@bountylens/mcp
OfficialEnables managing bug bounty hunt sessions, findings, leads, and reports for Bugcrowd programs through the BountyLens platform.
Enables managing bug bounty hunt sessions, findings, leads, and reports for Intigriti programs through the BountyLens platform.
Supports tracking and managing hunt sessions, findings, and reports for Shopify's bug bounty program via BountyLens.
Supports tracking and managing hunt sessions, findings, and reports for Uber's bug bounty program via BountyLens.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@@bountylens/mcpSave the XSS on /search to my current session"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
@bountylens/mcp
MCP server for BountyLens — connect Claude Code to your Hunter Tracker.
Push findings, leads, tested endpoints, and full report drafts directly from your terminal to the BountyLens dashboard. Search across all sessions, get program intelligence, and track your hunt stats — all without leaving the terminal. Everything you log appears in real-time in the web UI with an MCP badge.
Quick Start
1. Get an API key
Go to bountylens.com/dashboard/settings → Integrations → Generate New API Key.
Copy the key — it's only shown once.
2. Add to Claude Code
Add to your MCP config at ~/.claude/.mcp.json:
{
"mcpServers": {
"bountylens": {
"command": "npx",
"args": ["-y", "@bountylens/mcp"],
"env": {
"BOUNTYLENS_API_KEY": "bl_your_key_here"
}
}
}
}3. Restart Claude Code
The BountyLens tools will be available immediately. No other setup needed.
Related MCP server: MCP Intigriti Server
Tools (23)
Sessions
Tool | Description |
| List hunt sessions — filter by |
| Start a new hunt session with a title and optional program (by ID or handle) |
| Get a session with all its entries and counts |
| Update title, status, or notes |
| Permanently delete a session and all its entries and reports |
Entries
All entry tools support the Tracker Pro fields: tags (lowercase, max 10), chain_id (link to another entry in the same session to build exploit chains), and retest_at (ISO-8601 timestamp → retest queue).
Tool | Description |
| List entries in a session — filter by |
| Log a validated finding with severity, endpoint, method, description, |
| Log a promising lead — supports |
| Mark an endpoint or feature as tested — supports |
| Add a freeform note to the session — supports |
| Update title, description, status, severity, type, endpoint, method, |
| Remove an entry |
| Add up to 50 entries in one call — each item supports |
Tag conventions: vuln:<class> (vuln:idor, vuln:ssrf…), surface:<type> (web, api, graphql, mobile, cloud-aws…), src:<origin> (src:hack, src:pentest), platform:<name> (h1, synack, bugcrowd, intigriti, ywh). Don't tag severity or status — those are first-class fields.
Reports
Tool | Description |
| Create a report draft — include summary, steps to reproduce, impact, and remediation |
| List all report drafts in a session |
| Edit a report's title, body, severity, or status — lifecycle (draft/ready/submitted) or closed outcome (resolved/duplicate/informative/not_applicable) |
| Permanently delete a report |
Search
Tool | Description |
| Search across ALL sessions for entries matching a query — finds past findings, leads, or tested endpoints without knowing which session they're in |
Programs
Tool | Description |
| Search bug bounty programs by name or handle |
| Get full program details — bounties, dupe risk, health score, scope list, and recent scope changes |
Intelligence
Tool | Description |
| Get program recommendations ranked by opportunity score — filter by platform or minimum bounty |
| Get your watched programs with metrics — bounties, dupe risk, health, scope changes, and session count |
| Get your hunt statistics — sessions, findings, leads, tested endpoints, time spent, and per-program breakdown |
Usage Examples
During a hunt in Claude Code, the LLM uses these tools automatically based on your instructions:
"List my active sessions"
→ bountylens_list_sessions with status=active
"Save this XSS finding to my Shopify session"
→ bountylens_add_finding with title, severity, endpoint, description
"What leads do I have open on the Uber hunt?"
→ bountylens_list_entries with type=lead
"Mark /api/auth as tested, CSRF tokens are present"
→ bountylens_add_tested with endpoint and description
"Have I tested SSRF on any target before?"
→ bountylens_search_entries with query="SSRF"
"What's the scope for Shopify's program?"
→ bountylens_get_program with handle="shopify"
"What should I hunt next?"
→ bountylens_recommend_programs with min_bounty=1000
"How much time have I spent hunting this month?"
→ bountylens_get_my_stats
"Draft a report for the SSRF finding"
→ bountylens_draft_report with full report body
"Push reports/ssrf-uber.md to my Uber session"
→ reads the file, calls bountylens_draft_report with contentsEnvironment Variables
Variable | Required | Default | Description |
| Yes | — | API key from dashboard settings |
| No |
| Custom instance URL (self-hosted) |
API Reference
The MCP server wraps the BountyLens API v1. All endpoints require a Bearer token in the Authorization header.
GET /api/v1/sessions — list sessions
POST /api/v1/sessions — create session
GET /api/v1/sessions/:id — get session + entries
PUT /api/v1/sessions/:id — update session
DELETE /api/v1/sessions/:id — delete session
GET /api/v1/sessions/:id/entries — list entries
POST /api/v1/sessions/:id/entries — create entry
POST /api/v1/sessions/:id/entries/bulk — bulk create entries (max 50)
PUT /api/v1/sessions/:id/entries/:entryId — update entry
DELETE /api/v1/sessions/:id/entries/:entryId — delete entry
GET /api/v1/sessions/:id/reports — list reports
POST /api/v1/sessions/:id/reports — create report
PUT /api/v1/sessions/:id/reports/:reportId — update report
DELETE /api/v1/sessions/:id/reports/:reportId — delete report
GET /api/v1/search?q=query — search entries across all sessions
GET /api/v1/programs?q=search — search programs
GET /api/v1/programs/:handle — get program details
GET /api/v1/recommend — get program recommendations
GET /api/v1/watchlist — get watched programs
GET /api/v1/stats — get hunt statisticsRate limit: 60 requests/minute per API key.
Security
API keys are SHA-256 hashed in the database — never stored in plaintext
Keys are shown once on creation and cannot be retrieved
All queries are parameterized — no SQL injection
Every request verifies resource ownership — no IDOR
Pro subscription is validated on every API call
Rate limited to prevent abuse
Requirements
Node.js 18+
BountyLens Pro subscription
API key from the dashboard
Contributing
We welcome contributions. See CONTRIBUTING.md for guidelines.
License
MIT — see LICENSE
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseAqualityFmaintenanceProvides Claude Code with access to a comprehensive bug bounty knowledge base including techniques, payloads, wordlists, and real-world reports through 14 tools for searching, retrieving payloads, and assessing report quality.Last updated1416GPL 3.0
- Flicense-qualityDmaintenanceEnables security researchers to interact with Intigriti's bug bounty platform through Claude Desktop, providing access to programs, scope, activities, and rules of engagement via natural language.Last updated1

theLeadRouter MCPofficial
Alicense-qualityDmaintenanceConnects Claude Code to the theLeadRouter lead routing platform, enabling lead management, routing, and reporting via API.Last updated111MIT- FlicenseAqualityBmaintenanceA local, read-only MCP server that connects your HackerOne researcher account to Claude Desktop and Claude Code, helping you find targets, analyze program scopes, review reports and earnings, and draft bug reports.Last updated175
Related MCP Connectors
Connect Claude to Fathom meeting recordings, transcripts, and summaries
Persistent context for Claude. Your AI always knows your projects and next actions across sessions.
WHOOP recovery, strain, sleep and workouts in Claude via official WHOOP OAuth. Free, open source.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/bountylens/mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server