Browse documentation
bbradar guide

Frequently asked questions

Answers about supported programs, catalog freshness, Self-Hosted programs, Pro features, opportunity signals, alerts, API and MCP access, billing, and account setup.

10 min readReviewed Read as Markdown
On this page

Questions and answers

HackZar coverage includes public program profiles, reward ranges or recognition-only VDP status, scope targets, and total report counts where available. Enable Include VDPs to see recognition-only programs. Pro users can inspect targets and report counts and select HackZar in Notification Rules. Catalog dates use the Created date published on each program page. When that date is unavailable, a conservative estimate is used.

We check listings throughout the day. Update times vary by platform and depend on source availability, rate limits, and successful verification. Incomplete checks preserve existing listings.

BBRadar is a tracker, not a submission platform. Open each program and submit your report directly on the program’s platform page. We link to the official program URL for every listing.

BBRadar.io focuses on publicly available programs. Private or invite‑only programs are not listed.

Yes. Use the “Sort by” control above the listings to sort by date (newest/oldest), name (A–Z/Z–A), and by maximum or minimum bounty. Pro users can also sort by report count or submission cost. Programs without a detected submission cost are currently treated as free.

Yes, with Pro. When a platform publishes this data, bbradar shows the program’s submission fee or deposit in program listings, program details, Latest Targets, and Pro API responses. The Free submission fee only toggle works together with the other listing and Latest Targets filters. Money is displayed with a $ prefix, while non-cash systems such as YesWeHack are shown in credits. If no submission cost is detected, the program is currently shown as Free. Only positive costs are added to program, lifecycle, and target-change notifications.

We check sources throughout the day. A program appears after its source data has been retrieved, validated, and saved. Source outages, rate limits, and verification can delay publication.

The platform has confirmed that the program is paused. Its listing remains available for reference, with previously published rewards and scope. Current bounty eligibility and active opportunity signals are disabled while paused. Check the official policy before choosing work; retained targets do not establish current permission to test.

The Self-Hosted Pro catalog makes security programs run directly by organizations easy to find alongside the main platform catalog. It brings each program’s rewards, scope, policy, and reporting route into one profile, shows paid bounties first, and lets you include VDPs when you want broader disclosure coverage. Always review the linked official policy before testing.

Latest Targets helps you follow confirmed scope additions, re-additions, updates, and removals. The Commits tab shows supported repository branch updates connected to bounty targets. Use these feeds to spot activity, then open the linked official scope or repository provider before acting.

They are Pro research signals that help you compare programs and targets. Program opportunity tiers highlight promising listings, while each target can include a score, label, factor breakdown, and dupe-risk context. Use them to prioritize research, not as a guarantee of payout, exploitability, or a duplicate-free report.

Pro includes:
  • Live program notifications.
  • A separate verified Self-Hosted paid-program and VDP catalog with reward ranges, reporting routes, tags, and structured scope.
  • Separate Telegram streams for new Self-Hosted bounties and VDPs.
  • Live target change notifications.
  • Repository-change alerts for supported GitHub and Gists, GitLab, Bitbucket, Gitea, Forgejo, SourceHut, and HTTPS Git hosts, with direct provider links.
  • Private Telegram DM delivery for personal alerts.
  • Program opportunity tiers plus target scores, labels, factor breakdowns, and dupe-risk context.
  • Platform-reported submission fees or deposits in listings, program details, Latest Targets, API responses, and positive-cost alerts, plus cost sorting.
  • Notification rules for streams, opportunity signals, platforms, scope tags, languages, rewards, programs, and targets.
  • Opportunity filters for Elite, Hot, Strong, and Potential programs.
  • Upcoming program visibility for future-dated launches.
  • Full program targets with eligibility details.
  • Pro API access with API key generation, regeneration, and revoke controls.
  • Local MCP server access through the @bbradar/mcp npm package.

When a bounty target links to a supported repository and branch, later updates can appear in the Commits feed.

  • The first observation establishes a starting point and does not create an alert.
  • Later branch changes can appear under the Commits tab.
  • Discord and opted-in Telegram notifications are grouped into hourly digests.
  • Digest entries open the source provider's comparison, commit, or repository view.
  • A confirmed scope match has supporting evidence. An unverified scope impact means the repository changed but the available comparison could not establish whether the scoped files changed.
  • Historical events without recorded evidence quality are labelled as unknown.
  • bbradar does not retain code, patches, filenames, or commit messages.

Yes. Pro users can run the @bbradar/mcp npm package as a local STDIO MCP server for compatible AI clients.

  • Requires Node.js 20 or newer and a bbradar Pro API key.
  • Most clients can run it with npx -y @bbradar/mcp.
  • Add your key as BBRADAR_API_KEY in the MCP client environment.

No. The Pro API covers platform and Self-Hosted program profiles, active target inventories, platform opportunity data, target intelligence, platform target changes, and minimal platform repository-change events. Self-Hosted responses explicitly mark unavailable signals instead of inventing opportunity scores, report counts, target-change history, submission costs, or repository changes. Repository events are available through the website, read-only Pro API, and supported notifications; MCP 0.2.3 also exposes get_repository_changes with compact program summaries and incremental polling. Snapshot parameters and some newer provenance fields remain HTTP API capabilities.

Yes. Pro users can manage notification rules for platform program, Self-Hosted paid/VDP, target, and repository-change streams plus program opportunity tiers, target scores and labels, dupe risk, platforms, scope tags, languages, bounty ranges, free or paid submission fees with an optional maximum, target changes, and specific programs or targets.

Monthly and yearly Pro plans include the same current features. Stripe handles checkout, invoices, payment methods, and cancellation. If you cancel, Pro normally remains available until the end of the period you already paid for; use Account & Billing to manage the subscription and confirm its current status.