United Airlines

  • Safe harbor
  • No collaboration

Reward bonuses for New Customer Identity and Access Management Solution

United Airlines is excited share the creation of a more user-friendly and secure customer experience with one-time passcodes (OTP) for our MileagePlus account holders.

One-time passcodes are an enhanced security measure that will replace security questions and will be sent to the member’s verified phone number or email address when logging into their account on new or unknown devices.

We are pleased to announce United Airlines is now offering bonuses starting as of June 19, 2024, and will end on June 28, 2024!

For the above date range, this program will be paying out double the awards miles for any valid submissions on the below endpoints. Please note that only the specified CIAM endpoints are in-scope for bonus awards, and that other authentication related endpoints are excluded from this promotion.

Below are the bonus details:

Previous Reward Range New Reward Range
50,000 - 1 million miles 100,000 - 2 million miles

Bonus Qualifications for P(1-5) on the following:

  • https://www.united.com/xapi/auth/signin
  • https://www.united.com/xapi/auth/partner-login-validate-session
  • https://www.united.com/xapi/auth/send-otp
  • https://www.united.com/xapi/auth/validate-otp
  • https://www.united.com/xapi/auth/step-up-initiate
  • https://www.united.com/xapi/auth/step-up-complete
  • https://www.united.com/xapi/auth/step-up-validate
  • https://www.united.com/xapi/auth/channel/send-verification-otp
  • https://www.united.com/xapi/auth/channel/validate-verification-otp
  • https://mobileapi.united.com/mpauthenticationservice/api/MileagePlusCsl/ValidateMPSignInV3
  • https://mobileapi.united.com/mpauthenticationservice/api/MileagePlusCsl/ValidateSecurityCode
  • https://mobileapi.united.com/customerprofileservice/api/GetOtpCode
  • https://mobileapi.united.com/customerprofileservice/api/ValidateOtpCode
  • https://mobileapi.united.com/mpauthenticationservice/api/MileagePlusCSL/TOTPDeviceEnrollment
  • https://mobileapi.united.com/mpauthenticationservice/api/MileagePlusCSL/TOTPDeviceDeRegister

Note, all bonuses and scope are subject to change at the discretion of United Airlines. If you have any questions, please reach out to support@bugcrowd.com.