Frequently Asked Questions

    Quick answers about BBRadar.io: supported platforms, update frequency, Pro alerts, Telegram delivery, notification rules, MCP setup, and searching for programs.

    Which bug bounty platforms are supported on BBRadar.io?

    We aggregate programs from major platforms including HackerOneBugCrowdIntigritiImmunefiHackenProofYesWeHackStandoff365BI.ZONECode4renaSherlockCodeHawksCantinaBugbaseBugRapIssueHuntInspectivBug Bounty SwitzerlandAuditOneCertiKHuntrRemedyCompass SecurityGObugfreePatchDay We keep expanding as new platforms emerge.

    How often are programs updated?

    Listings are refreshed frequently throughout the day. New public programs usually appear on BBRadar.io within minutes of being published on the source platform.

    How do I submit a bug to a program?

    BBRadar is a tracker, not a submission platform. Open each program and submit your report directly on the program’s platform page. We link to the official program URL for every listing.

    How can I find mobile or web3 bug bounty programs?

    Use tags and filters: try the mobile tag for mobile targets, or the smart contract tag for web3. You can also use the search bar to filter by keywords.

    Are all programs public?

    BBRadar.io focuses on publicly available programs. Private or invite‑only programs are not listed.

    Can I sort programs by rewards or alphabetically?

    Yes. Use the “Sort by” control above the listings to sort by date (newest/oldest), name (A–Z/Z–A), and by maximum or minimum bounty. Pro users can also sort by report count or submission cost. Programs without a detected submission cost are currently treated as free.

    Can I see whether a program charges to submit a report?

    Yes, with Pro. When a platform publishes this data, bbradar shows the program’s submission fee or deposit in program listings, program details, Latest Targets, and Pro API responses. The Free submission fee only toggle works together with the other listing and Latest Targets filters. Money is displayed with a $ prefix, while non-cash systems such as YesWeHack are shown in credits. If no submission cost is detected, the program is currently shown as Free. Only positive costs are added to program, lifecycle, and target-change notifications.

    How fresh are the “Latest” programs?

    We poll and refresh throughout the day. When new public programs go live on their platforms, they typically appear on BBRadar.io within minutes.

    What does Pro include?

    Pro includes:
    • Live program notifications.
    • Live target change notifications.
    • Repository-change alerts for GitHub and Gists, GitLab, Bitbucket, Gitea, allowlisted Forgejo, SourceHut, and trusted generic Git hosts, with direct provider links.
    • Private Telegram DM delivery for personal alerts.
    • Program opportunity tiers plus target scores, labels, factor breakdowns, and dupe-risk context.
    • Platform-reported submission fees or deposits in listings, program details, Latest Targets, API responses, and positive-cost alerts, plus cost sorting.
    • Notification rules for streams, opportunity signals, platforms, scope tags, languages, rewards, programs, and targets.
    • Opportunity filters for Elite, Hot, Strong, and Potential programs.
    • Upcoming program visibility for future-dated launches.
    • Full program targets with eligibility details.
    • Pro API access with API key generation, regeneration, and revoke controls.
    • Local MCP server access through the @bbradar/mcp npm package.

    How do repository change alerts work?

    bbradar detects supported repositories referenced by bug bounty scope and monitors supported branches separately from platform ingestion.

    • The first observation creates a silent baseline, so deployment does not generate an alert storm.
    • Later branch changes can appear under the Commits tab.
    • Repository alerts use stable staggered slots, avoiding a top-of-hour notification burst.
    • Repeated changes to the same repository and branch coalesce into at most one hourly Discord or opt-in Telegram digest slot.
    • Digest entries open the source provider's comparison, commit, or repository view.
    • bbradar does not copy or store code, patches, filenames, or commit messages.

    Does bbradar Pro include an MCP server?

    Yes. Pro users can run the @bbradar/mcp npm package as a local STDIO MCP server for compatible AI clients.

    • Requires Node.js 20 or newer and a bbradar Pro API key.
    • Most clients can run it with npx -y @bbradar/mcp.
    • Add your key as BBRADAR_API_KEY in the MCP client environment.

    Where do I manage my Pro API key and endpoints?

    Go to Account & Billing to create, regenerate, or delete your API key. Then open Pro API Docs for endpoint details and cURL examples.

    Can I customize which Pro notifications I receive?

    Yes. Pro users can manage notification rules for program, target, and repository-change streams plus program opportunity tiers, target scores and labels, dupe risk, platforms, scope tags, languages, bounty ranges, free or paid submission fees with an optional maximum, target changes, and specific programs or targets.

    Where do Pro notifications appear?

    Notifications can be delivered to your private Telegram DM and the Pro Discord channels after you connect your account. You can also browse Latest Targets and Commits on the site.

    How do I enable Pro notifications?

    Subscribe to Pro, then use Account & Billing to connect Telegram for private DM alerts and connect Discord for server channel access. Then open Notification Rules to choose which alerts you want.

    Can Telegram alerts be sent to groups or shared channels?

    No. Telegram delivery is limited to private 1:1 DMs connected from the Pro user account, so alerts stay personal and tied to active Pro access.

    How do I request a platform or program to be added?

    Use the “Get Listed” page to contact us. We welcome requests from platforms and maintainers of public programs.

    Is BBRadar.io affiliated with any platform?

    No. We are an independent aggregator. Each program remains owned and managed by its respective platform or organization.