Browse documentation
bbradar documentation
Explore the free bug bounty catalog, compare Pro features, set up alerts and API access, and understand program and target data.
On this page
Use the public catalog to discover programs and compare their published details. Pro adds the target data, personal alerts, and developer tools used by the guides below.
- Task
- Find programs
- Free access
- Browse platform listings, rewards, tags, program pages, and official policy links.
- With Pro
- Add target-aware search, opportunity signals, report counts, and submission costs.
- Task
- Understand scope activity
- Free access
- See aggregate target counts and redacted examples of recent changes.
- With Pro
- Read full target identities, eligibility, target changes, and supported repository events.
- Task
- Find direct programs
- Free access
- Read the Self-Hosted guide and feature explanation.
- With Pro
- Browse verified Self-Hosted paid programs and optional VDPs.
- Task
- Receive alerts or use data in tools
- Free access
- Review the public setup guides and API reference.
- With Pro
- Connect personal Telegram alerts, shared Discord access, the Pro API, and local MCP.
| Task | Free access | With Pro |
|---|---|---|
| Find programs | Browse platform listings, rewards, tags, program pages, and official policy links. | Add target-aware search, opportunity signals, report counts, and submission costs. |
| Understand scope activity | See aggregate target counts and redacted examples of recent changes. | Read full target identities, eligibility, target changes, and supported repository events. |
| Find direct programs | Read the Self-Hosted guide and feature explanation. | Browse verified Self-Hosted paid programs and optional VDPs. |
| Receive alerts or use data in tools | Review the public setup guides and API reference. | Connect personal Telegram alerts, shared Discord access, the Pro API, and local MCP. |
Start with the account checklist. It takes you from active Pro access to a working alert channel and, if you need automation, a Pro API key.
Open your account
Sign in with Google and confirm the Pro badge appears in Account & Billing.Choose an alert channel
Connect Telegram for personal filtered alerts, Discord for shared Pro server access, or both.Review notification rules
Select the events you want. Repository changes are opt-in, so enable that stream explicitly.Create an API key if needed
Use one key for the Pro API and the local@bbradar/mcpserver.
Account & Billing
Set up your Pro workspace
- Target-aware catalog search
- Verified Self-Hosted paid programs and VDPs
- Full active target identities
- Program and target opportunity signals
- Latest target-change feed
- Multi-provider repository-change feed
- Personal Telegram rules
- Discord Pro role
- Pro API and local MCP access
- Term
- Bug bounty and VDP
- Meaning
- A paid program advertises a monetary reward, which may have no published amount. A vulnerability disclosure policy (VDP) has no confirmed monetary reward.
- Term
- Self-Hosted
- Meaning
- A security program run directly by an organization. Admission uses first-party program evidence; the linked current policy controls scope and permission.
- Term
- Program opportunity
- Meaning
- A comparative program tier based on available freshness, public report activity, rewards, and scope evidence.
- Term
- Target Intelligence
- Meaning
- A target score, label, factor breakdown, and dupe-risk context, when the source supports those signals.
- Term
- Dupe risk
- Meaning
- An estimate of visible crowding, not a measured probability of a duplicate report. Unknown means evidence is insufficient.
- Term
- Paused program
- Meaning
- A confirmed paused platform listing remains browsable. Retained scope and rewards describe previously published information; current bounty eligibility is disabled.
- Term
- Latest changes
- Meaning
- Retained observations of material target changes. The feed is not a complete immutable history, and its first observation is distinct from a new upstream launch.
- Term
- Repository baseline
- Meaning
- The first observed ref/SHA is a silent starting point. Later supported branch updates can appear in the Commits feed.
| Term | Meaning |
|---|---|
| Bug bounty and VDP | A paid program advertises a monetary reward, which may have no published amount. A vulnerability disclosure policy (VDP) has no confirmed monetary reward. |
| Self-Hosted | A security program run directly by an organization. Admission uses first-party program evidence; the linked current policy controls scope and permission. |
| Program opportunity | A comparative program tier based on available freshness, public report activity, rewards, and scope evidence. |
| Target Intelligence | A target score, label, factor breakdown, and dupe-risk context, when the source supports those signals. |
| Dupe risk | An estimate of visible crowding, not a measured probability of a duplicate report. Unknown means evidence is insufficient. |
| Paused program | A confirmed paused platform listing remains browsable. Retained scope and rewards describe previously published information; current bounty eligibility is disabled. |
| Latest changes | Retained observations of material target changes. The feed is not a complete immutable history, and its first observation is distinct from a new upstream launch. |
| Repository baseline | The first observed ref/SHA is a silent starting point. Later supported branch updates can appear in the Commits feed. |
: the API reference now describes paused programs, optional inventory queries, stable snapshots, expiry recovery, and current field types. The MCP guide confirms repository-feed support in version 0.2.3 and identifies remaining HTTP API capabilities.
These are documentation review notes, not program discovery dates or promises of source freshness. Check the authenticated capabilities response and the installed MCP guide for the contract your client uses.
