A security.txt, VDP, or bug-bounty program gives researchers a defined way to report vulnerabilities. Signals a provider that expects and handles security findings.
6 API providers on the APIs.io network offer vulnerability disclosure & bug bounty. The highest-rated are Packagist, Cybereason, BeyondTrust, Cresta, US Cyber Command.
Providers
Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.
This feature is a canonical term. These are the free-text strings
providers wrote in their own apis.yml that map onto it.
Joint Cybersecurity AdvisoriesRFC 9116 security.txt with HackerOne submission form and PGP keySecurity advisories API aggregating FriendsOfPHP, GitHub Advisory Database, and PSA sourcesVulnerability Management
Every feature here is available over the APIs.io API and to AI agents over MCP. Features is not yet its own endpoint on the v1 API. Reach it through catalog search and the tag graph, or the MCP server.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for features
3 MCP tools reach this
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.