How to Use the HackerOne MCP in Claude
Run your HackerOne bug bounty triage directly from Claude Desktop without jumping between browser tabs.
Works with every AI agent you already use
…and any MCP-compatible client
Connect HackerOne MCP to Claude Desktop
Create your Vinkius account to connect HackerOne to Claude Desktop and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.
Triage HackerOne reports inside Claude Desktop
`list_reports` pulls your active bug submissions directly into your local chat interface. Your agent reads the incoming vulnerability details, checks the severity, and flags duplicates against previous submissions. You do not need to log into the web dashboard to change a report status. Run `change_report_state` to transition validated bugs to triaged or resolve them once patched.
Run HackerOne program audits in your workspace
`get_program` pulls scope rules and asset lists directly into your desktop environment. This lets your agent compare reported vulnerabilities against your declared scope to instantly spot out-of-scope submissions. Run `list_assets` to verify if a reported domain or endpoint is actually on your target list. Claude Desktop processes this data locally, keeping your program scope visible during active triage sessions.
Manage bounty payments with this MCP Server
`list_payments` retrieves your complete bounty transaction history directly inside the Claude Desktop chat window. Your agent analyzes past payouts to keep your current spending aligned with your budget. Execute `award_bounty` to reward researchers for valid findings without leaving your desktop terminal. You retain final approval on every transaction, keeping financial control secure.
Set up HackerOne MCP in Claude Web or Desktop
- 1
Open Claude Settings
Go to claude.ai, click your profile icon, then navigate to Customize → Connectors.
- 2
Add Custom Connector
Click the "+" button and select Add custom connector. Paste your Vinkius endpoint URL:
https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcpReplace[YOUR_TOKEN_HERE]with your token from cloud.vinkius.com. For OAuth-protected servers, expand Advanced settings to add credentials. - 3
Start a conversation
Open a new chat. The HackerOne MCP tools are available immediately — no restart needed.
Endpoint URL
https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp No configuration file needed — paste the URL directly in the Claude web interface.
Available on Free (1 connector), Pro, Max, Team, and Enterprise plans.
Why Choose Vinkius
Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.
Real-time monitoring
Live
visibility into every interaction
Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.
Built-in savings
60%
lower AI costs
Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.
Single dashboard
One
place for every integration
Every tool your AI connects to, managed from a single screen. One account, complete control.
Common questions about HackerOne MCP in Claude Desktop
Use it with your favorite AI tools
Connect this server to Cursor, Claude, VS Code, and more.
Start using the HackerOne MCP today
We host it, we monitor it, we maintain it. You just paste one token.