3000},"2":{"min":650,"max":1200},"3":{"min":300,"max":600},"4":{"min":100,"max":300},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"33da5d20-0c3b-4989-b9c7-78dca55a2ded","name":"Out of Scope Targets","targets":[{"id":"1e286fd7-72a9-4ef4-98ba-d1d003cc8c43","uri":"","name":"community.rapyd.net","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"566986d2-d73f-4ff5-aeb9-915a7c4454f6","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"9ab2d067-2e53-4d62-9781-d1c29c53949b","uri":"","name":"support.rapyd.net","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"27a52913-5910-4f88-a96f-f768509a4423","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"002b2997-9cb7-4432-82d7-8d6b4cfce380","uri":"","name":"docs.rapyd.net","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ceed842c-95cc-4786-9514-23aef3b3700f","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"1dd3f606-b01a-49d5-af31-9ed2be02bf01","uri":"","name":"sandbox.rapyd.net","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"225d3883-99e8-46f4-b46e-f4a3fa62d821","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"dbf5b715-98a5-4279-99be-439ebd76c4d9","uri":"","name":"3rd party services","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"cee2004e-60fd-4d5f-9c04-7445d79858d0","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"9ff3b24a-63b9-4639-a01e-b31897b24133","uri":"","name":"ghost.rapyd.net","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"00faf5f2-2a0e-4253-90e2-fe671192f770","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null},{"id":"c70e2795-c28c-49d6-ab81-03a017508cb5","uri":"","name":"*.neatcommerce.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a4cff40b-662f-43ec-854e-b1f4954873dc","sortOrder":6},"sortOrder":6,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c70e2795-c28c-49d6-ab81-03a017508cb5"}],"recentChangeFlags":null},{"id":"b005a4e0-0d35-4638-81bc-75869ced2681","uri":"","name":"*.neattest.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"83d933a5-d260-47bb-a253-3a7d892ec18e","sortOrder":7},"sortOrder":7,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b005a4e0-0d35-4638-81bc-75869ced2681"}],"recentChangeFlags":null},{"id":"ec76d247-b1ca-4f2f-9026-2049ec6be59b","uri":"","name":"*.neat.com.hk","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"24dd8e4c-9386-49e6-86bb-a44aa23a5591","sortOrder":8},"sortOrder":8,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ec76d247-b1ca-4f2f-9026-2049ec6be59b"}],"recentChangeFlags":null},{"id":"d9db943c-48d3-484a-8d4b-b92df1c47c93","uri":"","name":"*.neat.hk\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7d267615-54cb-47f6-99e7-81a4affb55d9","sortOrder":9},"sortOrder":9,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d9db943c-48d3-484a-8d4b-b92df1c47c93"}],"recentChangeFlags":null},{"id":"5abcedc7-f1c0-4015-8a27-a618266e430d","uri":"","name":"*.neat.wtf\t","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c2d72a8c-0a09-4505-a9c0-54d320d4e9f1","sortOrder":10},"sortOrder":10,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5abcedc7-f1c0-4015-8a27-a618266e430d"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":3,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eOur our-of-scope policy assets are ones hosted by a 3rd party, such as the described targets but not limited to.\u003cbr\u003e\nAutomation/scripts from any kind against support forms are completely out of scope.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[{"id":"79562186-89eb-4ee0-9021-c90166897fe3","attachmentPath":"https://bugcrowd.com/engagements/rapyd/attachments/79562186-89eb-4ee0-9021-c90166897fe3","name":"VerifyIframeDiscovery.mov","filename":"VerifyIframeDiscovery.mov","description":"","icon":"fileVideo","size":31266124,"sizeLabel":"29.8 MB","uploadedAt":"8 Aug 2024","fileType":"Video","embedUrl":"https://bugcrowd.com/engagements/rapyd/attachments/79562186-89eb-4ee0-9021-c90166897fe3"},{"id":"903f7799-ad94-4746-a5f9-1df08635cac6","attachmentPath":"https://bugcrowd.com/engagements/rapyd/attachments/903f7799-ad94-4746-a5f9-1df08635cac6","name":"rapyd-burp-configuration.json","filename":"rapyd-burp-configuration.json","description":null,"icon":"fileOther","size":26612,"sizeLabel":"26 KB","uploadedAt":"8 Aug 2024","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/rapyd/attachments/903f7799-ad94-4746-a5f9-1df08635cac6"}],"engagement":{"id":"fda2752f-4388-43e2-b7ca-c4abcb21b1aa","code":"rapyd","state":"in_progress","endsAt":null,"bountyId":"ea016afd-0402-4381-8c8d-c88403989048","startsAt":"2022-11-01T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/13a5/c1ee/7624f625/29a746eeb7538a2c124904dde8ea4b32_rapyd.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-11-01T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/rapyd","changelogs":"/engagements/rapyd/changelog","submissions":null,"announcements":"/engagements/rapyd/announcements","hallOfFame":"/engagements/rapyd/hall_of_fames","crowdstream":"/engagements/rapyd/crowdstream"},"announcementsCount":24,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/rapyd/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=rapyd\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/rapyd/engagement_subscribers","engagementChangelogsUrl":"/engagements/rapyd/changelog","publishedAt":"2026-06-17T14:06:44.156Z","engagementChangelogUrl":"/engagements/rapyd/changelog/4fd154ee-8a7d-4d42-bab8-2ff1e017c1b2","createUserFeedbacksUrl":"/engagements/rapyd/feedbacks","engagementCrowdstreamUrl":"/engagements/rapyd/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}