Browse documentation
Frequently asked questions
Answers about bug bounty programs, activity labels, sorting, program History, audit contests, Pro features, alerts and billing.
On this page
Questions and answers
We aggregate programs from major platforms including HackerOneBugCrowdIntigritiImmunefiHackenProofYesWeHackStandoff365BI.ZONECode4renaSherlockCodeHawksCantinaBugbaseBugRapIssueHuntInspectivBug Bounty SwitzerlandAuditOneCertiKHuntrRemedyCompass SecurityGObugfreePatchDayHackZar We keep expanding as new platforms emerge.
Open the free Web3 audit contest calendar to compare smart contract competitions and security challenges by platform, language, published reward and UTC schedule. Available ICS downloads are free. Full program scope, target inventory and program intelligence require Pro. The contest calendar guide explains filters, dates and exports.
BBRadar updates a schedule after the source data has been retrieved, checked and saved. A recently announced or changed deadline can appear on the official page first. Dates to confirm means the calendar does not yet have a complete, consistent verified schedule; it does not prove the platform has no deadline. Date-only deadlines remain labeled without an invented closing time. Check the official contest page for the latest schedule.
HackZar coverage includes public program profiles, reward ranges or recognition-only VDP status, scope targets, and total report counts where available. Enable Include VDPs to see recognition-only programs. Pro users can inspect targets and report counts and select HackZar in Notification Rules. Catalog dates use the Created date published on each program page. When that date is unavailable, a conservative estimate is used.
We check listings throughout the day. Update times vary by platform and depend on source availability, rate limits, and successful verification. Incomplete checks preserve existing listings.
BBRadar is a tracker, not a submission platform. Open each program and submit your report directly on the program’s platform page. We link to the official program URL for every listing.
Use tags and filters: try the mobile tag for mobile targets, or the smart contract tag for web3. You can also use the search bar to filter by keywords.
BBRadar.io focuses on publicly available programs. Private or invite‑only programs are not listed.
Sort by date or bounty to find new programs and compare rewards. Pro adds Recently updated, Most active (30 days), and Largest scope change (7 days), so you can put changing programs first. You can also sort by report count or submission cost with Pro.
Pro activity labels help you spot what deserves another look: expanded or reduced scope, higher or lower rewards, large scope changes, high activity, and recent updates. See them in program listings and on program details. Hover over a listing label for a quick explanation, or click it to open the program’s History.
With Pro, the report count badge brings report volume and dupe risk together. Its color and icon show the dupe-risk level when available; hover over it to see the label. This helps you compare how crowded programs may be while browsing.
Yes, with Pro. When a platform publishes this data, bbradar shows the program’s submission fee or deposit in program listings, program details, Latest Targets, and Pro API responses. The Free submission fee only toggle works together with the other listing and Latest Targets filters. Money is displayed with a $ prefix, while non-cash systems such as YesWeHack are shown in credits. If no submission cost is detected, the program is currently shown as Free. Only positive costs are added to program, lifecycle, and target-change notifications.
We check sources throughout the day. A program appears after its source data has been retrieved, validated, and saved. Source outages, rate limits, and verification can delay publication.
The platform has confirmed that the program is paused. Its listing remains available for reference, with previously published rewards and scope. Current bounty eligibility and active opportunity signals are disabled while paused. Check the official policy before choosing work; retained targets do not establish current permission to test.
The Self-Hosted Pro catalog brings programs run directly by organizations into one searchable place. Compare their published rewards, scope and reporting routes, then use History to follow recorded changes. Always check the linked official policy before testing.
Latest Targets helps you follow confirmed scope additions, re-additions, updates, and removals. The Commits tab shows supported repository branch updates connected to bounty targets. Use these feeds to spot activity, then open the linked official scope or repository provider before acting.
Start with Overview for key program information, a scope summary, and the latest changes. Open Targets to explore the scope, or History to compare changes over time. Pro unlocks the full target list, change details, and activity labels.
Open a program and choose History. With Pro, you can follow scope, rewards, policy, and repository updates in one timeline. Filter by date or change type, then open an update to see the details. Explore Program History.
Yes. Open an update in History to compare before and after details, see added or removed targets, and follow source links. It is a quick way to review a program before returning to your research.
Yes. Use the History filters to choose Scope, Rewards, Rules & policy, Program, or Repositories. Combine a category with a date range to find the updates that matter to your work.
Try All history and All events to see all available updates for that program.
No. History lets you browse a program’s updates whenever you need them. Choose the alerts you want separately in Notification Rules.
They are Pro research signals that help you compare programs and targets. Program opportunity tiers highlight promising listings, while each target can include a score, label, factor breakdown, and dupe-risk context. Use them to prioritize research, not as a guarantee of payout, exploitability, or a duplicate-free report.
- Activity labels for scope changes, reward changes, and active programs.
- Sorting by recent updates, most active programs, and largest scope changes.
- Program History with before and after details for scope, rewards, policy, and repository updates.
- Full program targets with eligibility details.
- Report counts with dupe-risk colors and icons for a quick comparison.
- Submission fees, cost sorting, and a free-submission filter.
- Program opportunity tiers and target intelligence to help build your shortlist.
- The verified Self-Hosted catalog for programs run directly by organizations.
- Program, target, and repository-change alerts through private Telegram messages and Pro Discord channels.
- Personal notification rules for the programs and changes you care about.
- Upcoming programs to plan your next research session.
- Pro API access and the
@bbradar/mcpserver for your own tools.
When a bounty target links to a supported repository and branch, later updates can appear in the Commits feed.
- The first observation establishes a starting point and does not create an alert.
- Later branch changes can appear under the Commits tab.
- Discord and opted-in Telegram notifications are grouped into hourly digests.
- Digest entries open the source provider's comparison, commit, or repository view.
- A confirmed scope match has supporting evidence. An unverified scope impact means the repository changed but the available comparison could not establish whether the scoped files changed.
- Historical events without recorded evidence quality are labelled as unknown.
- bbradar does not retain code, patches, filenames, or commit messages.
Yes. Pro users can run the @bbradar/mcp npm package as a local STDIO MCP server for compatible AI clients.
- Requires Node.js 20 or newer and a bbradar Pro API key.
- Most clients can run it with
npx -y @bbradar/mcp. - Add your key as
BBRADAR_API_KEYin the MCP client environment.
No. The Pro API covers platform and Self-Hosted program profiles, active target inventories, platform opportunity data, target intelligence, platform target changes, and minimal platform repository-change events. Self-Hosted responses explicitly mark unavailable signals instead of inventing opportunity scores, report counts, target-change feeds, submission costs, or repository changes. Repository events are available through the website, read-only Pro API, and supported notifications; MCP 0.2.3 also exposes get_repository_changes with compact program summaries and incremental polling. Snapshot parameters and some newer provenance fields remain HTTP API capabilities. The per-program History timeline currently requires a signed-in Pro browser session and is not included in API key endpoints or MCP tools.
Go to Account & Billing to create, regenerate, or delete your API key. Then open Pro API reference for endpoint details and cURL examples.
Yes. Pro users can manage notification rules for platform program, Self-Hosted paid/VDP, target, and repository-change streams plus program opportunity tiers, target scores and labels, dupe risk, platforms, scope tags, languages, bounty ranges, free or paid submission fees with an optional maximum, target changes, and specific programs or targets.
Notifications can be delivered to your private Telegram DM and the Pro Discord channels after you connect your account. You can also browse Latest Targets and Commits on the site.
Subscribe to Pro, then use Account & Billing to connect Telegram for private DM alerts and connect Discord for server channel access. Then open Notification Rules to choose which alerts you want.
No. Telegram delivery is limited to private 1:1 DMs connected from the Pro user account, so alerts stay personal and tied to active Pro access.
Monthly and yearly Pro plans include the same current features. Stripe handles checkout, invoices, and payment methods. Cancel from Account & Billing: paid access lasts through the paid period, while a past-due subscription ends immediately and automatic invoice retries stop. An unpaid invoice can remain open for separate review.
Email [email protected] for private account or billing questions. Include the page URL, approximate time, and visible status. Keep credentials, connection links, payment details, and session cookies out of the message. The troubleshooting guide lists useful support context.
Use the “Get Listed” page to contact us. We welcome requests from platforms and maintainers of public programs.
No. We are an independent aggregator. Each program remains owned and managed by its respective platform or organization.
