# Automate on reports: webhooks and the API

**Category:** [Bug Bounty](https://help.totalctrl.app/hc/totalctrl/totalctrl-help-center/en-US/categories/bug-bounty)
**Updated:** 2026-10-04

## Events you can subscribe to

Under **Webhooks**, the Bug Bounty group carries:

- `bugbounty.submission.received` — a researcher sent a report.
- `bugbounty.submission.acknowledged` — it was acknowledged.
- `bugbounty.submission.triaged` — reproduced and rated.
- `bugbounty.submission.accepted` — accepted as a real issue.
- `bugbounty.submission.resolved` — fixed.
- `bugbounty.submission.closed` — closed some other way.
- `bugbounty.submission.commented` — a comment was added.
- `bugbounty.program.published` — a program went live.

The same events are available as Orchestration triggers, so a workflow can post to a channel or open a ticket when a report arrives.

Payloads carry the reference, title, state, priority and timestamps — never the report body. A webhook payload ends up in a channel or a spreadsheet, and an exploit does not belong in either.
## REST

- `GET /api/v1/bugbounty/programs` — programs and their published scope.
- `GET /api/v1/bugbounty/submissions` — the queue, filterable by program, state, priority and whether a report is overdue.
- `GET /api/v1/bugbounty/submissions/<uid>` — one report.
- `POST /api/v1/bugbounty/submissions/<uid>/transition` — change a state. This is the only write, and it does everything a person doing it would: timestamps, history, audit and the email to the reporter.

## The AI assistant

The assistant can list your programs, list reports, and tell you what is past a promised response time. It is read-only here on purpose: closing a report is a message to somebody outside your company, and that should be a person’s decision.

---

## Related Articles

- [Put the program on your own domain](https://help.totalctrl.app/en-US/articles/bugbounty-custom-domain-1)
- [Scope groups and reward tables](https://help.totalctrl.app/en-US/articles/bugbounty-scope-and-rewards-1)
- [Send reports to Issue Tracking or Jira](https://help.totalctrl.app/en-US/articles/bugbounty-trackers-1)
- [Getting started with Bug Bounty](https://help.totalctrl.app/en-US/articles/bugbounty-getting-started-1)
- [Response times and the disclosure window](https://help.totalctrl.app/en-US/articles/bugbounty-sla-1)

---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)