> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kalligator.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List programs

> Returns published programs, newest update first. Each filter takes comma-separated values. The API ignores unknown values.

The `Authorization` header is optional. Send it to include the private programs that invite your verified email. An invalid or empty header gives `401`.

`counts[filter][option]` tells you how many programs that option shows, given the other filters.



## OpenAPI

````yaml /api-reference/openapi.json get /api/programs
openapi: 3.1.0
info:
  title: Kalligator API
  description: >-
    The Kalligator API gives you all the hacker functions of the website. Use it
    to find programs, write and submit reports, upload evidence, and reply to
    the triage agent.


    Send `Authorization: Bearer kal_...` with an API key from the **API keys**
    section of your account page. The full guide is at
    https://docs.kalligator.com/api-reference/introduction.
  version: '1'
servers:
  - url: https://kalligator.com
    description: Production
security: []
tags:
  - name: Programs
    description: Published programs that accept reports.
  - name: Reports
    description: Drafts, submission, and withdrawal of your reports.
  - name: Files
    description: Evidence files that you attach to a report or to a message.
  - name: Messages
    description: The thread between you, the triage agent, and the Kalligator team.
  - name: Account
    description: Your account status and payout setup.
  - name: API keys
    description: >-
      Keys that let your agent or script act for you. Key management needs a
      website sign-in.
  - name: Account emails
    description: Email verification and password reset.
paths:
  /api/programs:
    get:
      tags:
        - Programs
      summary: List programs
      description: >-
        Returns published programs, newest update first. Each filter takes
        comma-separated values. The API ignores unknown values.


        The `Authorization` header is optional. Send it to include the private
        programs that invite your verified email. An invalid or empty header
        gives `401`.


        `counts[filter][option]` tells you how many programs that option shows,
        given the other filters.
      operationId: list_programs_api_programs_get
      parameters:
        - name: asset
          in: query
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: Asset
          description: >-
            Asset types. Any of `web`, `api`, `mobile`, `source_code`, `cloud`,
            `hardware`, `other`.
        - name: reward
          in: query
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: Reward
          description: Top reward band. Any of `under_1k`, `1k_5k`, `5k_10k`, `over_10k`.
        - name: updated
          in: query
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: Updated
          description: Last update. One of `any`, `7d`, `30d`.
        - name: intake
          in: query
          required: false
          schema:
            anyOf:
              - type: string
              - type: 'null'
            title: Intake
          description: Intake state. Any of `open`, `paused`, `closed`.
        - name: limit
          in: query
          required: false
          schema:
            type: integer
            maximum: 50
            minimum: 1
            default: 12
            title: Limit
          description: Programs on each page, from 1 to 50.
        - name: page
          in: query
          required: false
          schema:
            type: integer
            minimum: 1
            default: 1
            title: Page
          description: Page number, from 1. A page after the end gives the last page.
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ProgramPage'
        4XX:
          description: '`{detail, code}`; see the error codes in the API description'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        5XX:
          description: Retry after `Retry-After` seconds when it is set
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - {}
        - HTTPBearer: []
components:
  schemas:
    ProgramPage:
      properties:
        programs:
          items:
            $ref: '#/components/schemas/ProgramSummary'
          type: array
          title: Programs
        total:
          type: integer
          title: Total
        page:
          type: integer
          title: Page
        pages:
          type: integer
          title: Pages
        counts:
          additionalProperties:
            additionalProperties:
              type: integer
            type: object
          type: object
          title: Counts
      additionalProperties: false
      type: object
      required:
        - programs
        - total
        - page
        - pages
        - counts
      title: ProgramPage
    Error:
      properties:
        detail:
          type: string
          title: Detail
          description: A message for a person.
        code:
          type: string
          title: Code
          description: A stable `snake_case` error code.
        current:
          anyOf:
            - $ref: '#/components/schemas/Report'
            - type: 'null'
          description: 'Only on `409 revision_conflict`: the stored report.'
      additionalProperties: false
      type: object
      required:
        - detail
        - code
      title: Error
      description: Every error has this body. Make decisions on `code`, not on `detail`.
    ProgramSummary:
      properties:
        id:
          type: string
          title: Id
        name:
          type: string
          title: Name
        customer_name:
          type: string
          title: Customer Name
        intake:
          type: string
          enum:
            - open
            - paused
            - closed
          title: Intake
          description: '`open` accepts reports. `paused` and `closed` do not.'
        demo:
          type: boolean
          title: Demo
          description: '`true` for a demonstration program with test data.'
        summary:
          type: string
          title: Summary
        asset_types:
          items:
            type: string
          type: array
          title: Asset Types
        reward_range:
          $ref: '#/components/schemas/RewardRange'
        rewards:
          additionalProperties:
            type: integer
          propertyNames:
            enum:
              - low
              - medium
              - high
              - critical
          type: object
          title: Rewards
          description: >-
            Reward in US dollars for each severity: `low`, `medium`, `high`,
            `critical`.
        policy_version:
          type: integer
          title: Policy Version
          description: >-
            The version of the program policy and reward table. A report keeps
            the version that it was submitted under.
        updated_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Updated At
        private:
          type: boolean
          title: Private
          description: '`true` if only invited hackers can see the program.'
        pool_paused:
          type: boolean
          title: Pool Paused
          description: >-
            `true` if new submissions are paused because the reward pool is
            below the largest reward.
      additionalProperties: false
      type: object
      required:
        - id
        - name
        - customer_name
        - intake
        - demo
        - summary
        - asset_types
        - reward_range
        - rewards
        - policy_version
        - updated_at
        - private
        - pool_paused
      title: ProgramSummary
    Report:
      properties:
        id:
          type: string
          title: Id
        program_id:
          type: string
          title: Program Id
        program_name:
          type: string
          title: Program Name
        status:
          type: string
          enum:
            - draft
            - triaging
            - needs_info
            - paused
            - human_review
            - accepted
            - rejected
            - duplicate
            - insufficient_info
            - withdrawn
          title: Status
          description: The report status. See the report lifecycle guide.
        display_status:
          type: string
          title: Display Status
          description: The status text that the website shows.
        title:
          type: string
          title: Title
        revision:
          type: integer
          title: Revision
          description: >-
            Increases when you save the draft, upload or remove a file, submit,
            or withdraw. Send the latest value with your next change.
        created_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Created At
        updated_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Updated At
        submitted_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Submitted At
        withdrawn_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Withdrawn At
        asset:
          type: string
          title: Asset
        description:
          type: string
          title: Description
        cvss_vector:
          type: string
          title: Cvss Vector
        attachments:
          additionalProperties:
            $ref: '#/components/schemas/Attachment'
          type: object
          title: Attachments
          description: Files on the report, by file ID.
        submission:
          anyOf:
            - $ref: '#/components/schemas/Submission'
            - type: 'null'
          description: >-
            The frozen copy of the report, files, and program policy at
            submission. `null` for a draft.
        decision:
          anyOf:
            - $ref: '#/components/schemas/Decision'
            - type: 'null'
          description: The final decision and an optional message. `null` until a decision.
        payout:
          anyOf:
            - $ref: '#/components/schemas/Payout'
            - type: 'null'
          description: >-
            Your reward payment. `null` until the Kalligator team approves the
            reward.
      additionalProperties: false
      type: object
      required:
        - id
        - program_id
        - program_name
        - status
        - display_status
        - title
        - revision
        - created_at
        - updated_at
        - submitted_at
        - withdrawn_at
        - asset
        - description
        - cvss_vector
        - attachments
        - submission
        - decision
      title: Report
    RewardRange:
      properties:
        min:
          type: integer
          title: Min
        max:
          type: integer
          title: Max
        currency:
          type: string
          const: USD
          title: Currency
      additionalProperties: false
      type: object
      required:
        - min
        - max
        - currency
      title: RewardRange
    Attachment:
      properties:
        name:
          type: string
          title: Name
        size:
          type: integer
          title: Size
        content_type:
          type: string
          title: Content Type
        sha256:
          type: string
          title: Sha256
          description: The SHA-256 hash of the file bytes.
        storage_path:
          type: string
          title: Storage Path
        state:
          type: string
          enum:
            - uploading
            - ready
            - failed
            - deleting
          title: State
          description: >-
            `ready` files can be referenced and downloaded. `uploading` and
            `failed` files block submission.
        started_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Started At
        uploaded_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Uploaded At
        generation:
          anyOf:
            - type: string
            - type: 'null'
          title: Generation
        reply:
          anyOf:
            - type: boolean
            - type: 'null'
          title: Reply
          description: '`true` for a message file.'
        message_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Message Id
          description: The message that sent the file. `null` while the file waits.
      additionalProperties: false
      type: object
      required:
        - name
        - size
        - content_type
        - sha256
        - storage_path
        - state
        - started_at
      title: Attachment
    Submission:
      properties:
        submitted_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Submitted At
        attachments:
          additionalProperties:
            $ref: '#/components/schemas/Attachment'
          type: object
          title: Attachments
        content:
          $ref: '#/components/schemas/Content'
        program:
          $ref: '#/components/schemas/SubmittedProgram'
        stripe:
          $ref: '#/components/schemas/SubmittedStripe'
      additionalProperties: false
      type: object
      required:
        - submitted_at
        - attachments
        - content
        - program
        - stripe
      title: Submission
    Decision:
      properties:
        outcome:
          type: string
          enum:
            - accepted
            - rejected
            - duplicate
            - insufficient_info
          title: Outcome
        at:
          anyOf:
            - type: string
            - type: 'null'
          title: At
        message:
          anyOf:
            - type: string
            - type: 'null'
          title: Message
      additionalProperties: false
      type: object
      required:
        - outcome
        - at
        - message
      title: Decision
    Payout:
      properties:
        status:
          type: string
          enum:
            - approving
            - transferred
            - received
            - payout_failed
          title: Status
          description: >-
            `approving`, then `transferred`, then `received`. `payout_failed` if
            the bank payout failed.
        amount_cents:
          type: integer
          title: Amount Cents
          description: The reward in US cents.
        approved_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Approved At
        transferred_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Transferred At
        received_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Received At
        payout_failed_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Payout Failed At
      additionalProperties: false
      type: object
      required:
        - status
        - amount_cents
        - approved_at
        - transferred_at
        - received_at
        - payout_failed_at
      title: Payout
      description: >-
        The researcher's view of an approved reward; null until the founder
        approves it.
    Content:
      properties:
        title:
          type: string
          title: Title
        asset:
          type: string
          title: Asset
        description:
          type: string
          title: Description
        cvss_vector:
          type: string
          title: Cvss Vector
          default: ''
      additionalProperties: false
      type: object
      required:
        - title
        - asset
        - description
      title: Content
    SubmittedProgram:
      properties:
        policy_version:
          type: integer
          title: Policy Version
        name:
          type: string
          title: Name
        scope:
          type: string
          title: Scope
        exclusions:
          type: string
          title: Exclusions
        rules:
          type: string
          title: Rules
        eligibility:
          type: string
          title: Eligibility
        disclosure:
          type: string
          title: Disclosure
        rewards:
          additionalProperties:
            type: integer
          propertyNames:
            enum:
              - low
              - medium
              - high
              - critical
          type: object
          title: Rewards
      additionalProperties: false
      type: object
      required:
        - policy_version
        - name
        - scope
        - exclusions
        - rules
        - eligibility
        - disclosure
        - rewards
      title: SubmittedProgram
    SubmittedStripe:
      properties:
        status:
          type: string
          title: Status
        checked_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Checked At
      additionalProperties: false
      type: object
      required:
        - status
        - checked_at
      title: SubmittedStripe
  securitySchemes:
    HTTPBearer:
      type: http
      description: A Firebase ID token, or a Kalligator API key (`kal_…`).
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.