Bring your own model
Your model, your key: where your code goes
A review runs on the model you choose, under your own API key: OpenRouter, Anthropic, OpenAI, Google Gemini, xAI, DeepSeek, Mistral or Groq. Your files and your key pass through our server in memory. It adds the review method and sends the request to that provider. Bounty Operator stores no code, no prompts, no keys and no results.
No key at hand: export the prompt of a core profile to your chat app, with no daily limit.
- Key
- Yours. Used for the one request it belongs to.
- Files
- Sent through our server to the provider you choose. Not stored by Bounty Operator.
- Method
- Added on our server. Open source for the three core profiles.
- Providers
- 8, each called at one fixed endpoint
- Chat plan
- Prompt export of a core profile, then paste the answer back
- Coding agent
- MCP: prepare a core review, or run any profile hosted
- Record
- A packet with a SHA-256 manifest of every file
Where your code goes
A hosted review has three stops. Each one is listed with what it does to your files.
-
Your browser
- Reads the files you choose.
- Runs the privacy check on every file and on your instructions.
- Shows the request before it leaves the tab.
- Hashes each file with SHA-256 and builds the review packet you download.
-
bountyoperator.com
- Receives your files, your request and your API key.
- Checks your allowance and runs the privacy check again.
- Adds the review method of the profile you picked and sends the request, with your key, to one fixed endpoint of the provider you chose.
- Streams the review back. Writes none of it to the database or to logs.
-
Your provider
- Receives your files, your request and our review instructions.
- Runs the model you picked.
- Bills the usage to your account.
A GitHub import goes from your browser straight to api.github.com at a pinned commit. The repository is never uploaded to our server.
Three ways to run a review
Same output format, same packet.
Hosted review, your API key
Paste a key from one of eight providers and run the review in the workbench. It goes through our server to your provider, and the answer streams into finding cards.
- Every profile, the Gauntlet and Panel review
- Free: 1 hosted review per UTC day, any single profile
- Operator: unlimited, four at once
- The key is used for that request only
Prompt export, your chat subscription
For the three core profiles the workbench hands you the full prompt as one document. Paste it into your chat app or a local model, then paste the answer back.
- Code security review, Solidity review, challenge a draft report
- No API key, no account and no daily limit
- Your files stay in your browser until you paste the prompt
- Paste-back gives you the same cards and packet
MCP, your coding agent
Connect an agent to the MCP server. prepare_review builds the request of a core profile for the agent’s own model. run_review runs any profile as a hosted review, and is the one way to run a hosted profile from an agent.
list_profiles,prepare_reviewandbuild_packetneed no accountrun_reviewneeds a connection token from your account- Your provider key travels in the
X-Provider-Keyheader, never as a tool argument
Who holds the key
You do.
You create the key in your provider’s console and paste it into the workbench when you run a review. It travels with that request to our server, goes on to the provider’s endpoint, and is gone when the request ends.
Each provider is called at one fixed endpoint. A redirect is refused. An error message from the provider is shown to you with the key removed.
Model usage is billed by the provider to the account that owns the key. Operator is a flat US$10 per week for the hosted workbench and does not include model usage.
The privacy check
It runs before anything is sent, in your browser and again on the server.
- Private keys, API keys, GitHub and Slack tokens, wallet keys and seed phrases block the request.
- A file that normally holds credentials blocks the request.
- An email address or a public IP address asks you to confirm before sending.
- A finding names the file and the line. It never repeats the secret.
Up to 50 files, 120 KB per file, 240 KB and 20,000 lines in total.
What is stored
The full list is on the privacy page, and the security page shows how it is protected. This is the short version.
Never stored
- Your files and your code
- Your prompts and review instructions
- Your provider API key and any GitHub token
- The review the model returns
Stored
- A random account identifier, passkey public keys and a hashed recovery code.
- Hashed session tokens and hashed connection tokens, with their labels and last-use times.
- Review activity for up to seven days: status, profile, web or MCP, timestamps. It enforces the daily allowance.
- Billing references from Stripe: customer and subscription ids, status, paid-until and the receipt email.
- Daily totals per page and per event, with no account identifier.
Providers supported
One key from any of these runs every single profile. The default model is preselected and the others are suggestions in the model list.
| Provider | Default model | Also suggested | Key starts with | Create a key |
|---|---|---|---|---|
| OpenRouter | Default modelanthropic/claude-sonnet-5.5 | Also suggestedanthropic/claude-opus-5.5openai/gpt-6-astragoogle/gemini-3.8-flashx-ai/grok-4.7 | Key starts withsk-or- | Create a keyopenrouter.ai |
| Anthropic | Default modelclaude-opus-5-5 | Also suggestedclaude-sonnet-5-5claude-fable-5-1claude-haiku-4-5 | Key starts withsk-ant- | Create a keyconsole.anthropic.com |
| OpenAI | Default modelgpt-6.1-sol | Also suggestedgpt-6-astragpt-6-luna | Key starts withsk- | Create a keyplatform.openai.com |
| Google Gemini | Default modelgemini-3.8-flash | Also suggestedgemini-3.1-pro-previewgemini-3.5-flash-lite | Key starts withAIza | Create a keyaistudio.google.com |
| xAI | Default modelgrok-4.7 | Also suggestedgrok-4.6grok-4.3 | Key starts withxai- | Create a keyconsole.x.ai |
| DeepSeek | Default modeldeepseek-v4-pro | Also suggesteddeepseek-flash | Key starts withsk- | Create a keyplatform.deepseek.com |
| Mistral | Default modelmistral-medium-latest | Also suggestedmistral-large-2512mistral-small-latest | Key starts withNo fixed prefix | Create a keyconsole.mistral.ai |
| Groq | Default modelopenai/gpt-oss-120b | Also suggestedqwen/qwen3.8-27bopenai/gpt-oss-20b | Key starts withgsk_ | Create a keyconsole.groq.com |
Questions
Can I use my ChatGPT or Claude subscription?
Yes, for the three core profiles: code security review, Solidity review and challenge a draft report. Export the prompt, paste it into your chat app and paste the answer back. The workbench turns the answer into finding cards and a packet. A hosted review needs an API key, which providers bill separately from a chat subscription.
Does Bounty Operator see my API key?
The key passes through our server in memory for the one request it belongs to and goes to your provider’s endpoint. It is not written to the database or to logs.
What does your server add to my request?
The review instructions: the output format every review shares, and the method of the profile you picked. The three core profiles carry their method in the open, so their preview is the whole prompt. Every other profile is hosted: the preview shows the request that leaves your tab, with your focus, your context and the files, and the server adds the method before it goes to your provider.
Who bills the model usage?
Your provider, on your key. Operator at US$10 per week covers the hosted workbench: unlimited reviews, the Gauntlet, Panel review and four reviews running at once.
What does the provider keep?
The provider processes the request under its own terms and retention settings. Read them for the key you use, and run a review only on material you are allowed to share with that provider.
Which key does Panel review use?
One OpenRouter key covers a whole panel: it reaches models from several labs, so two to four different models review the same files. A panel model on another provider takes that provider’s own key.
Run it on the model you already pay for
Paste a key, or export the prompt of a core profile to your chat app.
Free: 1 hosted review per UTC day. No card.