Bounty Operator MCP server

Run the pre-submission checks from your coding agent. One command adds the server. Preparing a core review and building the packet need no account.

Install

Claude Code

Remote endpointNothing to install

Terminal
claude mcp add --transport http bounty-operator https://bountyoperator.com/api/mcp

Local serverNode 22 or later

Terminal
claude mcp add --transport stdio bounty-operator -- npx -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz

On Windows outside WSL, start it through cmd: end the command with -- cmd /c npx -y and the same address.

Add your account tokenfor account and run_review

Remote endpoint. The two headers carry your account token and your provider key:

Terminal
claude mcp add --transport http bounty-operator https://bountyoperator.com/api/mcp --header "Authorization: Bearer $BOUNTY_OPERATOR_TOKEN" --header "X-Provider-Key: $OPENROUTER_API_KEY"

Local server. The same two values go in as environment variables:

Terminal
claude mcp add --env BOUNTY_OPERATOR_TOKEN=$BOUNTY_OPERATOR_TOKEN --env OPENROUTER_API_KEY=$OPENROUTER_API_KEY --transport stdio bounty-operator -- npx -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz

Your shell fills in $BOUNTY_OPERATOR_TOKEN when the command runs. In PowerShell write $env:BOUNTY_OPERATOR_TOKEN. If the server is already added, run claude mcp remove bounty-operator first.

Codex

Remote endpointNothing to install

Terminal
codex mcp add bounty-operator --url https://bountyoperator.com/api/mcp

Local serverNode 22 or later

Terminal
codex mcp add bounty-operator -- npx -y https://bountyoperator.com/dl/bounty-operator-mcp.tgz
Add your account tokenfor account and run_review

Remote endpoint, in ~/.codex/config.toml. Codex reads both values from your environment:

~/.codex/config.toml
[mcp_servers.bounty-operator]
url = "https://bountyoperator.com/api/mcp"
bearer_token_env_var = "BOUNTY_OPERATOR_TOKEN"
env_http_headers = { "X-Provider-Key" = "OPENROUTER_API_KEY" }
tool_timeout_sec = 300

Local server:

~/.codex/config.toml
[mcp_servers.bounty-operator]
command = "npx"
args = ["-y", "https://bountyoperator.com/dl/bounty-operator-mcp.tgz"]
env_vars = ["BOUNTY_OPERATOR_TOKEN", "OPENROUTER_API_KEY"]
tool_timeout_sec = 300

Codex stops a tool call after 60 seconds by default. A hosted review runs for up to 270 seconds, so keep the tool_timeout_sec line.

Cursor

Remote endpointNothing to install

~/.cursor/mcp.json
{
  "mcpServers": {
    "bounty-operator": {
      "url": "https://bountyoperator.com/api/mcp"
    }
  }
}

Add to CursorOpens Cursor and adds the remote endpoint.

Local serverNode 22 or later

~/.cursor/mcp.json
{
  "mcpServers": {
    "bounty-operator": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "https://bountyoperator.com/dl/bounty-operator-mcp.tgz"
      ]
    }
  }
}
Add your account tokenfor account and run_review

Remote endpoint. Cursor fills ${env:NAME} from your environment:

~/.cursor/mcp.json
{
  "mcpServers": {
    "bounty-operator": {
      "url": "https://bountyoperator.com/api/mcp",
      "headers": {
        "Authorization": "Bearer ${env:BOUNTY_OPERATOR_TOKEN}",
        "X-Provider-Key": "${env:OPENROUTER_API_KEY}"
      }
    }
  }
}

Local server:

~/.cursor/mcp.json
{
  "mcpServers": {
    "bounty-operator": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "https://bountyoperator.com/dl/bounty-operator-mcp.tgz"
      ],
      "env": {
        "BOUNTY_OPERATOR_TOKEN": "${env:BOUNTY_OPERATOR_TOKEN}",
        "OPENROUTER_API_KEY": "${env:OPENROUTER_API_KEY}"
      }
    }
  }
}

Use .cursor/mcp.json in a project folder to add the server to that project only.

No account needed for either route. list_profiles, prepare_review for the three core profiles and build_packet work as soon as the server is added. The local package is listed with its SHA-256 in SHA256SUMS.txt.

The tools it exposes

The remote endpoint exposes five tools. Three run with no account, so an agent can prepare a review and package the result on the first call. The local server adds a sixth, run_gauntlet_plan, and reads files by path.

Code security review, Solidity review and Challenge a draft report are the three core profiles. prepare_review hands their request to your agent’s own model. Every other profile runs on the hosted service through run_review, and so do seven of the gauntlet’s stages.

  • list_profiles

    No account

    The review profiles and what each one needs as input. Every profile carries hosted: false for a core profile, true for a hosted one.

  • prepare_review

    No account

    For the three core profiles: runs the privacy check on the files, then returns a SHA-256 manifest and the exact review request. Your agent’s own model answers it. A hosted profile is refused with hosted_profile.

  • run_gauntlet_plan

    No accountLocal server

    The eight gauntlet stages in order, the Context fields still empty and the call that ends the run. The plan names the tool that runs each stage.

  • build_packet

    No account

    Turns a finished review into the evidence packet: the manifest with hashes, your context, the review and a link to verify it.

  • account

    Account token

    Your plan, the reviews used today and when the allowance resets.

  • run_review

    Account tokenProvider key

    A hosted review of any profile on the provider and model you name, and the only way to run a hosted profile. Returns the review, the manifest and your remaining allowance.

A call takes up to 50 text files, 120 KB per file, 240 KB and 20,000 lines in total. File names are repo-relative paths such as src/Vault.sol. When the privacy check blocks a file, the result lists the file, the line and the kind of match, and never the matched text.

The remote endpoint takes file text inline as files. On the local server, prepare_review and run_review also take paths: the server reads those files under its working directory, so your agent does not send the text. A client that starts the server outside your project sets BOUNTY_OPERATOR_ROOT to the project folder.

A first request to try:

Prompt
Use bounty-operator to prepare a Solidity review of src/Vault.sol. Answer the request it returns, then build the packet.

Core and hosted profiles

list_profiles marks every profile. hosted: false is one of the three core profiles: its method is open source and prepare_review hands it to your agent. hosted: true is a hosted profile: the service adds its method when run_review runs and sends it with your files to the provider you named, under your key. It is not in the local package or in the public repository, and no tool or prompt returns it.

For a hosted profile the tools answer like this:

  • list_profiles

    The profile with its name, its description, the inputs it reads and hosted: true.

  • prepare_review

    A failed call with the code hosted_profile, the profile id and a sentence that names run_review. It is refused before any file is read.

  • run_review

    The review, its verdict, the reference check, the manifest and your remaining allowance. It uses one hosted review. verdict and panel run on Operator only.

  • build_packet

    The evidence packet for the review run_review returned. Pass source: "ai".

The refusal, as the remote endpoint returns it for triage:

prepare_review
{
  "profile": "triage",
  "error": "Triager simulation runs on the server. Call run_review with profile \"triage\", your connection token and your provider key in the X-Provider-Key header.",
  "code": "hosted_profile"
}

The local server returns the same code and names BOUNTY_OPERATOR_TOKEN in the sentence. run_review sends the files and your provider key to the service, which adds the method of the profile, calls your provider and returns the review.

Three slash commands

The server ships three prompts. A client that supports MCP prompts lists them as commands. In Claude Code, type / and pick one, or type the full name:

  • /mcp__bounty-operator__challenge-report

    Checks every claim in your draft report against the code it cites, then builds the evidence packet.

  • /mcp__bounty-operator__solidity-review

    Maps entry points and invariants in the contracts you name and reports what the code proves, with file and line.

  • /mcp__bounty-operator__gauntlet

    Takes a finding through the pre-submission stages in order and ends with one verdict. Its hosted stages run through run_review.

challenge-report and solidity-review prepare the review with prepare_review, have your agent’s own model answer and end with build_packet, so both work with no account.

gauntlet lists the eight stages with the tool that runs each one. Seven are hosted and run through run_review. The report stage is a core profile, so your agent’s own model answers it from prepare_review. The run needs an account token and your provider key, and it uses seven hosted reviews. Free covers one hosted review per UTC day, so a full run takes Operator. On the local server the prompt starts from run_gauntlet_plan.

Skills and the plugin

The repository is also a Claude Code plugin with five skills. challenge-report, solidity-review and code-security-review carry the three core methods and run on your agent’s own model with no account. gauntlet runs the eight stages through this server. hunt-with-gate runs only when you call it by name: it checks a finding before any report is written and never submits anything.

Terminal
claude plugin marketplace add bountyoperator/bounty-operator
claude plugin install bounty-operator@bounty-operator

The plugin adds this server too. It reads BOUNTY_OPERATOR_TOKEN and BOUNTY_OPERATOR_PROVIDER_KEY from the environment you start Claude Code in; both can stay unset for the core skills. Codex, Cursor and other agents take the skills with one command and the server with the commands above:

Terminal
npx skills add bountyoperator/bounty-operator

What needs an account token

Works with no token

  • list_profiles
  • prepare_review, for the three core profiles
  • build_packet
  • run_gauntlet_plan, on the local server
  • The challenge-report and solidity-review prompts

Your agent’s own model does the review. Nothing is counted against an allowance.

Needs a token

  • account
  • run_review, with your provider key
  • The gauntlet prompt, which runs its hosted stages with run_review

A hosted review uses the same allowance as the website: one per UTC day on Free, unlimited on Operator at US$10 per week.

Create a token

  1. Sign in at bountyoperator.com with your passkey and open the account panel.
  2. Under Connections, name the connection after the client that will use it, and create it.
  3. Copy the token. It starts with bok_ and is shown once.
  4. Set it as BOUNTY_OPERATOR_TOKEN in your environment and add the server with the token command for your client.

A token lasts 90 days. An account holds three at a time. Revoke one in the account panel and it stops working at once.

Your provider key

run_review runs on your own model key. The remote endpoint takes it in the X-Provider-Key header. The local server reads it from the provider’s environment variable:

ProviderEnvironment variable
OpenRouterOPENROUTER_API_KEY
AnthropicANTHROPIC_API_KEY
OpenAIOPENAI_API_KEY
Google GeminiGEMINI_API_KEY
xAIXAI_API_KEY
DeepSeekDEEPSEEK_API_KEY
MistralMISTRAL_API_KEY
GroqGROQ_API_KEY

The remote endpoint uses the provider’s default model when a call names none. The local server needs a model: pass model, or set BOUNTY_OPERATOR_MODEL.

What the server can reach

  • A token does two things

    It reads your usage and runs a review. Billing, passkeys, recovery and deletion stay behind your passkey. We keep a SHA-256 of the token, its label and its last-used time.

  • The server sees what your agent passes

    The remote endpoint receives file contents as tool arguments and nothing else from your machine. The local server reads only the paths your agent names under its working directory.

  • A hosted review goes through our server

    The run_review tool sends the files and your provider key to bountyoperator.com. The server adds the method of the profile, calls your provider and returns the review. It stores none of it.

  • Keys stay out of the transcript

    The provider key travels in a header or an environment variable, never as a tool argument.

  • Stateless endpoint

    Each request stands alone. There is no MCP session to resume and no stream held open.

  • Local means local

    On the local server, preparing a review, planning a gauntlet and building a packet run on your machine with no network call.

The security page has the full data flow, what is stored and how to report a vulnerability.

When a call fails

A failed tool call comes back as a result with isError set and one JSON object: error, a sentence your agent can act on, and code, a value that does not change. Both servers use the same codes.

  • hosted_profile

    prepare_review was called with a hosted profile. Nothing was read and nothing was counted. Call run_review.

  • privacy_block

    The privacy check found a secret. The result lists the file, the line and the kind of each match. Remove it and call again.

  • privacy_warn

    The privacy check found an email or an IP address. Call again with acknowledgeWarnings: true to send the files as they are.

  • daily_used

    The free review of the day is used. The result carries resetsAt, the time the next one opens.

  • operator_only

    run_review was called with verdict or panel on an account without Operator. Those two profiles run only inside the gauntlet and a panel review. Nothing was sent to the provider and the review of the day is not used.

  • review_running

    The account is running as many reviews as its plan allows. Call again when one finishes.

  • provider

    Your provider refused the call or timed out: a rejected key, an unknown model, a rate limit. The review is not counted.

  • output_withheld

    The model repeated its instructions instead of reviewing, so the answer was stopped and the call used one review. Run it again or choose a stronger model.

account and run_review without a valid token are answered with HTTP 401 by the remote endpoint, which is what makes a client ask for the token. The local server returns the code token.

Questions

Do I need an account to use the MCP server?

No. list_profiles, prepare_review and build_packet work with no account and no key, and so do the challenge-report and solidity-review prompts: your agent’s own model answers the prepared request of a core profile. An account token adds account, run_review for every profile, and the gauntlet prompt.

Should I use the remote endpoint or the local server?

The remote endpoint needs nothing installed and works on any machine the client runs on. The local server needs Node 22 or later, keeps review preparation on your machine, reads files by path and adds run_gauntlet_plan. The other five tools are the same on both.

What does a hosted review cost through MCP?

run_review shares one allowance with the website: one hosted review per UTC day on Free, any profile, and unlimited on Operator at US$10 per week. A gauntlet run over MCP uses seven hosted reviews, one for every stage but the report stage, so a full run takes Operator. Your model provider bills its own usage to your key.

Which profiles can my agent’s own model run?

The three core profiles: Code security review, Solidity review and Challenge a draft report. prepare_review returns their method and the request. Every other profile is hosted: prepare_review refuses it with hosted_profile and run_review runs it on the service, on your provider key.

How do I check the service before a long run?

GET https://bountyoperator.com/api/health returns the version, reviews (whether hosted reviews are on) and profiles. profiles reads hosted when the service carries the full method of every hosted profile. A Worker built from the public repository reads community: it runs the hosted profiles on short stand-in instructions.

Which clients work?

Any client that speaks MCP over Streamable HTTP or stdio. This page has the commands for Claude Code, Codex and Cursor.