Connect your source code repositories to H1 Code to enrich HackerOne workflows with repository information and code-derived context. During setup, you temporarily leave HackerOne to verify your identity in H1 Code and authorize your repository provider.
This article explains the connection process, the information H1 Code can access, and how repository permissions relate to HackerOne permissions.
Before You Begin
Before you connect a repository, make sure you:
Are an Organization Admin for your HackerOne organization
Are an organization owner for your source code management provider.
Can sign in to your HackerOne account.
Connect Code Repositories
Sign in to HackerOne and navigate to the Repositories page in your organization’s settings. This page is only available to those with Organization Admin permissions.
Select Connect repositories.
Review the Continue to H1 Code dialog.
Select Continue to H1 Code.
Sign in with your HackerOne account if prompted.
Review the repository access disclosure in HackerOne
Select Continue to H1 Code to authorize access.
Complete identity verification in H1 Code.
Select your source code management provider.
Complete the authorization process in your repository provider.
The authorization process may ask you to select all repositories or specific repositories and review the requested permissions before completing the installation.
You will be redirected back to H1 Code to complete the installation process
Once the installation completes, you will land on the Account Integrations page under User Settings to confirm that your H1 organization is linked in H1 Code.
Click “Open in HackerOne” to return to HackerOne and confirm that the repositories are connected to your organization in HackerOne.
Why You’re Sent to H1 Code
Repository connections use H1 Code to verify your HackerOne identity and manage repository provider authorization.
Although you temporarily leave the HackerOne application during setup, H1 Code is a HackerOne product. The sign-in process confirms your identity before repository configuration continues.
Information H1 Code Can Access
During setup, H1 Code can access limited information from your HackerOne account, including:
Your basic HackerOne profile.
Your email address.
Confirmation that you have permission to manage repository connections for the organization.
Repository Data Used by H1 Code
After you authorize your repository provider, H1 Code may use repository information to support HackerOne workflows.
Depending on your configuration, this information may include:
Repository names.
Repository URLs.
Repository metadata.
Default branch information.
Repository provider account information.
Derived code context.
Repository-Derived Information in HackerOne
Repository information can provide additional context within HackerOne.
Depending on the feature and your organization’s configuration, HackerOne may display:
Relevant source code snippets.
Security evidence.
Remediation suggestions.
Dependency information.
Configuration context.
Security insights.
These outputs may appear in HackerOne assets, programs, findings, reports, or other organization workflows.
Understanding Permissions
Repository provider permissions and HackerOne permissions are managed separately.
A user who can view information in HackerOne may not have direct access to the associated repository through the source code provider. Repository-derived information may still appear in HackerOne when the user has permission to view the related organization, program, report, or engagement.
For example, a user may be able to view code-derived context attached to a HackerOne report without having permission to open the source repository directly.
Manage or Revoke Access
Repository connections must be managed from within H1 Code and/or the connected source code provider’s website. For GitHub and Bitbucket, access is directly revoked from the provider's website (e.g., GitHub Settings → Applications → Configure). H1 Code will automatically detect and reflect the change. For GitLab and Azure DevOps, revoking access must be done through H1 Code; removing the app on the provider's website alone will not cleanly disconnect your repositories, and you'll need to also uninstall from within H1 Code to ensure data is cleaned up.
Supported Repository Providers
Supported source code providers include:
Cloud Integrations: GitHub, GitLab, Bitbucket, Azure DevOps
On-premises Integrations: GitHub, GitLab, Bitbucket, Azure DevOps
Note: If support for on-premises source code management providers is needed, additional steps outside of the described repository connection flow are required. Please reach out to your HackerOne accounts manager or representative for help.
Troubleshooting
If you experience issues connecting a repository:
Verify that you are signed in with the correct HackerOne account.
Confirm that you have permission to configure repository integrations.
Verify that you have the required permissions in your repository provider.
Restart the authorization process.
Frequently Asked Questions
Why Am I Being Sent from HackerOne to H1 Code?
H1 Code handles identity verification and repository provider authorization before repository configuration continues. Although the setup process temporarily moves you to another domain, H1 Code is a HackerOne product.
What Does H1 Code Access in My HackerOne Account?
H1 Code accesses your basic HackerOne profile information and email address. It also verifies that you have permission to manage repository connections for your organization.
What Does H1 Code Request from My Repository Provider?
H1 Code requests permission to access the repository information needed to configure repository connections and support HackerOne workflows.
GitHub
Read access to code, members, and metadata
Read and write access to commit statuses, issues, and pull requests
GitLab
Read and write access to the API, including all groups and projects, the container registry, the dependency proxy, and the package registry
Read-only access to user profile information such as username, public email, and full name
Read-only access to container registry images on private projects
Bitbucket
Read your account information
Read your team membership information
Administer your repositories
Read your repositories and their pull requests
Read your repositories’ issues
Azure DevOps
Code (read)
Pull Request Threads (Read & write)
What Repository Information May Appear in HackerOne?
Repository metadata and repository-derived information may appear in supported HackerOne workflows. This information may include code context, remediation suggestions, dependency information, and security insights.
Who Can View Repository-Derived Information?
Repository-derived information is available based on the HackerOne organization, program, report, or engagement permissions. Access in HackerOne does not equate to access in the repository provider.
How Do HackerOne Permissions Differ from Repository Provider Permissions?
Repository provider permissions control access to the source repository. HackerOne permissions control access to information displayed within HackerOne workflows.
The two permission models operate independently.
Where Can I Manage or Revoke Access?
Repository connections may be managed through H1 Code and the connected source code provider’s website. To add or remove repository connections, return to the HackerOne Repositories page and go through the flow again. You will be routed back to the source code management configuration page in H1 Code to do one of the following:
Add a new source code management provider integration (multiple source code management provider integrations are supported for a single organization)
Configure repository connections for an existing source code management provider integration
What Should I Do if I Use Open-Source or On-Premises Repositories?
Setting up a self-hosted/on-premises environment requires additional support from the HackerOne technical support team.






