MCP server connecting Claude to the HackerOne Hacker API — programs, scope, reports, hacktivity, payouts
An MCP server that connects Claude to the HackerOne Hacker API. List your programs, pull structured scope, read and submit reports, browse Hacktivity, and check your balance — all from inside Claude Code.
Tool What it does -------------------- testconnection Verify credentials work (run this first) listprograms List programs you can access getprogram Full details for one program by handle getprogramscope Structured scope (in-scope assets), filter by bounty/submission getprogramweaknesses Accepted weakness (CWE) types getscopeexclusions Out-of-scope categories searchscope Search a keyword across ALL your programs' scopes listmyreports Reports you've submitted getreport One report by ID (activities, bounties, state) submitreport Submit a new vulnerability report hacktivity Query publicly disclosed reports for intel getbalance / getearnings / getpayouts Money hackeroneapi Raw passthrough for any other endpoint
1. Get an API token Go to , create a token, and note both the identifier (username) and the token value.
The server auto-loads .env from this folder — nothing else to configure.
Then in Claude: "list my HackerOne programs" or "pull the scope for program X".
To register only for the current project instead, add --scope project.
Credentials come from .env, or set HACKERONEAPIUSERNAME / HACKERONEAPITOKEN in the env block of the config.
Notes - Base URL: https://api.hackerone.com/v1, HTTP Basic auth. - submitreport creates a real report — review details before calling. - .env is gitignored; never commit your token.
From the project README.
Add the radar badge to your README — it shows your project was picked up by MCP Radar and links to this page:
[](https://mcp.liqiwa.com/s/abdugafforov-bobur--hackerone-mcp.html)
Turn scattered notes, docs and transcripts into a queryable Markdown wiki — an LLM knowledge-base compiler with MCP access, no embeddings, self-hosted.
alxgntv/substack-api-mcpMCP server for Substack posts (FastMCP + substack-api-client)
sm18lr88/STT-MCPFast, local speech-to-text MCP server
simonw/mcp-explorerCLI tool for exploring an MCP server
sandeepbazar/ocm-mcp-serverAn MCP server that lets AI agents operate a multi-cluster Kubernetes fleet through an Open Cluster Management hub, with policy, approval, and audit between the model and your clusters.
Vladimir-Human/ru-marketplace-mcpДевять российских маркетплейсов и китайский Taobao как MCP-серверы: Wildberries, Ozon, Яндекс Маркет, Детский мир, Авито, Мегамаркет, Lamoda, DNS, Ситилинк. Плюс сравнение цен по всем сразу. Только чт
The top new MCP servers of the week, every Monday. No spam, unsubscribe anytime.