Bounty Operator MCP server
Run the pre-submission checks from your coding agent. One command adds the server. Preparing a core review and building the packet need no account.
Install
Claude Code
Nothing to install
claude mcp add --transport http bounty-operator https://bountyoperator.com/api/mcp
Node 22 or later
claude mcp add --transport stdio bounty-operator -- npx -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz
On Windows outside WSL, start it through cmd: end the command with -- cmd /c npx -y and the same address.
Add your account tokenfor account and run_review
Remote endpoint. The two headers carry your account token and your provider key:
claude mcp add --transport http bounty-operator https://bountyoperator.com/api/mcp --header "Authorization: Bearer $BOUNTY_OPERATOR_TOKEN" --header "X-Provider-Key: $OPENROUTER_API_KEY"
Local server. The same two values go in as environment variables:
claude mcp add --env BOUNTY_OPERATOR_TOKEN=$BOUNTY_OPERATOR_TOKEN --env OPENROUTER_API_KEY=$OPENROUTER_API_KEY --transport stdio bounty-operator -- npx -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz
Your shell fills in $BOUNTY_OPERATOR_TOKEN when the command runs. In PowerShell write $env:BOUNTY_OPERATOR_TOKEN. If the server is already added, run claude mcp remove bounty-operator first.
Codex
Nothing to install
codex mcp add bounty-operator --url https://bountyoperator.com/api/mcp
Node 22 or later
codex mcp add bounty-operator -- npx -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz
Add your account tokenfor account and run_review
Remote endpoint, in ~/.codex/config.toml. Codex reads both values from your environment:
[mcp_servers.bounty-operator]
url = "https://bountyoperator.com/api/mcp"
bearer_token_env_var = "BOUNTY_OPERATOR_TOKEN"
env_http_headers = { "X-Provider-Key" = "OPENROUTER_API_KEY" }
tool_timeout_sec = 300
Local server:
[mcp_servers.bounty-operator]
command = "npx"
args = ["-y", "https://bountyoperator.com/dl/bounty-operator-mcp.tgz"]
env_vars = ["BOUNTY_OPERATOR_TOKEN", "OPENROUTER_API_KEY"]
tool_timeout_sec = 300
Codex stops a tool call after 60 seconds by default. A hosted review runs for up to 270 seconds, so keep the tool_timeout_sec line.
Cursor
Nothing to install
{
"mcpServers": {
"bounty-operator": {
"url": "https://bountyoperator.com/api/mcp"
}
}
}
Add to CursorOpens Cursor and adds the remote endpoint.
Node 22 or later
{
"mcpServers": {
"bounty-operator": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"https://bountyoperator.com/dl/bounty-operator-mcp.tgz"
]
}
}
}
Add your account tokenfor account and run_review
Remote endpoint. Cursor fills ${env:NAME} from your environment:
{
"mcpServers": {
"bounty-operator": {
"url": "https://bountyoperator.com/api/mcp",
"headers": {
"Authorization": "Bearer ${env:BOUNTY_OPERATOR_TOKEN}",
"X-Provider-Key": "${env:OPENROUTER_API_KEY}"
}
}
}
}
Local server:
{
"mcpServers": {
"bounty-operator": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"https://bountyoperator.com/dl/bounty-operator-mcp.tgz"
],
"env": {
"BOUNTY_OPERATOR_TOKEN": "${env:BOUNTY_OPERATOR_TOKEN}",
"OPENROUTER_API_KEY": "${env:OPENROUTER_API_KEY}"
}
}
}
}
Use .cursor/mcp.json in a project folder to add the server to that project only.
No account needed for either route. list_profiles, prepare_review for the three core profiles and build_packet work as soon as the server is added. The local package is listed with its SHA-256 in SHA256SUMS.txt.
The tools it exposes
The remote endpoint exposes five tools. Three run with no account, so an agent can prepare a review and package the result on the first call. The local server adds a sixth, run_gauntlet_plan, and reads files by path.
Code security review, Solidity review and Challenge a draft report are the three core profiles. prepare_review hands their request to your agent’s own model. Every other profile runs on the hosted service through run_review, and so do seven of the gauntlet’s stages.
-
list_profilesNo account
The review profiles and what each one needs as input. Every profile carries
hosted: false for a core profile, true for a hosted one. -
prepare_reviewNo account
For the three core profiles: runs the privacy check on the files, then returns a SHA-256 manifest and the exact review request. Your agent’s own model answers it. A hosted profile is refused with
hosted_profile. -
run_gauntlet_planNo accountLocal server
The eight gauntlet stages in order, the Context fields still empty and the call that ends the run. The plan names the tool that runs each stage.
-
build_packetNo account
Turns a finished review into the evidence packet: the manifest with hashes, your context, the review and a link to verify it.
-
accountAccount token
Your plan, the reviews used today and when the allowance resets.
-
run_reviewAccount tokenProvider key
A hosted review of any profile on the provider and model you name, and the only way to run a hosted profile. Returns the review, the manifest and your remaining allowance.
A call takes up to 50 text files, 120 KB per file, 240 KB and 20,000 lines in total. File names are repo-relative paths such as src/Vault.sol. When the privacy check blocks a file, the result lists the file, the line and the kind of match, and never the matched text.
The remote endpoint takes file text inline as files. On the local server, prepare_review and run_review also take paths: the server reads those files under its working directory, so your agent does not send the text. A client that starts the server outside your project sets BOUNTY_OPERATOR_ROOT to the project folder.
A first request to try:
Use bounty-operator to prepare a Solidity review of src/Vault.sol. Answer the request it returns, then build the packet.
Core and hosted profiles
list_profiles marks every profile. hosted: false is one of the three core profiles: its method is open source and prepare_review hands it to your agent. hosted: true is a hosted profile: the service adds its method when run_review runs and sends it with your files to the provider you named, under your key. It is not in the local package or in the public repository, and no tool or prompt returns it.
For a hosted profile the tools answer like this:
-
list_profilesThe profile with its name, its description, the inputs it reads and
hosted: true. -
prepare_reviewA failed call with the code
hosted_profile, the profile id and a sentence that namesrun_review. It is refused before any file is read. -
run_reviewThe review, its verdict, the reference check, the manifest and your remaining allowance. It uses one hosted review.
verdictandpanelrun on Operator only. -
build_packetThe evidence packet for the review
run_reviewreturned. Passsource: "ai".
The refusal, as the remote endpoint returns it for triage:
{
"profile": "triage",
"error": "Triager simulation runs on the server. Call run_review with profile \"triage\", your connection token and your provider key in the X-Provider-Key header.",
"code": "hosted_profile"
}
The local server returns the same code and names BOUNTY_OPERATOR_TOKEN in the sentence. run_review sends the files and your provider key to the service, which adds the method of the profile, calls your provider and returns the review.
Three slash commands
The server ships three prompts. A client that supports MCP prompts lists them as commands. In Claude Code, type / and pick one, or type the full name:
-
/mcp__bounty-operator__challenge-reportChecks every claim in your draft report against the code it cites, then builds the evidence packet.
-
/mcp__bounty-operator__solidity-reviewMaps entry points and invariants in the contracts you name and reports what the code proves, with file and line.
-
/mcp__bounty-operator__gauntletTakes a finding through the pre-submission stages in order and ends with one verdict. Its hosted stages run through
run_review.
challenge-report and solidity-review prepare the review with prepare_review, have your agent’s own model answer and end with build_packet, so both work with no account.
gauntlet lists the eight stages with the tool that runs each one. Seven are hosted and run through run_review. The report stage is a core profile, so your agent’s own model answers it from prepare_review. The run needs an account token and your provider key, and it uses seven hosted reviews. Free covers one hosted review per UTC day, so a full run takes Operator. On the local server the prompt starts from run_gauntlet_plan.
Skills and the plugin
The repository is also a Claude Code plugin with five skills. challenge-report, solidity-review and code-security-review carry the three core methods and run on your agent’s own model with no account. gauntlet runs the eight stages through this server. hunt-with-gate runs only when you call it by name: it checks a finding before any report is written and never submits anything.
claude plugin marketplace add bountyoperator/bounty-operator
claude plugin install bounty-operator@bounty-operator
The plugin adds this server too. It reads BOUNTY_OPERATOR_TOKEN and BOUNTY_OPERATOR_PROVIDER_KEY from the environment you start Claude Code in; both can stay unset for the core skills. Codex, Cursor and other agents take the skills with one command and the server with the commands above:
npx skills add bountyoperator/bounty-operator
What needs an account token
Works with no token
list_profilesprepare_review, for the three core profilesbuild_packetrun_gauntlet_plan, on the local server- The
challenge-reportandsolidity-reviewprompts
Your agent’s own model does the review. Nothing is counted against an allowance.
Needs a token
accountrun_review, with your provider key- The
gauntletprompt, which runs its hosted stages withrun_review
A hosted review uses the same allowance as the website: one per UTC day on Free, unlimited on Operator at US$10 per week.
Create a token
- Sign in at bountyoperator.com with your passkey and open the account panel.
- Under Connections, name the connection after the client that will use it, and create it.
- Copy the token. It starts with
bok_and is shown once. - Set it as
BOUNTY_OPERATOR_TOKENin your environment and add the server with the token command for your client.
A token lasts 90 days. An account holds three at a time. Revoke one in the account panel and it stops working at once.
Your provider key
run_review runs on your own model key. The remote endpoint takes it in the X-Provider-Key header. The local server reads it from the provider’s environment variable:
| Provider | Environment variable |
|---|---|
| OpenRouter | OPENROUTER_API_KEY |
| Anthropic | ANTHROPIC_API_KEY |
| OpenAI | OPENAI_API_KEY |
| Google Gemini | GEMINI_API_KEY |
| xAI | XAI_API_KEY |
| DeepSeek | DEEPSEEK_API_KEY |
| Mistral | MISTRAL_API_KEY |
| Groq | GROQ_API_KEY |
The remote endpoint uses the provider’s default model when a call names none. The local server needs a model: pass model, or set BOUNTY_OPERATOR_MODEL.
What the server can reach
A token does two things
It reads your usage and runs a review. Billing, passkeys, recovery and deletion stay behind your passkey. We keep a SHA-256 of the token, its label and its last-used time.
The server sees what your agent passes
The remote endpoint receives file contents as tool arguments and nothing else from your machine. The local server reads only the paths your agent names under its working directory.
A hosted review goes through our server
The run_review tool sends the files and your provider key to bountyoperator.com. The server adds the method of the profile, calls your provider and returns the review. It stores none of it.
Keys stay out of the transcript
The provider key travels in a header or an environment variable, never as a tool argument.
Stateless endpoint
Each request stands alone. There is no MCP session to resume and no stream held open.
Local means local
On the local server, preparing a review, planning a gauntlet and building a packet run on your machine with no network call.
The security page has the full data flow, what is stored and how to report a vulnerability.
When a call fails
A failed tool call comes back as a result with isError set and one JSON object: error, a sentence your agent can act on, and code, a value that does not change. Both servers use the same codes.
-
hosted_profileprepare_reviewwas called with a hosted profile. Nothing was read and nothing was counted. Callrun_review. -
privacy_blockThe privacy check found a secret. The result lists the file, the line and the kind of each match. Remove it and call again.
-
privacy_warnThe privacy check found an email or an IP address. Call again with
acknowledgeWarnings: trueto send the files as they are. -
daily_usedThe free review of the day is used. The result carries
resetsAt, the time the next one opens. -
operator_onlyrun_reviewwas called withverdictorpanelon an account without Operator. Those two profiles run only inside the gauntlet and a panel review. Nothing was sent to the provider and the review of the day is not used. -
review_runningThe account is running as many reviews as its plan allows. Call again when one finishes.
-
providerYour provider refused the call or timed out: a rejected key, an unknown model, a rate limit. The review is not counted.
-
output_withheldThe model repeated its instructions instead of reviewing, so the answer was stopped and the call used one review. Run it again or choose a stronger model.
account and run_review without a valid token are answered with HTTP 401 by the remote endpoint, which is what makes a client ask for the token. The local server returns the code token.
Questions
Do I need an account to use the MCP server?
No. list_profiles, prepare_review and build_packet work with no account and no key, and so do the challenge-report and solidity-review prompts: your agent’s own model answers the prepared request of a core profile. An account token adds account, run_review for every profile, and the gauntlet prompt.
Should I use the remote endpoint or the local server?
The remote endpoint needs nothing installed and works on any machine the client runs on. The local server needs Node 22 or later, keeps review preparation on your machine, reads files by path and adds run_gauntlet_plan. The other five tools are the same on both.
What does a hosted review cost through MCP?
run_review shares one allowance with the website: one hosted review per UTC day on Free, any profile, and unlimited on Operator at US$10 per week. A gauntlet run over MCP uses seven hosted reviews, one for every stage but the report stage, so a full run takes Operator. Your model provider bills its own usage to your key.
Which profiles can my agent’s own model run?
The three core profiles: Code security review, Solidity review and Challenge a draft report. prepare_review returns their method and the request. Every other profile is hosted: prepare_review refuses it with hosted_profile and run_review runs it on the service, on your provider key.
How do I check the service before a long run?
GET https://bountyoperator.com/api/health returns the version, reviews (whether hosted reviews are on) and profiles. profiles reads hosted when the service carries the full method of every hosted profile. A Worker built from the public repository reads community: it runs the hosted profiles on short stand-in instructions.
Which clients work?
Any client that speaks MCP over Streamable HTTP or stdio. This page has the commands for Claude Code, Codex and Cursor.