Postmates HackerOne


Target Policy
https://hackerone.com/postmates?type=team
Structured Scope
  • Asset Identifier
    Asset Type
    Max Severity
  • postmates.com/developer
    URL
    none
  • raster-static.postmates.com

    Image resizing and proxy service.

    URL
    critical
  • postmates.com/partner
    URL
    none
  • com.postmates.android

    This is the primary Android app for our customers/buyers to purchase goods, view their account information, add/edit card details, etc.

    GOOGLE_PLAY_APP_ID
    critical
  • partner.postmates.com

    This is the self serve dashboard for our merchants.
    Merchants can change their API keys, review payment information, view past order and payout history, disable themselves from the platform, etc.

    URL
    critical
  • support.postmates.com

    This is the self serve help center for our customers.

    URL
    low
  • blog.postmates.com
    URL
    none
  • brand.postmates.com

    Brand.postmates.com is operated by a third-party vendor, not Postmates. Since it's owned by a different company, we would ask that researchers avoid interacting with it.

    URL
    none
  • buyer-prod.postmates.com

    Main production backend for the mobile and web apps for our consumers/buyers.

    URL
    critical
  • iOS/Android fleet apps

    You may download the fleet apps used by our couriers by visiting https://fleet.postmates.com/app.
    These apps are used for accepting and fulfilling any deliveries that come into our platform.

    OTHER
    critical
  • about.postmates.com

    This is the subdomain hosting some of our legal terms, some information about the company, and so on.

    URL
    medium
  • fleet.postmates.com

    This is the self serve dashboard and sign up location for our fleet.
    Couriers can manage their personal information, get past order history, check payment information, etc.

    URL
    critical
  • 512393983

    This is the primary iOS app for our customers/buyers to purchase goods, view their account information, add/edit card details, etc.

    APPLE_STORE_APP_ID
    critical
  • postmates.com

    This is the main website where customers can register, login, make orders, see order status, change credit card / name / phone number / delivery address / etc.
    This also includes ipa.postmates.com (the backend servicing the requests).

    URL
    critical
Target Scope Domains
  • about.postmates.com
  • buyer-prod.postmates.com
  • fleet.postmates.com
  • partner.postmates.com
  • postmates.com
  • raster-static.postmates.com
  • support.postmates.com
Tech Stack

Last Finished Scan:
Scan Name
Fleet
Finished
State
allkxss
1 year, 1 month ago
Finished
  • Fleet: allkxss
  • Duration: 17.68 Minutes
  • Finished: 1 year, 1 month ago