Security — entry 015 of 30

HackerOne

Verified Jul 2026

HackerOne's API lets bug bounty program customers pull vulnerability reports, manage program and asset data, and issue bounty payouts programmatically, using an API token identifier/value pair sent as HTTP Basic auth credentials. Generating a token requires an active Professional, Community, or Enterprise program -- standard commercial access is sold on custom pricing negotiated with sales, with a free sandbox available to test calls before committing. The only genuinely free path is HackerOne's Community Edition, reserved for qualifying, actively-maintained open-source projects.

bug-bountyvulnerability-disclosurecrowdsourced-securitypenetration-testingsecurity-programs
AuthenticationAPI KeySign up with the provider to obtain credentials.
HTTPSSupportedTraffic is encrypted in transit.
CORSDisabledBrowser calls need a server-side proxy.
PricingPaidSubscription required — no meaningful free tier.
FormatsJSONResponses can be requested as JSON.

GreatAPIs Score

Score53out of 100
Authentication15/25API key required
Pricing9/20Paid API
Docs0/20No docs or spec available
Formats9/15Single response format
Freshness20/20Verified within 6 months

Embed this badge

Scored 53 on greatapis.com
<a href="https://greatapis.com/api/hackerone/"><img src="https://greatapis.com/badge/hackerone.svg" alt="Scored 53 on greatapis.com"></a>

Auth quickstart

  1. Sign up with the provider to get an API key.
  2. Send it on every request as a headerAuthorization: <key>
  3. The exact header isn't documented — Authorization is a common default; confirm in the provider's docs.
Stored keyNo key stored

Your key is stored only in this browser (localStorage) and sent directly to the API — never to greatapis.