About
MCP server for the HackerOne GraphQL API
README
A Docker image that provides access to HackerOne's GraphQL API through the Model Context Protocol (MCP).
Supported MCP transport types: Currently only stdio transport is supported. Please file an issue if you require other transports.
Multi-Architecture Support: This image supports both Intel/AMD (amd64) and Apple Silicon (arm64) architectures.
Built on Apollo MCP Server: This project is a thin wrapper around the upstream Apollo MCP Server, which exposes GraphQL operations as MCP tools.
Quick Start
- Run with an MCP client:
docker run -i --rm \ -e ENDPOINT="https://hackerone.com/graphql" \ -e TOKEN="<your_base64_encoded_token>" \ -e MUTATION_MODE="none" \ hackertwo/hackerone-graphql-mcp-server:1.0.7
Docker Image Tags
latest: Latest stable release (only updated on version releases)dev-main: Development builds from main branch1.x.x: Specific version releasespr-<ref>: Pull request builds
Environment Variables
| Variable | Description | Default |
|---|---|---|
ENDPOINT |
GraphQL endpoint URL | https://hackerone.com/graphql |
TOKEN |
Base64 encoded API token in format: base64(username:api_key) |
- |
MUTATION_MODE |
Controls which mutations are allowed: • none: No mutations allowed• explicit: Only explicitly defined mutations allowed• all: All mutations allowed |
none |
DISABLE_TYPE_DESCRIPTION |
If set to true, tools will have no type descriptions (e.g. "The returned value has type ...") |
false |
DISABLE_SCHEMA_DESCRIPTION |
If set to true, tools will have no schema description |
false |
Generating an API Token
Option 1: Using the included script (recommended)
- Visit https://hackerone.com/settings/api_token/edit to generate an API key
- Run the token generation script:
./scripts/generate_token.shThis will prompt for your username and API key, then automatically encode and copy the token to your clipboard. - Use the resulting string as your TOKEN value
Option 2: Manual encoding
- Visit https://hackerone.com/settings/api_token/edit to generate an API key
- Encode as:
echo -n "username:api_key" | base64 - Use the resulting string as your TOKEN value
Example config in Flowise
- Go to an Agent node
- Go to tools
- Select custom MCP
- Put the following in the MCP parameters:
{
"command": "/usr/local/bin/docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"ENDPOINT=https://hackerone.com/graphql",
"-e",
"TOKEN=<your_base64_encoded_token>",
"-e",
"MUTATION_MODE=none",
"hackertwo/hackerone-graphql-mcp-server:1.0.7"
]
}
Example config in editor (Zed)
{
"context_servers": {
"hackerone-graphql-mcp-server": {
"source": "custom",
"command": "/usr/local/bin/docker",
"args": [
"run",
"-i",
"--rm",
"-e",
"ENDPOINT=https://hackerone.com/graphql",
"-e",
"TOKEN=<your_base64_encoded_token>",
"-e",
"MUTATION_MODE=none",
"hackertwo/hackerone-graphql-mcp-server:1.0.7"
]
}
}
}
Notes
- The Docker container is designed to be piped into an MCP-compatible client
- Running the container directly will result in an error as it expects an MCP client connection
- The
-iflag is required to maintain standard input for the stdio transport - The
schema.graphqlin this repository may become outdated over time, you can download the latest one from HackerOne at https://hackerone.com/schema.graphql
Development
Creating a Release
To create a new release:
Create a new release in GitHub.
GitHub Actions will automatically:
- Build multi-architecture images (amd64, arm64)
- Push to Docker Hub with appropriate tags
- Update the
latesttag
Manual Build (Local Development)
For local development and testing:
# Setup buildx
docker buildx create --name multiarch --driver docker-container --use
docker buildx inspect --bootstrap
# Build and push the image
bin/build
# Clean up
docker buildx rm multiarch
Debugging
Run MCP inspector:
npx @modelcontextprotocol/inspectorConnect to the HackerOne MCP server from the web interface:
Command:
/usr/local/bin/dockerArguments:
run -i --rm -e ENDPOINT=http://host.docker.internal:3000/graphql -e TOKEN=<TOKEN> -e ALLOW_MUTATIONS=all hackertwo/hackerone-graphql-mcp-server:1.0.5
Issues & Contributions
- HackerOne-specific behavior, configuration, token handling, schema quirks, mutation allow-listing, etc.: open an issue in this repository.
- Generic MCP behavior, transports, protocol details, or GraphQL tool exposure mechanics: consider checking/filing upstream in apollographql/apollo-mcp-server.
Licensing Notes
This project depends on Apollo MCP Server, which is licensed under the MIT License.
Your use of this image includes use of Apollo MCP Server under its license; please review the upstream LICENSE.
Installing Hackerone Graphql
This server has no published package — it is built from source. Open the repository and follow its README.
▸ github.com/Hacker0x01/hackerone-graphql-mcp-serverFAQ
Is Hackerone Graphql MCP free?
Yes, Hackerone Graphql MCP is free — one-click install via Unyly at no cost.
Does Hackerone Graphql need an API key?
No, Hackerone Graphql runs without API keys or environment variables.
Is Hackerone Graphql hosted or self-hosted?
Self-hosted: the server runs locally on your machine via the install command above.
How do I install Hackerone Graphql in Claude Desktop, Claude Code or Cursor?
Open Hackerone Graphql on unyly.org, pick your client tab (Claude Desktop, Claude Code, Cursor) and press Install — the config is generated automatically, no JSON editing.
Related MCPs
GitHub
PRs, issues, code search, CI status
by GitHubFilesystem
Secure file operations with configurable access controls.
Memory
Knowledge graph-based persistent memory system.
Template MCP Server
A CLI tool to create a new Model Context Protocol server project with TypeScript support, dual transport options, and an extensible structure
by mcpdotdirectCompare Hackerone Graphql with
Not sure what to pick?
Find your stack in 60 seconds
Author?
Embed badge for your README
Browse similar
All development MCPs
