Bring your AI client
Use the workbench from your AI.
The local MCP server works with clients that support stdio MCP, including Claude Desktop, Claude Code, Codex and compatible editors. Your AI can prepare a selected-code review, check the allowance, or run a hosted review. It reads only the file contents you supply.
1. Install the local connection
Unzip the package. Install Node.js 22 or later if needed. In the package’s mcp folder, run:
npm ci --ignore-scripts
You can give the downloaded setup instructions to your AI to guide the installation. The instructions contain no account secret.
2. Create your account connection
Sign in on Bounty Operator and open the account portal. Name an AI client connection and download its private settings. Replace the placeholder path with the absolute path to mcp/server.mjs on your computer. Add that configuration to your client’s MCP settings.
The connection secret expires after 90 days. You can revoke it in the portal. Keep the settings file out of chat and source control.
3. Choose how the analysis runs
Use your current AI: ask it to use bounty_check_inputs on the source you select, then review the returned request. Local checks and this request preparation need no account or API key.
Run a hosted review: configure OPENAI_API_KEY or OPENROUTER_API_KEY in the local MCP process, then ask your client to use bounty_review. The provider key is read from your local settings, not from a tool argument. Hosted reviews use the same one-a-day free allowance as the website; Operator removes the daily cap. Provider usage is billed separately.
An ordinary starting request
Review the code I select and am authorized to assess. Use Bounty Operator to check the inputs first. Use the Solidity source review profile if the files are Solidity. Explain observations, defensive fixes and missing evidence. Keep unsupported impact unrated and save the evidence packet.
Available tools
bounty_profiles— list the profiles and local connection state.bounty_check_inputs— privacy checks, manifest and a review request for your current AI.bounty_account— read the shared hosted allowance.bounty_review— run a selected-code review using your configured provider.
The connection has no billing, account-deletion or passkey permissions. The MCP package does not enumerate your filesystem, execute uploaded code, probe targets or submit reports.
Client setup references
See Claude Code’s MCP setup and Codex’s MCP setup. Config formats differ between clients; the package includes the server and its exact dependency lockfile.