MCP server exposing 3 tools for bug-bounty-programs.
This URL is a JSON-RPC 2.0 endpoint over HTTP. Issue POST requests with a JSON-RPC body. Browsers and search crawlers land here on GET.
POST https://gateway.pipeworx.io/bug-bounty-programs/mcp
Content-Type: application/json
{"jsonrpc":"2.0","id":1,"method":"tools/list"}
bounty_programs_search — Search public bug-bounty program directories on Bugcrowd, YesWeHack and HackerOne — program name, cash bounty range, and status (open/paused/disabled), each sourced from that platform's own public, unauthenticated directory. has_wildcard checks real scope asset identifiers on YesWeHack and HackerOne (Bugcrowd's scope is behind a researcher login and is reported as such, not silently empty).bounty_program — One bug-bounty program by platform + handle: bounty range, status, and scope assets where the platform publishes them without a login. YesWeHack returns a full severity x asset-value reward table; HackerOne returns real scope but no numeric reward table (not exposed publicly); Bugcrowd returns neither (login-walled) and says so.bounty_new_programs — Bug-bounty programs launched in the last N days, by real launch date. Currently HackerOne only — the only one of the three platforms that publishes a `launched_at` field without a login; Bugcrowd and YesWeHack expose no launch-date field at all (confirmed by enumerating their public endpoints), and are named, not silently merged in.Code samples (curl / TypeScript / one-click client install), schemas, and the live playground are on the pack page:
https://pipeworx.io/packs/bug-bounty-programs/
Pipeworx is an open MCP gateway connecting AI agents to live data. pipeworx.io