Skip to main content

API Token

Hackers: Generate an API token

Introduction

You can generate a personal API token to experiment with or use the HackerOne API. This article explains how to generate a token, how to use it to authenticate your API requests, and how to revoke it if needed.

If you are setting up an integration or testing the Hacker API, you will need this token to authenticate your requests.

Using Your API Token for Authentication

When authenticating to the Hacker API, use your HackerOne username and your API token value.

  • Use your HackerOne username as the username.

  • Use your generated API token value as the credential.

Note: There is no separate “token identifier” for personal Hacker API tokens. The identifier referenced in older documentation refers to your HackerOne username.

Generating a Personal API Token

To generate a personal API token:

  1. Sign in to your HackerOne account.

  2. Go to the API Token page in your account settings.

  3. Click Generate API token. This revokes any previously generated token.

  4. Copy the token value and store it securely. The token is only shown once.

Warning: If you lose the token value, you must generate a new token. You will not be able to view it again.

Revoking Your API Token

To revoke a token, you can:

  • Click Generate API token to create a new token; this automatically revokes the previous one.

  • Click Click here on the API Token settings page to manually revoke the existing token.

Next Steps

After generating your token, use your HackerOne username and the token value to authenticate your API requests. If you encounter authentication errors, confirm that you are using your correct username and the most recently generated token.

Did this answer your question?