The industry’s first hacker API that helps increase productivity towards creative bug bounty hunting.
HackerOne provides an API for organizations running vulnerability disclosure or bug bounty programs. It allows programs to pull vulnerability reports into their own systems, access program information such as settings, balance, and recent transactions, and award bounties to hackers who report vulnerabilities, including for issues found outside HackerOne through the program bounty endpoint.
The API also supports importing findings from external systems or penetration tests into HackerOne, which improves duplicate detection and centralizes reporting alongside vulnerabilities submitted directly through the platform.
This is intended for security teams and organizations that run bug bounty or vulnerability disclosure programs on HackerOne and want to automate report handling, bounty payments, and program management workflows.
You can pull vulnerability reports, access program information, award bounties, and import external findings.
Yes, the Reports API lets you import findings from external systems or pentests to improve duplicate detection and reporting.
Yes, the program bounty endpoint lets you reward hackers for vulnerabilities found outside of HackerOne.
Yes, the API lets you manage your program settings and access your current balance and recent transactions.
Show your product to thousands of developers
· 100k monthly pageviews
· 7k newsletter subscribers
Searchable attack surface database of the entire internet.
Scan files for secrets (API Keys, database credentials).
Query IPs in the GreyNoise dataset and retrieve a subset of the full IP context data.
Passwords which have previously been exposed in data breaches.
Perform OSINT via Intelligence X.
Bot detection and fraud prevention API with IP reputation and email validation.