4,500+ servers built on MCP Fusion
Vinkius
HackerOne logo
Vinkius
Claude Desktop logo

How to Use the HackerOne MCP in Claude

Run your HackerOne bug bounty triage directly from Claude Desktop without jumping between browser tabs.

See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

HackerOne MCP on Cursor AI Code Editor MCP Client HackerOne MCP on Claude Desktop App MCP Integration HackerOne MCP on OpenAI Agents SDK MCP Compatible HackerOne MCP on Visual Studio Code MCP Extension Client HackerOne MCP on GitHub Copilot AI Agent MCP Integration HackerOne MCP on Google Gemini AI MCP Integration HackerOne MCP on Lovable AI Development MCP Client HackerOne MCP on Mistral AI Agents MCP Compatible HackerOne MCP on Amazon AWS Bedrock MCP Support
MCP Servers - Free for Subscribers
Claude Desktop

Connect HackerOne MCP to Claude Desktop

Create your Vinkius account to connect HackerOne to Claude Desktop and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.

GDPR Free for Subscribers

Triage HackerOne reports inside Claude Desktop

`list_reports` pulls your active bug submissions directly into your local chat interface. Your agent reads the incoming vulnerability details, checks the severity, and flags duplicates against previous submissions. You do not need to log into the web dashboard to change a report status. Run `change_report_state` to transition validated bugs to triaged or resolve them once patched.

Run HackerOne program audits in your workspace

`get_program` pulls scope rules and asset lists directly into your desktop environment. This lets your agent compare reported vulnerabilities against your declared scope to instantly spot out-of-scope submissions. Run `list_assets` to verify if a reported domain or endpoint is actually on your target list. Claude Desktop processes this data locally, keeping your program scope visible during active triage sessions.

Manage bounty payments with this MCP Server

`list_payments` retrieves your complete bounty transaction history directly inside the Claude Desktop chat window. Your agent analyzes past payouts to keep your current spending aligned with your budget. Execute `award_bounty` to reward researchers for valid findings without leaving your desktop terminal. You retain final approval on every transaction, keeping financial control secure.

Setup guide

Set up HackerOne MCP in Claude Web or Desktop

  1. 1

    Open Claude Settings

    Go to claude.ai, click your profile icon, then navigate to Customize → Connectors.

  2. 2

    Add Custom Connector

    Click the "+" button and select Add custom connector. Paste your Vinkius endpoint URL: https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp Replace [YOUR_TOKEN_HERE] with your token from cloud.vinkius.com. For OAuth-protected servers, expand Advanced settings to add credentials.

  3. 3

    Start a conversation

    Open a new chat. The HackerOne MCP tools are available immediately — no restart needed.

Endpoint URL

https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp

No configuration file needed — paste the URL directly in the Claude web interface.

Available on Free (1 connector), Pro, Max, Team, and Enterprise plans.

Why Choose Vinkius

Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.

Real-time monitoring

Live

visibility into every interaction

Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.

Built-in savings

60%

lower AI costs

Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.

Single dashboard

One

place for every integration

Every tool your AI connects to, managed from a single screen. One account, complete control.

Common questions about HackerOne MCP in Claude Desktop

Open your local `claude_desktop_config.json` file and add the server configuration under the `mcpServers` key. Restart the app, and you will see the tools ready to use in your chat window.
Yes, by combining `list_reports` and `add_report_comment` to draft replies to researchers. You can review the drafted comments in your desktop chat before they go live.
The `award_bounty` tool allows Claude Desktop to trigger payouts directly from your prompt. We recommend manual verification before executing this tool to prevent accidental financial transfers.
Use `list_programs` to fetch your active programs, then run `list_assets` to see the defined scope. This lets you quickly check if a researcher's submission matches your actual attack surface.
Your vulnerability reports and payment records remain strictly within your local Claude Desktop environment. Vinkius handles the connection via a secure, ephemeral sandbox, meaning your raw security data is never stored or used for model training.

Start using the HackerOne MCP today

We host it, we monitor it, we maintain it. You just paste one token.

Built & Managed by Vinkius 30s setup 10 tools

We've already built the connector for HackerOne. Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 10 tools are live and waiting. You're up and running in seconds.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.