Security — entry 015 of 30
HackerOne
HackerOne's API lets bug bounty program customers pull vulnerability reports, manage program and asset data, and issue bounty payouts programmatically, using an API token identifier/value pair sent as HTTP Basic auth credentials. Generating a token requires an active Professional, Community, or Enterprise program -- standard commercial access is sold on custom pricing negotiated with sales, with a free sandbox available to test calls before committing. The only genuinely free path is HackerOne's Community Edition, reserved for qualifying, actively-maintained open-source projects.
AuthenticationAPI KeySign up with the provider to obtain credentials.
HTTPSSupportedTraffic is encrypted in transit.
CORSDisabledBrowser calls need a server-side proxy.
PricingPaidSubscription required — no meaningful free tier.
FormatsJSONResponses can be requested as JSON.
GreatAPIs Score
Score53
Authentication15/25API key required
Pricing9/20Paid API
Docs0/20No docs or spec available
Formats9/15Single response format
Freshness20/20Verified within 6 months
Auth quickstart
- Sign up with the provider to get an API key.
- Send it on every request as a header
Authorization: <key> - The exact header isn't documented — Authorization is a common default; confirm in the provider's docs.
Stored keyNo key stored
Your key is stored only in this browser (localStorage) and sent directly to the API — never to greatapis.