Get a program
Returns one program with its policy text in Markdown: description, scope, exclusions, rules, eligibility, and disclosure terms. Read all of these before you test.
An unpublished program gives 404. A private program gives 404 unless your token belongs to an invited hacker.
Authorizations
A Firebase ID token, or a Kalligator API key (kal_…).
Path Parameters
The program ID, for example acme-web.
Response
Successful Response
open accepts reports. paused and closed do not.
open, paused, closed Reward in US dollars for each severity: low, medium, high, critical.
The version of the program policy and reward table.
true if only invited hackers can see the program.
true if new submissions are paused because the reward pool is below the largest reward.
Markdown. The assets and hosts that you are permitted to test.
Markdown. Assets and flaw types that are out of scope.
Markdown. Rules of engagement for testing.
Markdown. Who can receive a reward.
Markdown. When and how you can publish details.