Immunefi · Authentication Profile

Immunefi Authentication

Authentication

Immunefi declares 0 security scheme(s) across its OpenAPI definitions.

CompanySecurityBug BountyVulnerability DisclosureWeb3BlockchainSmart ContractsApplication SecurityCryptocurrencyCrowdsourced Security
Methods: Schemes: 0 OAuth flows: API key in:

Security Schemes

Source

Authentication Profile

immunefi-authentication.yml Raw ↑
generated: '2026-08-23'
method: probed
source: https://immunefi.com/public-api/bounties.json
note: >-
  Immunefi publishes no OpenAPI and no authentication documentation, so this profile was
  established by probe rather than from a spec. The single public endpoint was fetched with no
  credentials, no cookie and no Authorization header and returned HTTP 200 with 6,498,795 bytes of
  application/json, so anonymous access is confirmed, not assumed. Authenticated surfaces exist
  (the researcher application at bugs.immunefi.com and the Magnus customer console) but their
  contracts are not public.
security_schemes:
- name: none
  type: none
  in: null
  scheme: null
  description: >-
    No credential of any kind is required or accepted on the public bounty-programs endpoint.
  applies_to:
  - GET https://immunefi.com/public-api/bounties.json
  evidence:
    url: https://immunefi.com/public-api/bounties.json
    method: GET
    request_headers_sent: [User-Agent]
    http_status: 200
    content_type: application/json
    bytes: 6498795
    fetched: '2026-08-23'
oauth2: false
openid_connect: false
api_keys: false
mutual_tls: false
gated_surfaces:
- name: Immunefi Bugs researcher application
  url: https://bugs.immunefi.com/
  status: 200
  note: >-
    Client-rendered application. No public API contract; account-based sign-in. Its
    /.well-known/* paths return a Next.js 404 shell.
- name: Immunefi support knowledge base
  url: https://immunefisupport.zendesk.com/hc/en-us
  status: 403
  note: >-
    Cloudflare interactive bot challenge ("Enable JavaScript and cookies to continue"), not an
    Immunefi authorization gate. A human browser reaches the same pages; our probe was turned
    away, so any auth detail documented there could not be read.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/immunefi-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.