> For the complete documentation index, see [llms.txt](https://bugrecon.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://bugrecon.gitbook.io/docs/features-list/modules/integration.md).

# Integration

The Integration module connects BugRecon to bug bounty platforms so you can keep your projects and scope in sync with your programs. Synchronization supports multiple platforms from a single configuration.

> **Security notice:** Your integration configuration file is stored **encrypted** on our systems. No application administrator or system administrator can access its contents. We take the security of your data extremely seriously.\
> By connecting your accounts, you enable synchronization and can take advantage of automated scans triggered when your bug bounty program scope changes.

**Scenario: Sync → automated scans → async alerts** - When you synchronize, new or updated domains can trigger scans automatically (depending on your [Automation](/docs/features-list/automation.md) settings). Results are sent asynchronously via notifications, so you stay informed without watching the interface.

![Integration](https://1075470145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FV2n4UTcrS4SHhY2NTi0v%2Fuploads%2Fgit-blob-9d49438ca8c399060c2fa74a0bff799e5179d52b%2Fintegration.png?alt=media)

![Integration](https://1075470145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FV2n4UTcrS4SHhY2NTi0v%2Fuploads%2Fgit-blob-e588429e144d4d922257416fe057ae86d357e983%2Fintegration2.png?alt=media)

![Integration](https://1075470145-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FV2n4UTcrS4SHhY2NTi0v%2Fuploads%2Fgit-blob-34075f859434944fab57f21b474ec7204823603d%2Fintegration3.png?alt=media)

## Supported platforms

* **YesWeHack** – #1 Bug Bounty and Vulnerability Management Platform in Europe
* **HackerOne** – Global security platform for hackers and organizations
* **Bugcrowd** – Crowdsourced security and bug bounty platform
* **Intigriti** – European bug bounty and vulnerability disclosure platform

## Managing program processes

BugRecon manages program lifecycles identically across all platforms (YesWeHack, HackerOne, Bugcrowd, Intigriti). The same sync flow and behaviors apply regardless of which platform you connect.

### Sync flow (all platforms)

1. **Start sync** - Click **Synchronize** on the platform card (Integration page) or schedule a sync task ([Tasks](/docs/features-list/modules/tasks.md) → type: YesWeHack Sync Scopes, HackerOne Sync Scopes, Bugcrowd Sync Scopes, or Intigriti Sync Scopes).
2. **Check** - BugRecon fetches programs and scope from the platform and compares them to your existing projects.
3. **Preview** - You see what will be created, updated, reactivated, or disabled (on manual sync; scheduled tasks apply changes directly).
4. **Apply** - Confirm to apply changes (manual sync) or let the scheduled task complete automatically.

### Program lifecycle

| Action         | Description                                                                                                            |
| -------------- | ---------------------------------------------------------------------------------------------------------------------- |
| **Create**     | New programs (not yet in BugRecon) are turned into new projects with one scope per program.                            |
| **Update**     | Existing programs get their scope updated: new targets are added, removed targets are taken out.                       |
| **Reactivate** | Programs that were previously disabled (e.g. you lost access, then regained it) are re-enabled.                        |
| **Disable**    | Programs no longer returned by the platform (e.g. removed from your access) have their project disabled (not deleted). |

### Wildcard scopes

Wildcard targets (`*.example.com`) are kept in a scope's domain list so that wildcard-only automation (subdomain enumeration, CertStream monitoring) works.

**Bugcrowd caveat.** Bugcrowd's scope, as fetched, does not distinguish a wildcard (`*.example.com`) from an apex-only target (`example.com`): both arrive as the bare apex `example.com`. BugRecon does **not** guess - it stores the apex exactly as received, so a scope is never silently widened to subdomains you are not authorized to test. If a Bugcrowd target is actually a wildcard, add the `*.` yourself in the scope's domain list (Scope page, or `PATCH`/`POST /api/v1/scopes/{id}/subdomains`).

**Your wildcards survive re-syncs.** Once you promote a flat apex `example.com` to `*.example.com`, later synchronizations treat `example.com` (from the platform) and your stored `*.example.com` as the same target: the wildcard is neither removed nor reverted to the flat apex. Other platforms (YesWeHack, HackerOne, Intigriti) already provide the `*.` prefix and are unaffected.

### Platform-specific credentials

| Platform  | YAML config section | Required credentials             |
| --------- | ------------------- | -------------------------------- |
| YesWeHack | `yeswehack`         | `email`, `password`, `otpsecret` |
| HackerOne | `hackerone`         | `username`, `token`              |
| Bugcrowd  | `bugcrowd`          | `email`, `password`, `otpsecret` |
| Intigriti | `intigriti`         | `token`                          |

## Configuration

* **Where to configure:** In **Settings → Integration** you edit a single **YAML file** that can contain credentials and options for all supported platforms. The file is stored encrypted and is not accessible by system administrators.

## Synchronization

* **One card per platform** on the Integration page: each platform shows its title, description, last sync date, and a **Synchronize** button.
* **Flow:** Start sync → the app runs a check and shows a preview of what will be created, updated, reactivated, or disabled → you confirm to apply changes.
* **Enabled/disabled:** A program is considered **active** if it has at least one target in the sync output; if a program no longer appears, it is treated as removed and the corresponding project is disabled (not deleted).

## Availability

* **Premium and Enterprise** for full integration.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://bugrecon.gitbook.io/docs/features-list/modules/integration.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
