MCP v2 on bountyindex.in, 14 tool calls,happy bug hunting

Bounty.index MCP v2 lets security researchers and developers query a live bug bounty program index from MCP-compatible AI clients. They can search programs, check asset scope, and review reward and policy changes.

One of 124 tools in Research

MCP v2 on bountyindex.in, 14 tool calls,happy bug hunting screenshot

Who it's for

  • Bug bounty hunters using Claude Desktop, Cursor, Codex, or another MCP client to find programs and check asset scope.
  • Security researchers who need to check which indexed programs cover a URL, domain, or other asset.
  • Developers building agent workflows that need bounty.index program, payout, or scope data.

How it fits your workflow

Add the MCP endpoint to a compatible client's configuration and restart the client. The page says no API key or signup is needed.

Use tools to search programs, retrieve program records, look up scope for assets, and review recent changes. Named prompts provide workflows for triage, high-paying program discovery, and weekly digests.

The server is stateless and includes a live stats resource that clients can read without making a tool call.

Pricing

The vendor doesn't publish prices. Check with MCP v2 on bountyindex.in, 14 tool calls,happy bug hunting directly.

Prices checked on Oct 6, 2026 from the vendor's site. They can change; confirm before you buy.

Key features

Program search and discovery
Search programs by keyword, platform, reward, and asset type, with support for opportunity sorting. Other tools list platforms, site-wide statistics, top payouts, recently added programs, and trending programs.
Scope lookup
Retrieve a program's scope, filter scope rows by asset type, or reverse-look up which programs cover a URL or domain. Bulk scope lookup accepts up to 50 assets per call.
Program details and history
Fetch a full record for one program, optionally including raw data, find similar programs based on shared in-scope identifiers, and view a program's snapshot timeline.
Change monitoring
Find recent changes to scope, rewards, and safe-harbor terms across programs.
Bulk program retrieval
Fetch summaries for up to 100 programs in one call using numeric program IDs.
Agent workflows and live resource
Three named prompts support asset triage, high-paying program discovery, and weekly digests. The stats://overview resource provides live site-wide totals without a tool call.

Works with

  • Claude Desktop
  • Cursor
  • Other MCP clients

Limitations to know

  • The v2 server is identified as a public beta, version 0.2.
  • The stated rate limit is 60 requests per minute.
  • The server is stateless.
  • The index covers public programs across six platforms.

Getting started

An MCP-compatible client. The page names Claude Desktop, Cursor, and Codex.

  1. Add the bounty-index server URL, https://www.bountyindex.in//api/mcp/v2, to the MCP configuration for the chosen client.
  2. For Claude Desktop, use claude_desktop_config.json; for Cursor, use ~/.cursor/mcp.json.
  3. Restart the client.
  4. Call a tool or invoke one of the named prompts.