{"_id":"@bountylens/mcp","_rev":"7-b9b741e9144ce46fb6c41ee265f889df","name":"@bountylens/mcp","dist-tags":{"latest":"0.8.0"},"versions":{"0.1.0":{"name":"@bountylens/mcp","version":"0.1.0","keywords":["mcp","bountylens","bug-bounty","claude-code","security"],"author":{"name":"BountyLens"},"license":"MIT","_id":"@bountylens/mcp@0.1.0","maintainers":[{"name":"bountylens","email":"servies@bountylens.com"}],"homepage":"https://github.com/bountylens/mcp#readme","bugs":{"url":"https://github.com/bountylens/mcp/issues"},"bin":{"bountylens-mcp":"dist/index.js"},"dist":{"shasum":"aae5077070c57db6822756f5900d9ca7debb8430","tarball":"https://registry.npmjs.org/@bountylens/mcp/-/mcp-0.1.0.tgz","fileCount":4,"integrity":"sha512-Htoy9WG7+J0nqXshAvABAom2t3m1a+/W2UrI4G/c8YF0uEmGxAULeHnnAxWsGkuSv3S/j8gKR7imNtmCqm/6mA==","signatures":[{"sig":"MEYCIQCu2jsQyQtubHMCjDr+4iH8iRQlAfnqdA7iRel8RHbGkwIhAJAOc5lqmbr5+DylM2QshUwNWEcQodvVp9GH++BpYCDe","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":11383},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"gitHead":"37ae7189fcb565d658b59d3ad70c71b60447814a","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"bountylens","email":"servies@bountylens.com"},"repository":{"url":"git+https://github.com/bountylens/mcp.git","type":"git"},"_npmVersion":"11.12.1","description":"BountyLens MCP server — connect Claude Code to your Hunter Tracker","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@modelcontextprotocol/sdk":"^1.12.1"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.1.0_1777872993108_0.7409858035516126","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@bountylens/mcp","version":"0.2.0","keywords":["mcp","bountylens","bug-bounty","claude-code","security"],"author":{"name":"BountyLens"},"license":"MIT","_id":"@bountylens/mcp@0.2.0","maintainers":[{"name":"bountylens","email":"servies@bountylens.com"}],"homepage":"https://github.com/bountylens/mcp#readme","bugs":{"url":"https://github.com/bountylens/mcp/issues"},"bin":{"bountylens-mcp":"dist/index.js"},"dist":{"shasum":"9b5bcdaa6ed524c051c0826a99411cfae52c096c","tarball":"https://registry.npmjs.org/@bountylens/mcp/-/mcp-0.2.0.tgz","fileCount":4,"integrity":"sha512-h4+yF7LsPI5nz2m7gRDY3D8JLV0LVk2vzRFfV4rjIP4MWhSm/kbOncWE0nlxciAq2KUamT51ab3PdBqEJZo4vQ==","signatures":[{"sig":"MEUCIG7tAnTeBLwzO59+DLnRKC0IR0gVTbLsgl5bRnMVn30PAiEA5hgfP6pu5m6EgqhwoIS+7QbrkEKQFRdYXyTi2sMxaI8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":13243},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"gitHead":"c0b16388dfea67d8be8cff70bcb8bab45a50cbf0","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"bountylens","email":"servies@bountylens.com"},"repository":{"url":"git+https://github.com/bountylens/mcp.git","type":"git"},"_npmVersion":"11.12.1","description":"BountyLens MCP server — connect Claude Code to your Hunter Tracker","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@modelcontextprotocol/sdk":"^1.12.1"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.2.0_1777874728479_0.41346982545751065","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@bountylens/mcp","version":"0.3.0","keywords":["mcp","bountylens","bug-bounty","claude-code","security"],"author":{"name":"BountyLens"},"license":"MIT","_id":"@bountylens/mcp@0.3.0","maintainers":[{"name":"bountylens","email":"servies@bountylens.com"}],"homepage":"https://github.com/bountylens/mcp#readme","bugs":{"url":"https://github.com/bountylens/mcp/issues"},"bin":{"bountylens-mcp":"dist/index.js"},"dist":{"shasum":"65d064ae21cc0fa337a36b260cbabc9772c5070e","tarball":"https://registry.npmjs.org/@bountylens/mcp/-/mcp-0.3.0.tgz","fileCount":5,"integrity":"sha512-HIeFe2UkXN6W1luPWRyB1PCKQU0bd3YHjLekpSZcSuRfKkR/MZRdM5jKWtR9b92EA52L5SzOKD5Kgb5NiXZ8+A==","signatures":[{"sig":"MEQCIA/vT5c4wNlI7P/vnbCmgkbA5VrFfEceqF4L/XYv4AiWAiBLo55G6HGAXqRIMA+/0NjP59/4HnLiYlcd9oaAGU8jaA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":20063},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"gitHead":"70ce415068afe2e48a2427549789a856150c50f0","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"bountylens","email":"servies@bountylens.com"},"repository":{"url":"git+https://github.com/bountylens/mcp.git","type":"git"},"_npmVersion":"11.12.1","description":"BountyLens MCP server — connect Claude Code to your Hunter Tracker","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@modelcontextprotocol/sdk":"^1.12.1"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.3.0_1777987555209_0.7549641213309255","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@bountylens/mcp","version":"0.4.0","keywords":["mcp","bountylens","bug-bounty","claude-code","security"],"author":{"name":"BountyLens"},"license":"MIT","_id":"@bountylens/mcp@0.4.0","maintainers":[{"name":"bountylens","email":"servies@bountylens.com"}],"homepage":"https://github.com/bountylens/mcp#readme","bugs":{"url":"https://github.com/bountylens/mcp/issues"},"bin":{"bountylens-mcp":"dist/index.js"},"dist":{"shasum":"e50117e79fdd62175d336b2f3b5ff55be568dddf","tarball":"https://registry.npmjs.org/@bountylens/mcp/-/mcp-0.4.0.tgz","fileCount":5,"integrity":"sha512-Cg0/H1dgFG6GkXn2eSqRNnXpwKqJut+BGs7hMCRqiInFhQDvQ2vj+TsUJ/5Hgk8QOThKRu4vCRqemu3YuAgM7g==","signatures":[{"sig":"MEQCIFUkuLX/GEx0mBdciUkeaKSP4XE+j2Zb6JkbZdFrPIxzAiAE86WxOtEBKcVe7CkFN4BceQ2+daFu2qEkwDbJXgA36w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":23089},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"gitHead":"78be379176453d77e990b6aabfff3b2627e91bae","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"bountylens","email":"servies@bountylens.com"},"repository":{"url":"git+https://github.com/bountylens/mcp.git","type":"git"},"_npmVersion":"11.12.1","description":"BountyLens MCP server — connect Claude Code to your Hunter Tracker","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@modelcontextprotocol/sdk":"^1.12.1"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.4.0_1779710310924_0.8075060495843873","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@bountylens/mcp","version":"0.6.0","keywords":["mcp","bountylens","bug-bounty","claude-code","security"],"author":{"name":"BountyLens"},"license":"MIT","_id":"@bountylens/mcp@0.6.0","maintainers":[{"name":"bountylens","email":"servies@bountylens.com"}],"homepage":"https://github.com/bountylens/mcp#readme","bugs":{"url":"https://github.com/bountylens/mcp/issues"},"bin":{"bountylens-mcp":"dist/index.js"},"dist":{"shasum":"6c51705eef0e5cc373467a4bfe33027f5ad0837d","tarball":"https://registry.npmjs.org/@bountylens/mcp/-/mcp-0.6.0.tgz","fileCount":5,"integrity":"sha512-Z1CBt1Qg7oWcv9TCn0HbEhT2KkKo8pUtMfmrGLqSm46euEfKVJVxQ2cFrB/1TYZPiABZm3YrRAF/8esKkHHPRA==","signatures":[{"sig":"MEUCIQDtMIdWhw3GMDs7vj/zvpJQULQqBeMU2LFynOvRHHfKCgIgVTy/NhtmM66i2xF+UGpDUDTla5/w5Kbs0cUKzvYupws=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":27892},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"gitHead":"9909ce181b1437c874165fc491ba4afb5d90b5b4","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"bountylens","email":"servies@bountylens.com"},"repository":{"url":"git+https://github.com/bountylens/mcp.git","type":"git"},"_npmVersion":"11.12.1","description":"BountyLens MCP server — connect Claude Code to your Hunter Tracker","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@modelcontextprotocol/sdk":"^1.12.1"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.6.0_1781555684042_0.4317017740220128","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@bountylens/mcp","version":"0.7.0","keywords":["mcp","bountylens","bug-bounty","claude-code","security"],"author":{"name":"BountyLens"},"license":"MIT","_id":"@bountylens/mcp@0.7.0","maintainers":[{"name":"bountylens","email":"servies@bountylens.com"}],"homepage":"https://github.com/bountylens/mcp#readme","bugs":{"url":"https://github.com/bountylens/mcp/issues"},"bin":{"bountylens-mcp":"dist/index.js"},"dist":{"shasum":"0dc6679429de22da2f8f54d9861796cdabfda073","tarball":"https://registry.npmjs.org/@bountylens/mcp/-/mcp-0.7.0.tgz","fileCount":5,"integrity":"sha512-oHK153ckQrhUCkrcgF4lR+IaswRbvDEeAYmJwkr4Tv17GAcpChgacqWDwqyq9Ot0QU9XWlFWN9fVO4rjNp0eFw==","signatures":[{"sig":"MEQCIHlwCb6mFzIKxB220P3O2IvrdNlV6Vx9gIJXx2Ao7GdOAiAXDa6mP18e7+Ilnb4LtXHqWWrM82pGc1HCmjlWmQwF6w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":28162},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"gitHead":"912dce311f0c33efd2444179ba4c6b7f13f0f4a9","scripts":{"dev":"tsc --watch","build":"tsc","start":"node dist/index.js"},"_npmUser":{"name":"bountylens","email":"servies@bountylens.com"},"repository":{"url":"git+https://github.com/bountylens/mcp.git","type":"git"},"_npmVersion":"11.12.1","description":"BountyLens MCP server — connect Claude Code to your Hunter Tracker","directories":{},"_nodeVersion":"25.9.0","dependencies":{"@modelcontextprotocol/sdk":"^1.12.1"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp_0.7.0_1782152072672_0.7954162149675861","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@bountylens/mcp","version":"0.8.0","description":"BountyLens MCP server — connect Claude Code to your Hunter Tracker","type":"module","main":"dist/index.js","bin":{"bountylens-mcp":"dist/index.js"},"scripts":{"build":"tsc","dev":"tsc --watch","start":"node dist/index.js"},"keywords":["mcp","bountylens","bug-bounty","claude-code","security"],"author":{"name":"BountyLens"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/bountylens/mcp.git"},"engines":{"node":">=18"},"dependencies":{"@modelcontextprotocol/sdk":"^1.12.1"},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.7.0"},"gitHead":"912dce311f0c33efd2444179ba4c6b7f13f0f4a9","types":"./dist/index.d.ts","_id":"@bountylens/mcp@0.8.0","bugs":{"url":"https://github.com/bountylens/mcp/issues"},"homepage":"https://github.com/bountylens/mcp#readme","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-3QFVBGUDlgSkL0O+MpuOmomz9Ur5TanWO2YbG59p8TnpwbsrXPonAdGMrw+FOMaMpHrT5T1vDwvutib7k/qvdA==","shasum":"bfa8c9caa4712a6b3f295c4525953536066dc948","tarball":"https://registry.npmjs.org/@bountylens/mcp/-/mcp-0.8.0.tgz","fileCount":5,"unpackedSize":31741,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDjW/AZEyurZUG7dpo5zs8ttWUYfOQAjpBDHTBBlE81kQIgT8qnJctXlk+ps4/h3/BrnzprtcEtKGOW7UiuJLieRNg="}]},"_npmUser":{"name":"bountylens","email":"servies@bountylens.com"},"directories":{},"maintainers":[{"name":"bountylens","email":"servies@bountylens.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp_0.8.0_1784041974865_0.5110986654573353"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-04T05:36:33.018Z","modified":"2026-07-14T15:12:55.150Z","0.1.0":"2026-05-04T05:36:33.257Z","0.2.0":"2026-05-04T06:05:28.649Z","0.3.0":"2026-05-05T13:25:55.350Z","0.4.0":"2026-05-25T11:58:31.086Z","0.6.0":"2026-06-15T20:34:44.180Z","0.7.0":"2026-06-22T18:14:32.817Z","0.8.0":"2026-07-14T15:12:55.051Z"},"bugs":{"url":"https://github.com/bountylens/mcp/issues"},"author":{"name":"BountyLens"},"license":"MIT","homepage":"https://github.com/bountylens/mcp#readme","keywords":["mcp","bountylens","bug-bounty","claude-code","security"],"repository":{"type":"git","url":"git+https://github.com/bountylens/mcp.git"},"description":"BountyLens MCP server — connect Claude Code to your Hunter Tracker","maintainers":[{"name":"bountylens","email":"servies@bountylens.com"}],"readme":"# @bountylens/mcp\n\nMCP server for [BountyLens](https://bountylens.com) — connect Claude Code to your Hunter Tracker.\n\nPush findings, leads, tested endpoints, and full report drafts directly from your terminal to the BountyLens dashboard. Search across all sessions, get program intelligence, and track your hunt stats — all without leaving the terminal. Everything you log appears in real-time in the web UI with an `MCP` badge.\n\n## Quick Start\n\n### 1. Get an API key\n\nGo to [bountylens.com/dashboard/settings](https://bountylens.com/dashboard/settings) → **Integrations** → **Generate New API Key**.\n\nCopy the key — it's only shown once.\n\n### 2. Add to Claude Code\n\nAdd to your MCP config at `~/.claude/.mcp.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"bountylens\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@bountylens/mcp\"],\n      \"env\": {\n        \"BOUNTYLENS_API_KEY\": \"bl_your_key_here\"\n      }\n    }\n  }\n}\n```\n\n### 3. Restart Claude Code\n\nThe BountyLens tools will be available immediately. No other setup needed.\n\n## Tools (23)\n\n### Sessions\n\n| Tool | Description |\n|------|-------------|\n| `bountylens_list_sessions` | List hunt sessions — filter by `status` (active/paused/completed), `program_id`, or `program_handle` |\n| `bountylens_create_session` | Start a new hunt session with a title and optional program (by ID or handle) |\n| `bountylens_get_session` | Get a session with all its entries and counts |\n| `bountylens_update_session` | Update title, status, or notes |\n| `bountylens_delete_session` | Permanently delete a session and all its entries and reports |\n\n### Entries\n\nAll entry tools support the Tracker Pro fields: **`tags`** (lowercase, max 10), **`chain_id`** (link to another entry in the same session to build exploit chains), and **`retest_at`** (ISO-8601 timestamp → retest queue).\n\n| Tool | Description |\n|------|-------------|\n| `bountylens_list_entries` | List entries in a session — filter by `type` (tested/lead/finding/note) and/or `tag` |\n| `bountylens_add_finding` | Log a validated finding with severity, endpoint, method, description, `tags`, `chain_id` |\n| `bountylens_add_lead` | Log a promising lead — supports `tags`, `chain_id`, `retest_at` |\n| `bountylens_add_tested` | Mark an endpoint or feature as tested — supports `tags`, `retest_at` |\n| `bountylens_add_note` | Add a freeform note to the session — supports `tags` |\n| `bountylens_update_entry` | Update title, description, status, severity, type, endpoint, method, `tags`, `chain_id`, `retest_at` (passing `tags` replaces them) |\n| `bountylens_delete_entry` | Remove an entry |\n| `bountylens_bulk_add_entries` | Add up to 50 entries in one call — each item supports `tags`, `chain_id`, `retest_at` |\n\n**Tag conventions:** `vuln:<class>` (`vuln:idor`, `vuln:ssrf`…), `surface:<type>` (`web`, `api`, `graphql`, `mobile`, `cloud-aws`…), `src:<origin>` (`src:hack`, `src:pentest`), `platform:<name>` (`h1`, `synack`, `bugcrowd`, `intigriti`, `ywh`). Don't tag severity or status — those are first-class fields.\n\n### Reports\n\n| Tool | Description |\n|------|-------------|\n| `bountylens_draft_report` | Create a report draft — include summary, steps to reproduce, impact, and remediation |\n| `bountylens_list_reports` | List all report drafts in a session |\n| `bountylens_update_report` | Edit a report's title, body, severity, or status — lifecycle (draft/ready/submitted) or closed outcome (resolved/duplicate/informative/not_applicable) |\n| `bountylens_delete_report` | Permanently delete a report |\n\n### Search\n\n| Tool | Description |\n|------|-------------|\n| `bountylens_search_entries` | Search across ALL sessions for entries matching a query — finds past findings, leads, or tested endpoints without knowing which session they're in |\n\n### Programs\n\n| Tool | Description |\n|------|-------------|\n| `bountylens_search_programs` | Search bug bounty programs by name or handle |\n| `bountylens_get_program` | Get full program details — bounties, dupe risk, health score, scope list, and recent scope changes |\n\n### Intelligence\n\n| Tool | Description |\n|------|-------------|\n| `bountylens_recommend_programs` | Get program recommendations ranked by opportunity score — filter by platform or minimum bounty |\n| `bountylens_get_watchlist` | Get your watched programs with metrics — bounties, dupe risk, health, scope changes, and session count |\n| `bountylens_get_my_stats` | Get your hunt statistics — sessions, findings, leads, tested endpoints, time spent, and per-program breakdown |\n\n## Usage Examples\n\nDuring a hunt in Claude Code, the LLM uses these tools automatically based on your instructions:\n\n```\n\"List my active sessions\"\n→ bountylens_list_sessions with status=active\n\n\"Save this XSS finding to my Shopify session\"\n→ bountylens_add_finding with title, severity, endpoint, description\n\n\"What leads do I have open on the Uber hunt?\"\n→ bountylens_list_entries with type=lead\n\n\"Mark /api/auth as tested, CSRF tokens are present\"\n→ bountylens_add_tested with endpoint and description\n\n\"Have I tested SSRF on any target before?\"\n→ bountylens_search_entries with query=\"SSRF\"\n\n\"What's the scope for Shopify's program?\"\n→ bountylens_get_program with handle=\"shopify\"\n\n\"What should I hunt next?\"\n→ bountylens_recommend_programs with min_bounty=1000\n\n\"How much time have I spent hunting this month?\"\n→ bountylens_get_my_stats\n\n\"Draft a report for the SSRF finding\"\n→ bountylens_draft_report with full report body\n\n\"Push reports/ssrf-uber.md to my Uber session\"\n→ reads the file, calls bountylens_draft_report with contents\n```\n\n## Environment Variables\n\n| Variable | Required | Default | Description |\n|----------|----------|---------|-------------|\n| `BOUNTYLENS_API_KEY` | Yes | — | API key from dashboard settings |\n| `BOUNTYLENS_URL` | No | `https://bountylens.com` | Custom instance URL (self-hosted) |\n\n## API Reference\n\nThe MCP server wraps the BountyLens API v1. All endpoints require a `Bearer` token in the `Authorization` header.\n\n```\nGET    /api/v1/sessions                         — list sessions\nPOST   /api/v1/sessions                         — create session\nGET    /api/v1/sessions/:id                      — get session + entries\nPUT    /api/v1/sessions/:id                      — update session\nDELETE /api/v1/sessions/:id                      — delete session\nGET    /api/v1/sessions/:id/entries              — list entries\nPOST   /api/v1/sessions/:id/entries              — create entry\nPOST   /api/v1/sessions/:id/entries/bulk         — bulk create entries (max 50)\nPUT    /api/v1/sessions/:id/entries/:entryId     — update entry\nDELETE /api/v1/sessions/:id/entries/:entryId     — delete entry\nGET    /api/v1/sessions/:id/reports              — list reports\nPOST   /api/v1/sessions/:id/reports              — create report\nPUT    /api/v1/sessions/:id/reports/:reportId    — update report\nDELETE /api/v1/sessions/:id/reports/:reportId    — delete report\nGET    /api/v1/search?q=query                    — search entries across all sessions\nGET    /api/v1/programs?q=search                 — search programs\nGET    /api/v1/programs/:handle                  — get program details\nGET    /api/v1/recommend                         — get program recommendations\nGET    /api/v1/watchlist                         — get watched programs\nGET    /api/v1/stats                             — get hunt statistics\n```\n\nRate limit: 60 requests/minute per API key.\n\n## Security\n\n- API keys are SHA-256 hashed in the database — never stored in plaintext\n- Keys are shown once on creation and cannot be retrieved\n- All queries are parameterized — no SQL injection\n- Every request verifies resource ownership — no IDOR\n- Pro subscription is validated on every API call\n- Rate limited to prevent abuse\n\n## Requirements\n\n- Node.js 18+\n- [BountyLens](https://bountylens.com) Pro subscription\n- API key from the dashboard\n\n## Contributing\n\nWe welcome contributions. See [CONTRIBUTING.md](CONTRIBUTING.md) for guidelines.\n\n## License\n\nMIT — see [LICENSE](LICENSE)\n","readmeFilename":"README.md"}