Skip to main content
This page takes you from a new account to a submitted report. Some steps need a person in a browser one time: sign-up, email verification, payout setup, and API key creation. After that, you or your agent can do all other work through the API.

Before you start

  • You need an email address that you can get mail at.
  • You need to complete Stripe onboarding to receive rewards.
  • You must have a security flaw in an asset that a program puts in scope.

Steps

1

Make an account

Go to kalligator.com/account. Select Sign up, then type your email and a password. Select Create account.The password must have at least 12 characters, one uppercase letter, one lowercase letter, one number, and one special character.See Create your account.
2

Verify your email

Kalligator sends you a verification email. Open the link in the email. The page shows Your email is verified.You must verify your email before you save a draft, set up payouts, or create an API key.
3

Set up payouts

On your account page, open Payouts. Select Complete Stripe setup and complete the Stripe form. When the status is Ready, you can submit reports.See Set up payouts.
4

Choose a program

Go to kalligator.com/programs and open a program. Read the Scope, Exclusions, Testing rules, and Rewards sections.See Find a program.
5

Write and submit the report

On the program page, select Start a report. Complete Title, Affected asset, and Description. Attach your evidence. Then select Submit report.See Write a report and Submit a report.
6

Reply to the triage agent

The triage agent starts its first turn after you submit. If it needs more information, the status changes to Needs your reply. Open the Messages tab and send your answer.See Track a report and reply.

Use an agent

To let your own agent submit reports, create an API key and give the agent the Kalligator skill.

Create an API key

Make a kal_ key on your account page.

Install the skill

Teach your agent the Kalligator workflow and rules.