4,500+ servers built on MCP Fusion
Vinkius
HackerOne logo
Vinkius
Claude Code logo

How to Use the HackerOne MCP in Claude Code

Run HackerOne triage, post updates, and issue bounties directly from your terminal using Claude Code.

See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

HackerOne MCP on Cursor AI Code Editor MCP Client HackerOne MCP on Claude Desktop App MCP Integration HackerOne MCP on OpenAI Agents SDK MCP Compatible HackerOne MCP on Visual Studio Code MCP Extension Client HackerOne MCP on GitHub Copilot AI Agent MCP Integration HackerOne MCP on Google Gemini AI MCP Integration HackerOne MCP on Lovable AI Development MCP Client HackerOne MCP on Mistral AI Agents MCP Compatible HackerOne MCP on Amazon AWS Bedrock MCP Support
MCP Servers - Free for Subscribers
Claude Code

Connect HackerOne MCP to Claude Code

Create your Vinkius account to connect HackerOne to Claude Code and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.

GDPR Free for Subscribers

Pipe HackerOne reports directly into your terminal tools

The `list_reports` tool lets Claude Code fetch pending submissions straight to your command line. You can pipe this data into grep, jq, or local scripts to filter findings by severity or asset type. Claude Code reads the raw JSON payloads, summarizes the impact, and lets you update the state using `change_report_state` without leaving your shell. It is built for speed and keyboard-driven security workflows.

Monitor public disclosures using Claude Code

The `list_hacktivity` tool allows Claude Code to fetch the latest public activity from the HackerOne feed. You can track trending vulnerabilities and security disclosures directly from your terminal session. The agent parses the feed to identify common attack vectors or bug patterns. This helps you proactively search your own codebase for similar issues before researchers find them.

Audit security assets with the HackerOne MCP Server

This MCP Server exposes the `list_assets` and `get_program` tools so Claude Code can audit your attack surface from the CLI. The agent pulls your active targets and maps them against your local asset inventory. You can quickly verify which domains or repositories are in scope. Claude Code runs these checks in seconds, making it easy to keep your program definitions accurate.

Setup guide

Set up HackerOne MCP in Claude Code

Prerequisites

  • Claude Code CLI installed (npm install -g @anthropic-ai/claude-code)
  • Active Vinkius subscription with a valid endpoint token
  1. 1

    Run the add command

    Open your terminal and run the command shown on the right. Replace [YOUR_TOKEN_HERE] with your endpoint token from cloud.vinkius.com. Use --scope user to make it available across all projects.

  2. 2

    Verify the connection

    Start a Claude Code session and type /mcp to list connected servers. You should see hackerone-mcp with a green status indicator.

  3. 3

    Start using tools

    Ask Claude Code something like "Check my latest HackerOne transactions." It will automatically discover and invoke the available HackerOne tools.

Terminal
claude mcp add --transport http hackerone-mcp https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp

Why Choose Vinkius

Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.

Real-time monitoring

Live

visibility into every interaction

Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.

Built-in savings

60%

lower AI costs

Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.

Single dashboard

One

place for every integration

Every tool your AI connects to, managed from a single screen. One account, complete control.

Common questions about HackerOne MCP in Claude Code

Run the `claude mcp add` command with your HTTP or stdio parameters. Claude Code will save the configuration in your local JSON settings and load the tools instantly.
Yes, you can combine Claude Code with terminal commands to script report updates. The agent uses `list_reports` and `add_report_comment` to automate routine communication.
Yes, Claude Code can execute the `award_bounty` tool to pay researchers from your command line. It can also query `list_payments` to check historical transactions first.
Yes, Claude Code uses `list_programs` to display all the security programs you manage. You can quickly view program rules and scopes without opening a web browser.
Your vulnerability reports and payment history are fetched over encrypted connections using your local API token. Claude Code processes this data locally in your terminal session, keeping your private findings secure.

Start using the HackerOne MCP today

We host it, we monitor it, we maintain it. You just paste one token.

Built & Managed by Vinkius 30s setup 10 tools

We've already built the connector for HackerOne. Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 10 tools are live and waiting. You're up and running in seconds.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.