CONNECT APP
Build with HackerOne
Security
- API key
MCP
Give your agent HackerOne tools
Every HackerOne action is exposed as an MCP tool on Pipedream's remote server. Point a client at it with your end user's ID and Connect resolves that user's HackerOne account for each tool call — you store no tokens.
// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
new URL("https://remote.mcp.pipedream.net/v3"),
{
requestInit: {
headers: {
Authorization: `Bearer ${accessToken}`,
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
"x-pd-app-slug": "hackerone",
},
},
},
)
const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)
const { tools } = await mcp.listTools()
// e.g. run Create Group:
const result = await mcp.callTool({
name: "hackerone-create-group",
arguments: {
organizationId: "Organization ID",
name: "Name",
},
})# access_token: mint a short-lived token with the Connect SDK — see the MCP guide
headers = {
"Authorization": f"Bearer {access_token}",
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", # any stable ID for this user in your system
"x-pd-app-slug": "hackerone",
}
async with streamablehttp_client("https://remote.mcp.pipedream.net/v3", headers=headers) as (read, write, _):
async with ClientSession(read, write) as session:
await session.initialize()
tools = await session.list_tools()
# e.g. run Create Group:
result = await session.call_tool("hackerone-create-group", {
"organizationId": "Organization ID",
"name": "Name",
})API PROXY
Call the HackerOne API directly
For an endpoint with no pre-built tool, the Connect proxy forwards your request to the HackerOne API with the connected user's credentials attached. You store no tokens and write no refresh logic.
const resp = await pd.proxy.get({
externalUserId: "{external_user_id}", // any stable ID for this user in your system
accountId: "apn_xxxxxxx",
url: "https://api.hackerone.com/v1/me/organizations",
})
// Any allowed HackerOne endpoint works here. Pipedream attaches the
// connected account's credentials to the outgoing request.# The path segment is the target URL, URL-safe base64 encoded:
# https://api.hackerone.com/v1/me/organizations
curl "https://api.pipedream.com/v1/connect/{project_id}/proxy/aHR0cHM6Ly9hcGkuaGFja2Vyb25lLmNvbS92MS9tZS9vcmdhbml6YXRpb25z?external_user_id={external_user_id}&account_id=apn_xxxxxxx" \
-H "Authorization: Bearer {access_token}" \
-H "x-pd-environment: production"SDK
Run HackerOne actions from your backend
Connect a user's HackerOne account once, then run Create Group on their behalf from your own code — TypeScript, Python, or plain HTTP.
import { PipedreamClient } from "@pipedream/sdk"
const pd = new PipedreamClient({
projectId: process.env.PIPEDREAM_PROJECT_ID!,
clientId: process.env.PIPEDREAM_CLIENT_ID!,
clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
projectEnvironment: "production",
})
const result = await pd.actions.run({
id: "hackerone-create-group",
externalUserId: "{external_user_id}", // any stable ID for this user in your system
configuredProps: {
hackerone: { authProvisionId: "apn_xxxxxxx" },
organizationId: "Organization ID",
name: "Name",
},
})from pipedream import Pipedream
pd = Pipedream(
client_id="{oauth_client_id}",
client_secret="{oauth_client_secret}",
project_id="{project_id}",
project_environment="production",
)
result = pd.actions.run(
id="hackerone-create-group",
external_user_id="{external_user_id}", # any stable ID for this user in your system
configured_props={
"hackerone": {"authProvisionId": "apn_xxxxxxx"},
"organizationId": "Organization ID",
"name": "Name",
},
)curl -X POST https://api.pipedream.com/v1/connect/{project_id}/actions/run \
-H "Content-Type: application/json" \
-H "X-PD-Environment: production" \
-H "Authorization: Bearer {access_token}" \
-d '{
"external_user_id": "{external_user_id}",
"id": "hackerone-create-group",
"configured_props": {
"hackerone": { "authProvisionId": "apn_xxxxxxx" },
"organizationId": "Organization ID",
"name": "Name"
}
}'TOOLS
HackerOne actions
On-demand operations your product or agent can configure and run on behalf of a connected user.
-
Create Group
actionCreate a new organization group. See the documentationWritev0.0.2 -
Create Invitation
actionInvite a recipient to an organization using their email address. See the documentationWritev0.0.2 -
Get Members
actionList all members of an organization. See the documentationRead-onlyv0.0.2 -
List Organization ID Options
actionRetrieves available options for the Organization ID field.Read-onlyv0.0.1
EVENTS
HackerOne triggers
Event sources your backend can deploy for users and receive through a webhook.
No HackerOne triggers are available yet.
MULTI-APP
Use HackerOne with other popular apps
Most products don't stop at one integration. Pair HackerOne with the other apps your users rely on, and ship use cases that span both.
- App slug
- hackerone
- Authentication
- API key
- Categories
- Security
- Actions
- 4
- Triggers
- 0
- API proxy
- Available