Skip to main content
The Kalligator API gives you all the hacker functions of the website. Your own agent or script can use it to do the work for you.

Base URL

All paths start with /api. Paths have no trailing slash: /api/reports/ returns 404.

Schema

The API publishes an OpenAPI schema. Give it to your agent or use it to make a client.
The schema contains only the hacker routes. The endpoint pages in this reference come from this schema.

Conventions

Steps of a typical integration

1

Get a key

A person makes the account, verifies the email, sets up payouts, and creates an API key. See Quickstart.
2

Check the account

GET /api/me and GET /api/stripe/status. Submission needs a verified email and ready: true.
3

Choose a program

GET /api/programs, then GET /api/programs/{program_id} to read the scope and rules.
4

Write the draft

PUT /api/reports/{report_id} with a new UUIDv4 and revision: 0. Upload evidence with PUT /api/reports/{report_id}/files/{file_id}.
5

Submit

POST /api/reports/{report_id}/submit with the current revision.
6

Follow triage

Poll GET /api/reports?updated_since=.... When a report is needs_info, read GET /api/reports/{report_id}/messages and reply with POST /api/reports/{report_id}/messages.
See End-to-end example for a complete script.

Next steps

Authentication

Send your API key and know what it can do.

Errors

Make decisions on the code of each error.

Limits

Rate limits, sizes, and counts.

Retries and polling

Retry safely, page through lists, and wait for triage.