The platform is built on a REST API at https://api.<domain>/v1. The full, generated reference is at /reference.
X-Client-Key. Nothing in the API is reachable without it, except with a personal API key (below).Authorization: Bearer <access token>. Access tokens last 15 minutes; POST /v1/tokens exchanges the refresh token for a new pair (refresh tokens rotate on every use).POST /v1/login-challenges (password) → second factor (/verification, /email-codes, /totp-enrollment) → POST /v1/sessions.The staff API is a separate service on a private network and is not documented publicly.
Researchers and companies can use the API from their own scripts. Create a key in Settings → API keys (you need your password), then call api.rootbounty.com directly:
curl -H "Authorization: Bearer rbp_…" https://api.rootbounty.com/v1/me/reports
x-personal-key-scope in the API reference.GET collections accept ?page=&perPage= (max 100) and return:
{ "data": [ … ], "meta": { "page": 1, "perPage": 25, "total": 330, "totalPages": 14 } }
with Link (first, prev, next, last) and X-Total-Count headers.
Errors are RFC 9457 problem details (application/problem+json):
{
"type": "about:blank",
"title": "Validation failed",
"status": 422,
"detail": "Title: 10–200 characters.",
"errors": [{ "field": "title", "message": "Title: 10–200 characters." }],
"requestId": "…"
}
Machine-readable reasons come in code (for example invalid_client, account_pending_approval, posting_locked, rate_limited). Quote requestId when contacting support.
Sign-in, sign-up, reports, comments, uploads and posts are limited per account or network. Limited calls answer 429 with a Retry-After header.