— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for TrueLayer.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"id": "ed04d1ef-1aa3-49dd-92f1-06f50f9756b9",
"name": "TrueLayer",
"company_handle": "truelayer",
"handle": "truelayer",
"url": "https://www.intigriti.com/programs/truelayer/truelayer/detail",
"status": "open",
"confidentiality_level": "public",
"tacRequired": false,
"twoFactorRequired": false,
"min_bounty": {
"value": 75,
"currency": "EUR"
},
"max_bounty": {
"value": 6000,
"currency": "EUR"
},
"targets": {
"in_scope": [
{
"type": "url",
"endpoint": "api.truelayer[-sandbox].com",
"description": "The majority of our API endpoints live here",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "api.mtls.truelayer[-sandbox].com",
"description": "The same API as `api.truelayer[-sandbox].com` but with mutual TLS setup",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "auth.truelayer[-sandbox].com",
"description": "Our service for getting OAuth access tokens to access our APIs",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "auth.mtls.truelayer[-sandbox].com",
"description": "The same service as `auth.truelayer[-sandbox].com` but with mutual TLS setup",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "app.truelayer[-sandbox].com",
"description": "Hosted Payments Page v2",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "login-api.truelayer[-sandbox].com",
"description": null,
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "login.truelayer[-sandbox].com",
"description": "Where you can connect your bank account and use Open Banking to pull data such as transactions",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "onboarding-api.truelayer.com",
"description": "Used in the developer console",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "pay-api.truelayer[-sandbox].com",
"description": null,
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "pay.truelayer[-sandbox].com",
"description": "Some of our older payment API endpoints live here rather than on api.truelayer.com",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "paydirect.truelayer[-sandbox].com",
"description": "Some of our older payment API endpoints live here rather than on api.truelayer.com",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "payment.truelayer[-sandbox].com",
"description": "Our hosted payments page for merchants that want us to manage the UI screens for making payments",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "payments-experience-api.truelayer[-sandbox].com",
"description": "Hosted Payments Page dependency (e.g. for handoff)",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "user-authentication-api.truelayer[-sandbox].com",
"description": "Remember Me functionality for payments. See https://truelayer.com/legal/enduser_tos/#save-my-details-remember-me",
"impact": "Tier 1"
},
{
"type": "url",
"endpoint": "users-api.truelayer.com",
"description": "Internal service for managing users",
"impact": "Tier 1"
},
{
"type": "other",
"endpoint": "C# SDK",
"description": "https://github.com/TrueLayer/truelayer-dotnet",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "console-backend.truelayer[-sandbox].com",
"description": null,
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "console.truelayer[-sandbox].com",
"description": "Our developer console where you can login, create applications, manage your OAuth client ID/secret, upload public keys for request signing, view transactions",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "sftp.reports.truelayer.com",
"description": "SFTP reporting functionality in the Console. See https://docs.truelayer.com/docs/sftp-in-console",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Java SDK",
"description": "https://github.com/TrueLayer/truelayer-java",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "PHP SDK",
"description": "https://github.com/TrueLayer/truelayer-php",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "TrueLayer for Magento (Magento plugin)",
"description": "https://github.com/TrueLayer/magento2",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "shopify-admin.truelayer.com",
"description": "Shopify Plugin backend admin page. See https://docs.truelayer.com/docs/shopify",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "shop-pay-app-api.truelayer.com",
"description": "Shopify Plugin backend API. See https://docs.truelayer.com/docs/shopify",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "truelayer-signing",
"description": "https://github.com/TrueLayer/truelayer-signing is our open source library for generating signed requests for calling TrueLayer APIs. Many languages are supported including Rust, C#, NodeJS, Go, Java and PHP.",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "webhooks.truelayer[-sandbox].com",
"description": null,
"impact": "Tier 2"
},
{
"type": "wildcard",
"endpoint": "*.truelayer.cloud",
"description": null,
"impact": "Tier 3"
},
{
"type": "wildcard",
"endpoint": "*.truelayer.com",
"description": null,
"impact": "Tier 3"
},
{
"type": "wildcard",
"endpoint": "*.truelayer.io",
"description": null,
"impact": "Tier 3"
},
{
"type": "other",
"endpoint": "iOS SDK",
"description": "https://github.com/TrueLayer/TrueLayer-iOS-SDK",
"impact": "Tier 3"
},
{
"type": "other",
"endpoint": "React Native SDK",
"description": "https://github.com/TrueLayer/truelayer-react-native-sdk",
"impact": "Tier 3"
},
{
"type": "other",
"endpoint": "Web SDK",
"description": "https://www.npmjs.com/package/truelayer-web-sdk\n\nA lightweight web SDK for integrating Truelayer's payment services into your web application.",
"impact": "Tier 3"
},
{
"type": "other",
"endpoint": "Rust SDK",
"description": "https://github.com/TrueLayer/truelayer-rust\n\nCurrently we are not paying bounties for this asset as it's still in alpha.",
"impact": "No Bounty"
}
],
"out_of_scope": [
{
"type": "url",
"endpoint": "trust.truelayer.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "other",
"endpoint": "TrueLayer for WooCommerce (WordPress plugin)",
"description": "https://wordpress.org/plugins/truelayer-for-woocommerce/ is our WordPress plugin allowing you to use TrueLayer as a checkout option in your WooCommerce store. The source code is also [available on GitHub](https://github.com/TrueLayer/truelayer-woocommerce).",
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "banks.truelayer.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "careers.truelayer.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "docs.truelayer.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "docs.houston.truelayer.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "https://truelayer.com/contact/",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "index.truelayer.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "info.truelayer.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "signin.truelayer.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "support.truelayer.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "status.truelayer.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "truelayer.zendesk.com",
"description": null,
"impact": "Out of scope"
}
]
}
}api.truelayer[-sandbox].com· Tier 1api.mtls.truelayer[-sandbox].com· Tier 1auth.truelayer[-sandbox].com· Tier 1auth.mtls.truelayer[-sandbox].com· Tier 1app.truelayer[-sandbox].com· Tier 1login-api.truelayer[-sandbox].com· Tier 1login.truelayer[-sandbox].com· Tier 1onboarding-api.truelayer.com· Tier 1pay-api.truelayer[-sandbox].com· Tier 1pay.truelayer[-sandbox].com· Tier 1paydirect.truelayer[-sandbox].com· Tier 1payment.truelayer[-sandbox].com· Tier 1payments-experience-api.truelayer[-sandbox].com· Tier 1user-authentication-api.truelayer[-sandbox].com· Tier 1users-api.truelayer.comC# SDK· Tier 2Java SDK· Tier 2PHP SDK· Tier 2TrueLayer for Magento (Magento plugin)· Tier 2truelayer-signing· Tier 2iOS SDK· Tier 3React Native SDK· Tier 3Web SDK· Tier 3Rust SDK· No BountyTrueLayer for WooCommerce (WordPress plugin)console-backend.truelayer[-sandbox].com· Tier 2console.truelayer[-sandbox].com· Tier 2webhooks.truelayer[-sandbox].com· Tier 2