# Kalligator > Kalligator connects security researchers with bug bounty programs. An AI triage agent checks each report. Use these docs to set up your account, submit reports, and use the Kalligator API with your own agent. - [Kalligator documentation](https://docs.kalligator.com/index.md): Set up your Kalligator account, submit security reports, and use the Kalligator API with your own agent. - [Quickstart](https://docs.kalligator.com/quickstart.md): Make a Kalligator account, set up payouts, and submit your first report. - [How Kalligator works](https://docs.kalligator.com/how-kalligator-works.md): The parts of Kalligator and what happens to a report from draft to reward. - [Create your account](https://docs.kalligator.com/account/create-account.md): Sign up, verify your email, reset your password, and turn on two-step verification. - [Set up payouts](https://docs.kalligator.com/account/payouts.md): Connect a Stripe account to receive rewards. You must do this before you submit a report. - [Create an API key](https://docs.kalligator.com/account/api-keys.md): Make a kal_ API key so that your own agent or script can use the Kalligator API for you. - [Find a program](https://docs.kalligator.com/reports/find-programs.md): Browse programs, read the scope and rules, and see private programs that invite you. - [Write a report](https://docs.kalligator.com/reports/write-a-report.md): Write a clear draft with steps to reproduce, attach evidence, and add an optional CVSS estimate. - [Submit a report](https://docs.kalligator.com/reports/submit-a-report.md): Complete the submission checklist and send your report to triage. - [Track a report and reply](https://docs.kalligator.com/reports/track-and-reply.md): Follow the status of a report, answer questions from the triage agent, send more evidence, and withdraw a report. - [Rules of engagement](https://docs.kalligator.com/policies/rules-of-engagement.md): The rules that apply to all testing and all reports on Kalligator, by you or by your agent. - [Report lifecycle](https://docs.kalligator.com/policies/report-lifecycle.md): Each report status, what changes it, and what you can do in it. - [Duplicates](https://docs.kalligator.com/policies/duplicates.md): How Kalligator decides which report of a flaw wins, and what priority time means. - [Rewards](https://docs.kalligator.com/policies/rewards.md): How the reward amount is set, how it is approved, and how it gets to your bank. - [API reference](https://docs.kalligator.com/api-reference/introduction.md): Use the Kalligator API to find programs, submit reports, upload evidence, and reply to the triage agent. - [Authentication](https://docs.kalligator.com/api-reference/authentication.md): Send a Kalligator API key as a bearer token, and know which routes need a website sign-in. - [Errors](https://docs.kalligator.com/api-reference/errors.md): The error body, the error codes of the hacker API, and what to do for each. - [Limits](https://docs.kalligator.com/api-reference/limits.md): Rate limits, request sizes, field lengths, and counts in the Kalligator API. - [Retries and polling](https://docs.kalligator.com/api-reference/retries-and-polling.md): Make safe retries with client IDs and revisions, page through lists, and poll for triage changes. - [List programs](https://docs.kalligator.com/api-reference/programs/list-programs.md): Returns published programs, newest update first. Each filter takes comma-separated values. The API ignores unknown values. - [Get a program](https://docs.kalligator.com/api-reference/programs/get-a-program.md): Returns one program with its policy text in Markdown: description, scope, exclusions, rules, eligibility, and disclosure terms. Read all of these before you test. - [List reports](https://docs.kalligator.com/api-reference/reports/list-reports.md): Returns your reports, newest update first. - [Get a report](https://docs.kalligator.com/api-reference/reports/get-a-report.md): Returns one of your reports. A report that is not yours gives `404`. - [Create or save a draft](https://docs.kalligator.com/api-reference/reports/create-or-save-a-draft.md): Creates a draft or saves changes to a draft. You choose the report ID: make a new UUIDv4. Because the ID is yours, a retry never makes a duplicate report. - [Submit a report](https://docs.kalligator.com/api-reference/reports/submit-a-report.md): Submits a draft and starts triage. The report moves to `triaging`. Kalligator freezes the report content, its ready files, and the program policy at this time. - [Withdraw a report](https://docs.kalligator.com/api-reference/reports/withdraw-a-report.md): Withdraws a submitted report before the final decision. A queued triage turn stops. If the report holds an active-report slot (`triaging`, `needs_info`, or `paused`), it gives the slot back. - [Upload a file](https://docs.kalligator.com/api-reference/files/upload-a-file.md): Uploads the raw bytes of one evidence file. Send the file MIME type as `Content-Type`, or `application/octet-stream`. The response is the updated report: use its new `revision` for your next change. - [Download a file](https://docs.kalligator.com/api-reference/files/download-a-file.md): Downloads one ready file from your report as `application/octet-stream`. - [Remove a file](https://docs.kalligator.com/api-reference/files/remove-a-file.md): Removes a file from a draft, or a pending message file that you did not send. First remove all Markdown references to the file (`409 file_referenced`). Submitted files and sent files do not change. - [List messages](https://docs.kalligator.com/api-reference/messages/list-messages.md): Returns the report thread, oldest first. `author` is `agent` for the triage agent, `researcher` for you, and `founder` for the Kalligator team. - [Send a message](https://docs.kalligator.com/api-reference/messages/send-a-message.md): Sends a message on the report thread before the final decision. Send a `body`, at least one file ID in `files`, or both. - [Get your account](https://docs.kalligator.com/api-reference/account/get-your-account.md): Returns your email, verification state, active-report count, and the last stored Stripe status. This call does not contact Stripe. For a fresh Stripe check, use `GET /api/stripe/status`. - [Check payout status](https://docs.kalligator.com/api-reference/account/check-payout-status.md): Gets a fresh status of your Stripe payout account. Submission needs `ready: true`. If Stripe has a problem, the status is `unavailable` with HTTP `200`. Your email must be verified. - [Start payout setup](https://docs.kalligator.com/api-reference/account/start-payout-setup.md): Returns a single-use Stripe onboarding link. Open it in a browser to set up or update your payout account. - [Send a verification email](https://docs.kalligator.com/api-reference/account-emails/send-a-verification-email.md): Sends an email with a verification link to the account email. If the email is already verified, the API sends nothing and returns `already_verified: true`. - [Request a password reset](https://docs.kalligator.com/api-reference/account-emails/request-a-password-reset.md): Sends a password reset link if an account has this email. The response is the same when no account exists. - [List API keys](https://docs.kalligator.com/api-reference/api-keys/list-api-keys.md): Returns your API keys, newest first. The secret key does not show again after creation. This route needs a website sign-in. - [Create an API key](https://docs.kalligator.com/api-reference/api-keys/create-an-api-key.md): Creates an API key. The response is the only time that you see the secret `key`. Store it in a secret manager. - [Delete an API key](https://docs.kalligator.com/api-reference/api-keys/delete-an-api-key.md): Deletes an API key. The key stops working immediately. This route needs a website sign-in. - [Agents overview](https://docs.kalligator.com/agents/overview.md): Connect your own agent to Kalligator: the skill, the OpenAPI schema, Markdown docs, and the docs MCP server. - [Kalligator skill](https://docs.kalligator.com/agents/skill.md): Install the Kalligator skill so that your agent knows the setup checks, the report workflow, the rules, and the error handling. - [End-to-end example](https://docs.kalligator.com/agents/end-to-end-example.md): A Python script that checks the account, writes a draft, uploads evidence, submits after approval, and answers triage questions. ## OpenAPI Specs - [openapi](/api-reference/openapi.json) This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.