
HackerOne Connector
You're all set. Choose your MCP client and follow the setup instructions.
https://edge.vinkius.com/vk_preview_MdngwsTWgI8aN2tcglppukreOCXiR4XOops4TQFJ/mcpConnecting HackerOne to Qwen Code
About a minute, in your terminal
- 1Run: qwen mcp add --transport http HackerOne <your link>. The link above is the URL.
- 2Prefer a config file? Add it to ~/.qwen/settings.json (user) or .qwen/settings.json (project) with the httpUrl field. The link above is the URL.
- 3Enter /mcp in the chat to confirm the server appears. HackerOne is now part of Qwen Code.
{
"mcpServers": {
"hackerone-mcp": {
"url": "https://edge.vinkius.com/vk_preview_MdngwsTWgI8aN2tcglppukreOCXiR4XOops4TQFJ/mcp"
}
}
}Qwen Code + HackerOne
One chat. Your HackerOne, live inside Qwen Code.
Real prompts, answered with live data. This is the kind of session you will have in Qwen Code once the link is in.
Waiting for input…
Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.
These prompts ship with the HackerOne Connector. Once yours is connected, they work in your sessions.
The full capability set, the prompts and the observed latency live on the HackerOne Connector page.
Mission Control
See everything your Qwen Code agents do in HackerOne.
When Qwen Code runs a tool in HackerOne, it happens in your editor: you see the result, but not the request itself, what data it carried, or whether a rule was broken.
Now every move lands on your screen.
Every execution is recorded, enforced, and shown to you: what ran, what it returned, what was blocked, and why.
Know exactly what needs your attention before you even look at the charts. One briefing. The full picture. The next move.
AI Agents Activities
last 30 daysRequest Volume & Latency
requests latencyEvery request your Qwen Code agents make through HackerOne is logged, enforced and auditable. See how AI Governance turns agent activity into accountability, and what it means for your HackerOne workflows.
What sets us apart
It's not just the Connector that stays safe. Everything your agents do through it is.
Connecting HackerOne to your AI is step one. But an open line between your agents and HackerOne is only half the story: without protection, every action they take runs unguarded.
That's why protection doesn't stop at the door.
Every action your agents take through the Connector runs inside our infrastructure: signed activity logs, automatic key rotation, spending limits that pause instead of surprise, and a sandbox that isolates every execution.
Tamper Proof Activity Log
Every request your agents make in HackerOne is recorded and signed, so any change to the history becomes detectable.
Automatic Key Rotation
We rotate security keys every 24 hours. Your HackerOne connection stays protected without any manual work.
Spending Protection
We enforce the spending limit you choose and pause actions that exceed it until approval is received. Your HackerOne actions never surprise you.
Isolated Sandbox
Every execution through HackerOne runs isolated, with 34+ security rules covering memory, CPU, network access, file handling and execution.
Security Event Streaming
Security events flow to Splunk, Datadog or your own webhook, so HackerOne activity lands in the tools you already rely on.
Instant Resume
Idle connections resume in 3 to 5 ms while preserving their state, keeping your Qwen Code sessions responsive.
Malicious File Protection
We detect compressed files designed to exhaust system resources and block them before they ever reach HackerOne.
Credential Validation
We test your HackerOne credentials before saving them. Invalid credentials are rejected instead of being stored.
Separate Usage Limits
Usage stays isolated per account, so activity in one connection never consumes another account's allowance.
One Connector, one link, and the whole operation is protected. Not just the connection: everything your agents do through it.
These guarantees are not add-ons: they are the infrastructure every HackerOne connection runs on. Read how our infrastructure protects everything your Qwen Code agents do, end to end.
Inside Vinkius
Get HackerOne ready for your AI. It's easy.
You choose HackerOne from the Vinkius Catalog, sign in to your HackerOne account, and get one connection link. That's it.
You choose HackerOne
You find HackerOne in the Catalog and install the Connector with one click.
HackerOne
Active
Enable ConnectorActivating…You sign in
You connect your HackerOne account and choose what you want your AI to access. Your credentials stay encrypted and separate from your AI.
Configure Credentials
Configure credentials for {{connectorName}}
RequiredEncryptedSave & ContinueYou add the link in Qwen Code
Vinkius gives you one connection link. In Qwen Code, you run one qwen mcp add command with the link as the HTTP URL, and the connection is ready.
Token generated successfully
MCP Connection URL
https://edge.vinkius.com/vk_preview_MdngwsTWgI8aN2tcglppukreOCXiR4XOops4TQFJ/mcpGo to DashboardConnection Token
vk_live_••••••••
Set it up once. Use HackerOne with the AI you already use.
FAQ
Qwen Code access questions.
- 01
Does this work in the Qwen Code chat?
Yes. Run /mcp in the chat to open the MCP dialog and see your server's tools, prompts and resources. If Qwen Code was already running, restart it in the same project.
- 02
If I connect HackerOne to Gemini, can I use the same connection in Claude or ChatGPT later?
Yes, and that's the point: the connection is yours, not Gemini's. You paste the same link in any AI you use, and there's nothing new to set up or pay again. Connect a new AI and HackerOne is already there.
- 03
Do I need to hand my HackerOne password to Gemini?
Never. You sign in once at Vinkius, and we keep your logins encrypted and away from your AI. Gemini only ever sees the link, and you can remove it whenever you want.
- 04
What can I actually ask Gemini to do with HackerOne?
Whatever the Connector covers: check data, run actions and bring answers back. The Connector page lists every capability your AI gains, with real examples you can copy.
- 05
Gemini doesn't show the Connector. What do I check?
Run qwen mcp list or open the /mcp dialog, confirm the url was pasted exactly as copied, and confirm the Connector is active in your Vinkius account. If Qwen Code was already running, restart it in the same project.
- 06
Can I remove the access later?
Run qwen mcp remove and it's out of your sessions. Your Vinkius account keeps the connection and its history either way, ready for the next AI.
More questions about HackerOne? The Connector page answers them. See everything the HackerOne Connector can do
About the Connector
What HackerOne adds to your AI.
Once you connect it, your AI gains 10 capabilities: the exact actions it can take in HackerOne when you ask. The Connector page lists every one of them in detail, alongside the latency we measure in production and prompts worth trying first.
See everything the HackerOne Connector can do