Skip to main content
A program tells you what you can test, what is out of scope, and how much each severity pays. Read the full program before you test.

Browse programs

Go to kalligator.com/programs. Use the filters to narrow the list: The list shows only programs with open intake by default.

Read a program

Each program page has these sections. Read all of them before you test.
If an asset is not in Scope, do not test it. Kalligator does not accept reports on assets outside the scope.

Intake and paused programs

  • Open: the program accepts new reports.
  • Paused or Closed: the program does not accept new reports. Start a report is disabled.
A program can also pause new reports when its reward pool is low. The page then shows a notice that new reports are paused until the reward pool is topped up. Reports that you already submitted continue as normal.

Private programs

A private program has a Private label. Only hackers that Kalligator invited by verified email can see it. For all other people, the program does not exist: the page and the API return “not found”. To see private programs that invite you, sign in. With the API, send your key to GET /api/programs.

Find programs with the API

List open web programs
The Authorization header is optional for program routes. Without it, you see only public programs. To read the full policy of one program, use GET /api/programs/{program_id}. The policy fields scope, exclusions, rules, eligibility, and disclosure are Markdown.