HackerOne icon

CONNECT APP

Build with HackerOne

Attack Resistance Platform combines the most creative human intelligence with the latest artificial intelligence to reduce threat exposure at all stages of the software development lifecycle.

Security

  • API key

MCP

Give your agent HackerOne tools

Every HackerOne action is exposed as an MCP tool on Pipedream's remote server. Point a client at it with your end user's ID and Connect resolves that user's HackerOne account for each tool call — you store no tokens.

// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
  new URL("https://remote.mcp.pipedream.net/v3"),
  {
    requestInit: {
      headers: {
        Authorization: `Bearer ${accessToken}`,
        "x-pd-project-id": "{project_id}",
        "x-pd-environment": "production",
        "x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
        "x-pd-app-slug": "hackerone",
      },
    },
  },
)

const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)

const { tools } = await mcp.listTools()

// e.g. run Create Group:
const result = await mcp.callTool({
  name: "hackerone-create-group",
  arguments: {
    organizationId: "Organization ID",
    name: "Name",
  },
})

API PROXY

Call the HackerOne API directly

For an endpoint with no pre-built tool, the Connect proxy forwards your request to the HackerOne API with the connected user's credentials attached. You store no tokens and write no refresh logic.

const resp = await pd.proxy.get({
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  accountId: "apn_xxxxxxx",
  url: "https://api.hackerone.com/v1/me/organizations",
})

// Any allowed HackerOne endpoint works here. Pipedream attaches the
// connected account's credentials to the outgoing request.

SDK

Run HackerOne actions from your backend

Connect a user's HackerOne account once, then run Create Group on their behalf from your own code — TypeScript, Python, or plain HTTP.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "hackerone-create-group",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    hackerone: { authProvisionId: "apn_xxxxxxx" },
    organizationId: "Organization ID",
    name: "Name",
  },
})

EVENTS

HackerOne triggers

Event sources your backend can deploy for users and receive through a webhook.

No HackerOne triggers are available yet.

MULTI-APP

Use HackerOne with other popular apps

Most products don't stop at one integration. Pair HackerOne with the other apps your users rely on, and ship use cases that span both.

REFERENCE

App details

Reference metadata for the HackerOne connector in the Pipedream registry.

App slug
hackerone
Authentication
API key
Categories
Security
Actions
4
Triggers
0
API proxy
Available