HackerOneScore: 15/100
api.hackerone.com
About HackerOne
The industry’s first hacker API that helps increase productivity towards creative bug bounty hunting
🔌 API Specifications
Usage Tips
- 💡🔌 Test the API with Postman or curl before integrating
- 💡💬 Join the discussion below to share your experience and ask questions
Related Resources
Similar Tools
Resource Overview
📝 Content Notice
The overview, features, pros/cons, and use cases on this page are generated with AI assistance based on publicly available information. We review and edit AI-generated content for accuracy, but if you spot an error, please let us know.
About this tool
HackerOne is a bug bounty platform connecting security researchers with companies that pay for vulnerability reports. Its API lets security teams automate report triage, bounty payments, and vulnerability workflows. For bug hunters, the API provides programmatic access to their submissions, rewards, and reputation data.
Pros
- +Full report lifecycle: create, update, triage, close, and award bounties via API
- +Webhook events for real-time notifications on report submissions and state changes
- +OAuth 2.0 authentication for third-party integrations
- +Hacker activity API: track submissions, bounty earnings, and reputation across programs
- +Structured vulnerability data with CVSS scoring and weakness classification (CWE)
Data source: public-apis · Generated: 7/18/2026
Frequently Asked Questions
Is HackerOne free to use?
Yes, HackerOne is 100% free to use.
What are the best alternatives to HackerOne?
Top alternatives to HackerOne include similar tools in the free tools category. Visit our compare page to see detailed comparisons.
Is HackerOne open source?
Yes, HackerOne is open source software. You can view the source code on GitHub.
How do I get started with HackerOne?
The industry’s first hacker API that helps increase productivity towards creative bug bounty hunting
Resource data sourced from FMHY, last updated: Unknown
We are not responsible for the content of external websites. Please verify all information independently.
More Tools
Android library and API to verify the safety of user devices, detect rooted devices and other risks · Authentication: `apiKey` · HTTPS supported · CORS enabled
github.com
VisitProvide access to BinaryEdge 40fy scanning platform · Authentication: `apiKey` · HTTPS supported · CORS enabled
docs.binaryedge.io
VisitResource data sourced from FMHY and curated by the Craftisle team. Listings are regularly reviewed for accuracy and compliance. If you find an outdated link, let us know.
Comments are not yet configured. Set Giscus environment variables to enable.