Browse documentation
bbradar guide

bbradar documentation

Explore the free bug bounty catalog, compare Pro features, set up alerts and API access, and understand program and target data.

2 min readReviewed Read as Markdown
On this page

Use the public catalog to discover programs and compare their published details. Pro adds the target data, personal alerts, and developer tools used by the guides below.

Task
Find programs
Free access
Browse platform listings, rewards, tags, program pages, and official policy links.
With Pro
Add target-aware search, opportunity signals, report counts, and submission costs.
Task
Understand scope activity
Free access
See aggregate target counts and redacted examples of recent changes.
With Pro
Read full target identities, eligibility, target changes, and supported repository events.
Task
Find direct programs
Free access
Read the Self-Hosted guide and feature explanation.
With Pro
Browse verified Self-Hosted paid programs and optional VDPs.
Task
Receive alerts or use data in tools
Free access
Review the public setup guides and API reference.
With Pro
Connect personal Telegram alerts, shared Discord access, the Pro API, and local MCP.

Start with the account checklist. It takes you from active Pro access to a working alert channel and, if you need automation, a Pro API key.

  1. Open your account

    Sign in with Google and confirm the Pro badge appears in Account & Billing.
  2. Choose an alert channel

    Connect Telegram for personal filtered alerts, Discord for shared Pro server access, or both.
  3. Review notification rules

    Select the events you want. Repository changes are opt-in, so enable that stream explicitly.
  4. Create an API key if needed

    Use one key for the Pro API and the local @bbradar/mcp server.
Sanitized product view
Account setup checklist with Pro access active. Example data and credentials are fictional or redacted; named product controls match the interface.
  • Target-aware catalog search
  • Verified Self-Hosted paid programs and VDPs
  • Full active target identities
  • Program and target opportunity signals
  • Latest target-change feed
  • Multi-provider repository-change feed
  • Personal Telegram rules
  • Discord Pro role
  • Pro API and local MCP access
Term
Bug bounty and VDP
Meaning
A paid program advertises a monetary reward, which may have no published amount. A vulnerability disclosure policy (VDP) has no confirmed monetary reward.
Term
Self-Hosted
Meaning
A security program run directly by an organization. Admission uses first-party program evidence; the linked current policy controls scope and permission.
Term
Program opportunity
Meaning
A comparative program tier based on available freshness, public report activity, rewards, and scope evidence.
Term
Target Intelligence
Meaning
A target score, label, factor breakdown, and dupe-risk context, when the source supports those signals.
Term
Dupe risk
Meaning
An estimate of visible crowding, not a measured probability of a duplicate report. Unknown means evidence is insufficient.
Term
Paused program
Meaning
A confirmed paused platform listing remains browsable. Retained scope and rewards describe previously published information; current bounty eligibility is disabled.
Term
Latest changes
Meaning
Retained observations of material target changes. The feed is not a complete immutable history, and its first observation is distinct from a new upstream launch.
Term
Repository baseline
Meaning
The first observed ref/SHA is a silent starting point. Later supported branch updates can appear in the Commits feed.
How the signals are producedRead the evidence, freshness, and coverage limits behind the labels.

: the API reference now describes paused programs, optional inventory queries, stable snapshots, expiry recovery, and current field types. The MCP guide confirms repository-feed support in version 0.2.3 and identifies remaining HTTP API capabilities.

These are documentation review notes, not program discovery dates or promises of source freshness. Check the authenticated capabilities response and the installed MCP guide for the contract your client uses.