Docs
Use MakeBounty with your AI agent
Everything MakeBounty does for you in the browser — search bounties, post one, claim one, see what you posted and claimed — your own AI agent can do for you too. There are three doors, all opened by one API key from Account → Agent access: a remote MCP server for Claude, ChatGPT/Codex, Cursor and any other MCP client; a REST API with an OpenAPI document; and the makebounty CLI. The agent acts as you, and can never place a dispute, a payout or an admin action, and can never spend money — posting a bounty does not charge a card.
1. Get an API key
Sign in and open Account → Agent access. Name the key after the thing that will use it (“Claude Code on my laptop”) and pick a scope: read for search, bounty detail and listing your own bounties; write to also post or claim a bounty. The key is shown once. Put it in an environment variable — every snippet below reads MAKEBOUNTY_API_KEY — rather than pasting it into a config file that gets committed.
2. Claude Code, claude.ai and Claude Desktop
Claude Code, from a terminal (the key is sent as a header on every request):
claude mcp add --transport http makebounty https://makebounty.com/mcp \
--header "Authorization: Bearer $MAKEBOUNTY_API_KEY"Or add it to a project's .mcp.json so the whole team gets it; Claude Code expands ${MAKEBOUNTY_API_KEY} from the environment:
{
"mcpServers": {
"makebounty": {
"type": "http",
"url": "https://makebounty.com/mcp",
"headers": { "Authorization": "Bearer ${MAKEBOUNTY_API_KEY}" }
}
}
}claude.ai and Claude Desktop: Customize → Connectors → Add custom connector. Name it MakeBounty, set the URL to https://makebounty.com/mcp, choose “No sign in”, and under Request headers add Authorization with the value Bearer <your key>. Claude will ask before running any tool marked destructive.
3. Cursor
~/.cursor/mcp.json (all projects) or .cursor/mcp.json (one project):
{
"mcpServers": {
"makebounty": {
"url": "https://makebounty.com/mcp",
"headers": { "Authorization": "Bearer ${env:MAKEBOUNTY_API_KEY}" }
}
}
}4. ChatGPT and Codex
Codex CLI and the ChatGPT desktop app share one MCP configuration:
[mcp_servers.makebounty]
url = "https://makebounty.com/mcp"
bearer_token_env_var = "MAKEBOUNTY_API_KEY"ChatGPT's in-app custom connectors currently require OAuth or no authentication, and cannot send a fixed header. The server also exposes search and fetch in the shape ChatGPT's connectors expect, so the day sign-in with MakeBounty is available there, nothing else changes. Until then, use Codex above.
5. The CLI
Node 18 or newer. No install needed; npx fetches the makebounty package. It talks to the same API with the same key:
# one-time: paste your key when prompted (stored in ~/.config/makebounty/config.json, mode 600)
npx makebounty login
npx makebounty whoami
npx makebounty search "CNC bracket" --limit 5
npx makebounty get <id>
npx makebounty post --title "Replacement trim clip" --amount 2500 --yes # USD cents; refuses without --yes
npx makebounty claim <id>
npx makebounty mine
# any command: --json for machine-readable output; MAKEBOUNTY_API_KEY overrides the saved key6. The tools
What any MCP client sees from tools/list. “Read-only” and “destructive” are the server's own annotations; Claude and other clients use them to decide when to ask you first.
| Tool | Scope | Kind | What it does |
|---|---|---|---|
search_bounties | read | read-only | Search MakeBounty's public bounty board by keyword (matched against title and description) and/or status. Returns up to `limit` bounties with their current funding state (pledged amount is a SetupIntent on file, not captured money, until a solution is accepted). Public data, but counted and keyed like every agent call. |
get_bounty | read | read-only | Full detail for one bounty by id: title, description, amount, status, category/safety-critical flags, and funding (pledged amount and backer count — pledged, not captured, until acceptance). |
post_bounty | write | destructive | Create a new bounty listing naming a DIY problem and a goal amount (USD cents). This does NOT charge any card — pledges and the eventual charge to a solver happen separately and are not available from this agent surface — but it commits the poster's listing publicly and cannot be withdrawn through this tool, so it is treated as money-adjacent and destructive. A bounty in the "automotive" category requires an explicit safetyCritical: true|false. Call once WITHOUT confirm to see exactly what would be posted, then call again with confirm: true after the user approves. |
claim_bounty | write | writes | Claim an open bounty as its solver (you cannot claim your own). Optionally mark it an on-camera claim with a youtube.com/youtu.be videoUrl — any other host is refused. Rate limited same as the website. Does not move money. |
list_my_bounties | read | read-only | Every bounty this account posted, and every bounty this account claimed as solver, newest first. |
whoami | read | read-only | The account this API key belongs to, and the key's own name and scopes. Call this first when unsure what the user can do. |
search | read | read-only | Search bounties and return connector-shaped results: id, title and url of the public bounty page. Same results as search_bounties. Use fetch(id) for the full record. |
fetch | read | read-only | Fetch the full record for a search() result id (a bounty id): id, title, text (full bounty detail as JSON), url, metadata. |
Try the endpoint by hand — initialize and tools/list need no key:
curl -s -X POST https://makebounty.com/mcp \
-H "Content-Type: application/json" -H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"curl","version":"0"}}}'7. REST API and OpenAPI
The MCP tools and the CLI are thin layers over /api/v1. The full description is at /openapi.json (OpenAPI 3.1), which any code generator or agent framework can read directly.
curl -s "https://makebounty.com/api/v1/bounties?q=bracket&limit=3" \
-H "Authorization: Bearer $MAKEBOUNTY_API_KEY"
curl -s -X POST https://makebounty.com/api/v1/bounties \
-H "Authorization: Bearer $MAKEBOUNTY_API_KEY" -H "Content-Type: application/json" \
-d '{"title":"Replacement trim clip","description":"Discontinued 2003 trim clip, STL or STEP","amountCents":2500,"confirm":true}'Endpoints: GET /api/v1/me, GET /api/v1/bounties?q=, POST /api/v1/bounties, GET /api/v1/bounties/{id}, POST /api/v1/bounties/{id}/claim, GET /api/v1/bounties/mine.
8. Safety, limits and logging
- An API key acts as you. An agent sees only your data, under your own account.
- Posting a bounty never charges a card by itself. Nothing here can trigger a pledge, a payout, a refund, a dispute or an admin action — those stay on the website only.
- The one destructive tool,
post_bounty, needsconfirm: true; the first call only shows what would be posted. The CLI needs--yes. - Rate limit: 300 agent calls per key per hour, the same durable per-key limiter the website's own claim/pledge/upload routes use.
- Every authenticated call is logged (tool, key, outcome, duration) and shown back to you at
GET /api/v1/me; rows are kept 30 days. - Keys are stored hashed. Revoke one in Account and it stops working immediately. Deleting your account deletes its keys.
Questions
- How do I get an API key?
- Sign in, open Account, and under Agent access create a key with a name and a scope (read, or write). The full key is shown exactly once; copy it then. Keys are stored hashed, so a lost key cannot be recovered, only revoked. You can have up to 10 active keys, and every call made with a key is logged where you can see it (GET /api/v1/me).
- What is the difference between a read key and a write key?
- A read key can search bounties, read one bounty's detail, and list the account's own posted/claimed bounties. A write key can also post a bounty and claim one. Give an agent the smallest scope its job needs.
- Can an agent post a bounty by accident, or spend money?
- post_bounty is the one money-adjacent tool, and it is built so an agent cannot post on the first call: without confirm set to true it returns exactly what would be posted and asks the agent to confirm with you first. It is also marked destructive in its MCP annotations so clients such as Claude ask you before running it. Posting itself never charges a card — pledges and the eventual charge to a solver happen only on the website, through a Stripe-backed flow this agent surface does not expose at all. Disputes, payouts, refunds and anything admin are never available here either.
- Which MCP protocol versions does the server speak?
- Both the current stateless revision (2026-07-28, with server/discover) and the earlier handshake revisions clients still use today (2025-03-26, 2025-06-18, 2025-11-25). Transport is Streamable HTTP with plain JSON responses; the endpoint is POST https://makebounty.com/mcp. There are no sessions to manage.
- Does an agent ever see another customer's data?
- No. A key acts as the account it was created under — it sees exactly what that account's own session would see on the website, nothing more.
Reviewed 2026-10-02. Protocol facts checked against modelcontextprotocol.io on that date.