Skip to main content
Welcome to Cantina - the platform built to help organizations connect with the best security researchers. Whether you’re preparing for a launch, running a bug bounty, or in need of urgent incident response, this section will walk you through how to get started on the platform.

Account Creation

To begin using Cantina, you’ll need to create an Organization Account, which unlocks access to the platform’s solutions and tools.

Steps to create an account

  1. Navigate to the onboarding page at https://cantina.xyz/onboarding
  2. Choose your account type from the welcome screen:
    • Select “Organization” if you have security needs
    • Select “Researcher” if you offer security solutions
  3. Add your personal details: enter your full name (e.g., Jordan Patel), create a username (e.g., jordanpatel), and click “Continue” to proceed.
  4. Add your company details: enter your Company Name, create a Company Username (this will be your organization’s identifier), and click “Complete sign up”.
  5. Accept Terms of Use: review Cantina’s Terms of Use and click “Accept” to agree to the terms and complete registration.
  6. Access your dashboard: you’ll be redirected to your organization dashboard. The main navigation includes: Dashboard, Repositories, Opportunities, Leaderboard, and Discover Cantina.
After creating your account: complete your profile with additional company information, invite team members via the “Invite team members” option in your dashboard, and explore the platform’s resources and security solutions.

Platform Navigation

Cantina is designed to streamline the experience of managing security engagements. Once you’re logged in as part of an organization, here’s what you’ll find:
  • Dashboard: Your organization’s home base with welcome message, team management, and quick actions
  • Repositories: GitHub integration and code repository management for your projects
  • Opportunities: Browse available security engagements, competitions, and bounty programs with detailed filtering
  • Leaderboard: View researcher rankings and performance metrics across the platform
  • Discover Cantina: Explore platform features, resources, and educational content

User Menu (accessed via profile dropdown)

  • Settings: Account preferences and configuration
  • Support: Help resources and contact information
  • Sign out: Logout from your account

Dashboard Overview

The main dashboard provides important information at a glance:
  • Organization Profile: Display of your company name, username, and avatar
  • Team Management: Quick access to invite team members to your organization
  • Researcher Showcase: Visual display of top researchers available on the platform
  • Quick Actions: Direct buttons for starting security engagements

Opportunities Section

When you navigate to cantina.xyz/opportunities, you’ll find:
  • Platform Statistics: Live metrics including payouts available, total paid out, vulnerabilities found, and active researchers
  • Engagement Filters: Browse by All, Competitions, Bounties, or Ended engagements
  • Search Functionality: Find specific opportunities using the search bar
  • Live Programs: Active bug bounties and competitions with payout amounts and start dates

Notifications System

Access notifications through the inbox icon or directly via cantina.xyz/notifications:
  • Inbox: Centralized message center for all platform communications
  • Filter Options: Organize notifications by type (Pings & Assignments, New findings, Comments, Status changes, Payments, Badges, Spam)
  • Settings: Configure notification preferences and delivery methods

Settings

Navigate to Settings to manage your organization’s configuration at cantina.xyz/organization/settings/company:
  • Personal profile: Your individual account settings and preferences
  • Company profile: Organization information visible to others on Cantina, including company name and username, logo/avatar upload (WebP, PNG, or JPEG up to 2 MB), website and company email, social media links (X/Twitter, GitHub), about section with rich text editing, and a link to view your public profile page
  • Manage users: Team member access and permissions
  • Account security: Security settings and authentication options

Managing Team Members

To manage your organization’s team members:
  1. Go to Settings from your profile menu
  2. Select “Manage users” from the left sidebar, or navigate directly to cantina.xyz/organization/settings/members
  3. View all users who currently have access to the company
Adding team members: In the Manage users section, click the ”+” button, enter the email address of the person you want to invite, and send the invitation (users will initially have “Pending” status). Managing existing users: The Manage users page shows the user list (names, current roles, email addresses), role management via the “Role” dropdown (Manager: full access to organization settings and user management; Member: standard access to engagements and repositories), status tracking for pending invitations, and a “Disable user” button to remove access when needed. Setting user roles: After a user accepts their invitation, locate them in your Manage users list, click their “Role” dropdown, and select either “Manager” or “Member”. The role change takes effect immediately.

Session Settings

Session settings apply to all company users and control how long user sessions remain active and how often they need to be refreshed. Where to configure: Organization Settings → Session Settings Available settings:
  • Refresh Time - How often user sessions need to be refreshed.
  • Max Session Duration - The maximum length of time a user session can remain active before the user must sign in again.
To update: Select a Refresh Time from the dropdown, select a Max Session Duration from the dropdown, then select Update Session Settings to apply the changes. Recommendations:
  • Set the refresh time to 8–12 hours for a good user experience.
  • Set the max session duration to 1–7 days for security.
  • The refresh time should always be less than the max session duration.
Managing your own sessions: Each user can view and manage their own active login sessions under User Profile → Settings → Account security. The Login sessions list shows every active session and device, including last activity, expiration date, and status. From here you can terminate a session (immediately sign out that device) or extend a session’s expiration date.

Going Further