Withings creates connected devices that make better health part of daily life. Our clinically validated and multi-award winning range is used by millions worldwide, and includes smart scales, hybrid watches, sleep analyzers and more. Everything connects to our app, which helps people get deep insights on their health, and find tailored programs to improve it.
With the goal of improving the security of our users and partners, we decided to launch a Bug Bounty program because we believe that security researchers will greatly help us achieve this goal.
To start our public program, we focus on our public API, our login portal and our web application Withings App. The scope of our public program will grow over the time.
If you are working on this program, you must abide by all of the following rules:
Public API (https://wbsapi.withings.net) documentation is available here.
Scope Type | Scope Name |
---|---|
api | https://wbsapi.withings.net |
api | https://scalews.withings.com |
undefined | Body Scan scale |
undefined | Body Comp scale |
undefined | Scanwatch Light |
undefined | Scanwatch 2 |
undefined | Scanwatch Nova |
undefined | Scanwatch |
web_application | https://healthmate.withings.com |
web_application | https://account.withings.com |
web_application | https://app.withings.com |
web_application | https://developer.withings.com/dashboard/ |
Scope Type | Scope Name |
---|---|
undefined | All domains, devices and mobile Apps not listed In-Scope. |
This policy crawled by Onyphe on the 2023-06-26 is sorted as bounty.
FireBounty © 2015-2025