Security — entry 015 of 30
HackerOne
HackerOne's API lets bug bounty program customers pull vulnerability reports, manage program and asset data, and issue bounty payouts programmatically, using an API token identifier/value pair sent as HTTP Basic auth credentials. Generating a token requires an active Professional, Community, or Enterprise program -- standard commercial access is sold on custom pricing negotiated with sales, with a free sandbox available to test calls before committing. The only genuinely free path is HackerOne's Community Edition, reserved for qualifying, actively-maintained open-source projects.
GreatAPIs Score
Auth quickstart
- Sign up with the provider to get an API key.
- Send it on every request as a header
Authorization: <key> - The exact header isn't documented — Authorization is a common default; confirm in the provider's docs.
Your key is stored only in this browser (localStorage) and sent directly to the API — never to greatapis.
Developer reference
Read: 600 requests/minute (300/min for report pages); Write: 25 requests per 20 seconds; billing transactions endpoint: 10 requests/minute