Skip to main content
GET
Get a program

Authorizations

Authorization
string
header
required

A Firebase ID token, or a Kalligator API key (kal_…).

Path Parameters

program_id
string
required

The program ID, for example acme-web.

Response

Successful Response

id
string
required
name
string
required
customer_name
string
required
intake
enum<string>
required

open accepts reports. paused and closed do not.

Available options:
open,
paused,
closed
demo
boolean
required
summary
string
required
asset_types
string[]
required
reward_range
RewardRange · object
required
rewards
Rewards · object
required

Reward in US dollars for each severity: low, medium, high, critical.

policy_version
integer
required

The version of the program policy and reward table.

updated_at
string | null
required
private
boolean
required

true if only invited hackers can see the program.

pool_paused
boolean
required

true if new submissions are paused because the reward pool is below the largest reward.

description
string
required
scope
string
required

Markdown. The assets and hosts that you are permitted to test.

exclusions
string
required

Markdown. Assets and flaw types that are out of scope.

rules
string
required

Markdown. Rules of engagement for testing.

eligibility
string
required

Markdown. Who can receive a reward.

disclosure
string
required

Markdown. When and how you can publish details.