2,500+ MCP servers ready to use
Vinkius
MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED
HackerOne

HackerOne MCP Server

Built by Vinkius GDPR ToolsFree for Subscribers

Automate bug bounty management via HackerOne — manage reports, programs, and payments directly from any AI agent.

Vinkius supports streamable HTTP and SSE.

AI AgentVinkius
High Security·Kill Switch·Plug and Play
HackerOne
Fully ManagedVinkius Servers
60%Token savings
High SecurityEnterprise-grade
IAMAccess control
EU AI ActCompliant
DLPData protection
V8 IsolateSandboxed
Ed25519Audit chain
<40msKill switch
Stream every event to Splunk, Datadog, or your own webhook in real-time

* Every MCP server runs on Vinkius-managed infrastructure inside AWS - a purpose-built runtime with per-request V8 isolates, Ed25519 signed audit chains, and sub-40ms cold starts optimized for native MCP execution. See our infrastructure

What is the HackerOne MCP Server?

The HackerOne MCP Server gives AI agents like Claude, ChatGPT, and Cursor direct access to HackerOne via 10 tools. Automate bug bounty management via HackerOne — manage reports, programs, and payments directly from any AI agent. Powered by the Vinkius - no API keys, no infrastructure, connect in under 2 minutes.

Built-in capabilities (10)

add_report_commentaward_bountychange_report_stateget_programget_reportlist_assetslist_hacktivitylist_paymentslist_programslist_reports

Tools for your AI Agents to operate HackerOne

Ask your AI agent "List all vulnerability reports submitted this week." and get the answer without opening a single dashboard. With 10 tools connected to real HackerOne data, your agents reason over live information, cross-reference it with other MCP servers, and deliver insights you would spend hours assembling manually.

Works with Claude, ChatGPT, Cursor, and any MCP-compatible client. Powered by the Vinkius - your credentials never touch the AI model, every request is auditable. Connect in under two minutes.

Why teams choose Vinkius

One subscription gives you access to thousands of MCP servers - and you can deploy your own to the Vinkius Edge. Your AI agents only access the data you authorize, with DLP that blocks sensitive information from ever reaching the model, kill switch for instant shutdown, and up to 60% token savings. Enterprise-grade infrastructure and security, zero maintenance.

Build your own MCP Server with our secure development framework →

Vinkius works with every AI agent you already use

…and any MCP-compatible client

CursorClaudeOpenAIVS CodeCopilotGoogleLovableMistralAWSCursorClaudeOpenAIVS CodeCopilotGoogleLovableMistralAWS

HackerOne MCP Server capabilities

10 tools
add_report_comment

Add a comment to a specific vulnerability report

award_bounty

Award a bounty for a vulnerability report

change_report_state

Update the state of a vulnerability report (e.g., triaged, resolved)

get_program

Get details for a specific security program

get_report

Get detailed information about a specific vulnerability report

list_assets

List assets defined in your security programs

list_hacktivity

List the HackerOne hacktivity feed

list_payments

List bounty payments history

list_programs

List bug bounty or VDP programs you have access to

list_reports

List vulnerability reports submitted to your HackerOne program

What the HackerOne MCP Server unlocks

Connect your HackerOne organization account to any AI agent and take full control of your vulnerability management workflows through natural conversation.

What you can do

  • Report Oversight — List all vulnerability reports, retrieve detailed information, and monitor their current state and severity.
  • Program Insights — Browse your bug bounty or VDP programs and access structured scopes and assets.
  • Report Interaction — Add comments to reports, change their triaged state, or award bounties directly from the chat.
  • Asset Tracking — Monitor the assets defined within your security programs and their reachability.
  • Financial Monitoring — Retrieve history of bounty payments and manage rewards efficiently.
  • Hacktivity Feed — Stay updated with the internal or public hacktivity feed to see recent discoveries.

How it works

1. Subscribe to this server
2. Enter your HackerOne API Token Identifier and Token Value
3. Start managing your security programs from Claude, Cursor, or any MCP-compatible client

No more jumping between report tabs. Your AI assistant acts as a dedicated Triage Engineer or Security Program Manager.

Who is this for?

  • Security Engineers — instantly retrieve report details and severity ratings during triage.
  • Bug Bounty Managers — automate the process of awarding bounties and communicating with researchers.
  • CISOs — maintain a real-time overview of incoming vulnerabilities and program health.

Frequently asked questions about the HackerOne MCP Server

01

How do I generate my HackerOne API Token?

Log in to HackerOne, navigate to Settings > API Token, and click 'Create API Token'. Make sure to copy both the Identifier and the Token Value immediately.

02

Can I award bounties through this integration?

Yes! Use the award_bounty tool by providing the report ID and the amount. You can also specify an optional bonus amount for the researcher.

03

Does the integration support internal comments?

Yes, the add_report_comment tool has an optional internal boolean parameter (defaults to true). This allows you to communicate with your team privately on a specific report.

04

Can I filter reports by their handle or ID?

You can use list_reports to see all reports or get_report with a specific ID to retrieve detailed information for a single discovery.

More in this category

You might also like

Give your AI agents the power of HackerOne MCP Server

Production-grade HackerOne MCP Server. Verified, monitored, and maintained by Vinkius. Ready for your AI agents — connect and start using immediately.