Credential Revocation Alerts Now Cover Program Access Loss
Customer credential revocation notifications now fire consistently across all scenarios in which a researcher loses access to a program, including voluntary departure, program/org ban, and platform ban.
What we did:
Program, organization, and platform bans now trigger the same workflow as a voluntary departure: claimed credentials are marked as revoked in HackerOne, and customer program admins are emailed to revoke that access in their own systems. Previously, a program ban revoked credentials only in our UI, and a platform ban did neither, leaving customer-side credentials live. With a backfill to be completed on October 7, 2026.
Why we did it:
Marking a credential revoked in our UI hides the secret from the researcher, but it does nothing to the credential itself. The credentials keep working against the customer's systems until the customer disables them. Our docs place that step with the customer, but we weren't consistently telling customers when to take action.
Who it helps:
Customers using asset-based credential management. Their offboarding is now driven by a notification rather than by noticing.
How to use it:
Nothing to enable. Program admins receive the notification automatically; credentials are managed under Program Settings → Credentials. A backfill for researchers who left before September 17, 2026, when this change was released, will be completed on October 7, 2026. CSMs have been contacted with potentially impacted customers.
Documentation: Asset-based credential management
Higher Hacker Limit for Spot Checks
Programs can now invite up to 50 hackers to a spot check, up from the previous cap of 15.
What we did:
Raised the maximum number of hackers that can be invited to a single spot check from 15 to 50.
Why we did it:
The 15-hacker cap was hardcoded, but some programs routinely want to run spot check with ~40 hackers. Every one of those required a one-off engineering escalation to override the limit, a recurring support cost that didn't scale.
Who it helps:
Any program running spot checks at scale and the Support/Engineering teams fielding override requests. Immediate relief for AWS, who drove the original ask.
How to use it:
No action needed. When creating a spot check, the hacker-count field now accepts any value between 1 and 50.
Documentation: Docsite page
