{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "check-payroll",
    "name": "Check",
    "vendor": "Check Technologies, Inc.",
    "vendorUrl": "https://www.checkhq.com",
    "kind": "http-api",
    "category": "payroll",
    "summary": "Check is an embedded payroll API from Check Technologies in New York. Software platforms build US payroll on it for their own customers, with tax calculation, payment and filing handled by Check. Access is by partner agreement.",
    "url": "https://www.anchorterminal.com/tools/check-payroll",
    "markdownUrl": "https://www.anchorterminal.com/tools/check-payroll.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/check-payroll.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/check-payroll.json",
    "repo": "https://github.com/check-technologies/mcp-server-check",
    "license": "Proprietary service under Check's terms of service and partner agreement. The MCP server and CLI on GitHub are MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.checkhq.com",
    "packages": [],
    "auth": "mixed",
    "authNotes": "A partner API key sent as `Authorization: Bearer`, one for sandbox and one for production, issued by Check after a request through its sales contact. The key carries the whole partner account, with no per-key scopes found. Check says unused keys expire, last activity is shown and IP restrictions can be set through the account team. Integration partners get OAuth tokens (authorisation code grant, with refresh tokens) limited to one employer and one permission level, after a Check partner authorises them. The hosted MCP server accepts the API key or a Console OAuth login that runs with the Console user's permissions. This listing grades embedded-payroll partner access. Check has no route to an existing employer's payroll account outside a partner platform.",
    "pricing": "paid",
    "pricingNotes": "No public prices. checkhq.com/pricing returns 404 and the site's buttons open a sales contact form. A sandbox exists at sandbox.checkhq.com under a Sandbox User Agreement, but the documentation says to request an API key from Check, so an agent can't start without a person contacting sales. Production needs a partner agreement. The Usage API reports billable companies, employees and contractors each month, with no unit price published (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the documentation index, the API reference pages read or the website (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 18,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.checkhq.com",
    "llmsTxt": "https://docs.checkhq.com/llms.txt",
    "capabilities": [
      "payroll.run",
      "payroll.employees",
      "payroll.embedded",
      "payroll.tax-filing",
      "payroll.contractors"
    ],
    "tags": [
      "hosted",
      "embedded-payroll",
      "us-payroll",
      "api-key",
      "oauth",
      "mcp",
      "llms-txt",
      "sandbox",
      "webhooks",
      "sales-led",
      "partner-approval",
      "status-page",
      "bug-bounty",
      "soc2"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 67.5,
      "grade": "B",
      "agentReady": false,
      "rank": 193,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 2,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 83,
        "maintenance": 72,
        "payments": 5,
        "reliability": 80,
        "schema": 78,
        "security": 74,
        "transparency": 62
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 80,
          "points": 16,
          "reason": "Read with the hosted lines and scored on the REST API under an embedded-payroll partnership. status.checkhq.com on Atlassian Statuspage lists four components (API, Console, Onboard, Payments) with incident history (20). Three incidents between 10 July and 8 October 2026. The Usage API was unavailable for about 100 minutes on 9 September, marked minor, and notices on 31 July and 4 September concerned deposits delayed at receiving banks, with no failed processing found on Check's side. Payroll endpoints were not affected in the window, so this reads as minor incidents only (20). An earlier incident on 6 June 2026, marked major, returned errors on payroll preview and approval for about four and a half hours and falls outside the 90 days. Limits with numbers, 10 to 80 requests a second by tier and 100 concurrent requests (15). 429 carries `Retry-After`, every response carries `RateLimit-Limit` and `RateLimit-Remaining`, and `X-Idempotency-Key` covers writes for 24 hours (15). No SLA is published, and the terms of service make no representation about uptime unless agreed in writing. The startups page claims 99.999 per cent historical uptime, which is a vendor claim (0). The REST API carries no beta label. The MCP server is labelled beta in its usage terms (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "Each reference page embeds an OpenAPI 3.1 fragment for its one operation, with typed parameters and request bodies. No single downloadable specification was found, and response bodies are given as examples, not schemas (15 of 25). llms.txt indexes 367 lines of guides and reference, and each page is served as Markdown (10). Guides say when to use synchronous or asynchronous preview and how sandbox differs from production. Reference descriptions are one line on most operations read (14 of 20). Request bodies list required fields and formats such as dates. No enums were seen on the operations read, and query filters are plain strings (10 of 15). Curl examples in the quickstart and guides, an error envelope with `input_errors` and `field_path`, and a table of error types. Most reference pages document only the success response (14 of 15). Dated versions through `Check-Version`, an API upgrades page listing six versions since 2021-01-15, and a product changelog (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 83,
          "points": 13.49,
          "reason": "`limit` sizes a page, and since version 2025-01-01 payrolls omit items unless `include_items` is set. No field selection. The MCP server exposes three meta-tools over 270 tools, with toolset filters and a read-only mode (20 of 25). Cursor pagination with `next` and `previous`, page sizes up to 100 or 500 on 19 endpoints, filters by company, workplace, status, ids and metadata (18 of 20). Typed error codes, `field_path` pointing at the invalid input, `X-Request-Log-Id` on every response and 409 `preview_superseded` on a stale approval (18 of 20). `X-Idempotency-Key` on writes with a stated 24-hour window and retry guidance, and the MCP server's source sets readOnlyHint, destructiveHint and idempotentHint on every tool (20). Few required fields on the operations read. No official SDK in a general programming language was found, only a Postman collection, a Python CLI and React Components (7 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 74,
          "points": 12.95,
          "reason": "A partner API key in the `Authorization` header, one per environment, carrying the whole partner account. Check says unused keys expire, last activity is shown and IP restrictions are available. Integration partners get OAuth tokens limited to one employer and permission level, and hosted MCP accepts a Console OAuth login bound to that user's role. No per-key scopes were found (22 of 30). The MCP server has read-only mode, toolset and tool filters and optional confirmation for destructive tools. The API requires a succeeded preview before approval and gates SSNs and account numbers behind the separately approved Sensitive Data API. No read-only API key was found (15 of 20). The MCP server's instructions tell the model to confirm before writes that affect payroll or money movement. No guidance on untrusted text in records was found (6 of 15). GET /logs with filters, `X-Request-Log-Id`, Console API logs for 14 days, last activity per key, and sensitive-data access logged (14 of 15). SOC 2 Type II, a bug bounty through Federacy and regular penetration tests per the security page. No security.txt (17 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 5,
          "points": 0.63,
          "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). No public price. checkhq.com/pricing returns 404 and the site asks visitors to get in touch (0). A sandbox exists under a Sandbox User Agreement, but the key is requested from Check through its sales contact, so partial credit (5 of 20). A person must contact sales and sign a partner agreement before production (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 72,
          "points": 6.3,
          "reason": "The product changelog's latest entry is 10 September 2026 and the MCP server repository's latest commit 7 October 2026 (30). Four dated changelog entries since 10 July (13 and 20 August, 9 and 10 September), and 109 commits to the MCP repository on 27 days in the same period (20). Closed service with a dated changelog, a help centre and developer support. The MCP repository is public with 10 open issues and pull requests, whose replies we couldn't read (10 of 15). No official SDK in a general programming language was found, and the official MCP registry returned no entry for Check. The CLI and MCP server are current (5 of 15). The repository runs lint and 465 tests in CI with a lock file. It has no tags and isn't published to PyPI (7 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 62,
          "points": 5.43,
          "note": "editorial 38, provenance 86",
          "reason": "Closed service. Terms of service (3 September 2021), a Sandbox User Agreement and employer terms are published. The partner agreement that governs API use is not. The MCP server and CLI are MIT (17 of 30). The privacy policy (effective 18 April 2024) says information is kept as long as needed, with no periods. The security page mentions a DPA, of which no public copy was found. The documentation states what request logs redact and that Console shows 14 days (12 of 30). Breaking changes ship as dated versions with a written definition of what counts as breaking, and a migration guide covers the legacy Tax Filings API. No notice period or removal dates were found (9 of 20). No sub-processor list or hosting locations were found on the security, privacy or terms pages (0)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`limit` sizes a page, and since version 2025-01-01 payrolls omit items unless `include_items` is set. No field selection. The MCP server exposes three meta-tools over 270 tools, with toolset filters and a read-only mode (20 of 25). Cursor pagination with `next` and `previous`, page sizes up to 100 or 500 on 19 endpoints, filters by company, workplace, status, ids and metadata (18 of 20). Typed error codes, `field_path` pointing at the invalid input, `X-Request-Log-Id` on every response and 409 `preview_superseded` on a stale approval (18 of 20). `X-Idempotency-Key` on writes with a stated 24-hour window and retry guidance, and the MCP server's source sets readOnlyHint, destructiveHint and idempotentHint on every tool (20). Few required fields on the operations read. No official SDK in a general programming language was found, only a Postman collection, a Python CLI and React Components (7 of 15).",
          "maintenance": "The product changelog's latest entry is 10 September 2026 and the MCP server repository's latest commit 7 October 2026 (30). Four dated changelog entries since 10 July (13 and 20 August, 9 and 10 September), and 109 commits to the MCP repository on 27 days in the same period (20). Closed service with a dated changelog, a help centre and developer support. The MCP repository is public with 10 open issues and pull requests, whose replies we couldn't read (10 of 15). No official SDK in a general programming language was found, and the official MCP registry returned no entry for Check. The CLI and MCP server are current (5 of 15). The repository runs lint and 465 tests in CI with a lock file. It has no tags and isn't published to PyPI (7 of 10).",
          "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). No public price. checkhq.com/pricing returns 404 and the site asks visitors to get in touch (0). A sandbox exists under a Sandbox User Agreement, but the key is requested from Check through its sales contact, so partial credit (5 of 20). A person must contact sales and sign a partner agreement before production (0).",
          "reliability": "Read with the hosted lines and scored on the REST API under an embedded-payroll partnership. status.checkhq.com on Atlassian Statuspage lists four components (API, Console, Onboard, Payments) with incident history (20). Three incidents between 10 July and 8 October 2026. The Usage API was unavailable for about 100 minutes on 9 September, marked minor, and notices on 31 July and 4 September concerned deposits delayed at receiving banks, with no failed processing found on Check's side. Payroll endpoints were not affected in the window, so this reads as minor incidents only (20). An earlier incident on 6 June 2026, marked major, returned errors on payroll preview and approval for about four and a half hours and falls outside the 90 days. Limits with numbers, 10 to 80 requests a second by tier and 100 concurrent requests (15). 429 carries `Retry-After`, every response carries `RateLimit-Limit` and `RateLimit-Remaining`, and `X-Idempotency-Key` covers writes for 24 hours (15). No SLA is published, and the terms of service make no representation about uptime unless agreed in writing. The startups page claims 99.999 per cent historical uptime, which is a vendor claim (0). The REST API carries no beta label. The MCP server is labelled beta in its usage terms (10).",
          "schema": "Each reference page embeds an OpenAPI 3.1 fragment for its one operation, with typed parameters and request bodies. No single downloadable specification was found, and response bodies are given as examples, not schemas (15 of 25). llms.txt indexes 367 lines of guides and reference, and each page is served as Markdown (10). Guides say when to use synchronous or asynchronous preview and how sandbox differs from production. Reference descriptions are one line on most operations read (14 of 20). Request bodies list required fields and formats such as dates. No enums were seen on the operations read, and query filters are plain strings (10 of 15). Curl examples in the quickstart and guides, an error envelope with `input_errors` and `field_path`, and a table of error types. Most reference pages document only the success response (14 of 15). Dated versions through `Check-Version`, an API upgrades page listing six versions since 2021-01-15, and a product changelog (15).",
          "security": "A partner API key in the `Authorization` header, one per environment, carrying the whole partner account. Check says unused keys expire, last activity is shown and IP restrictions are available. Integration partners get OAuth tokens limited to one employer and permission level, and hosted MCP accepts a Console OAuth login bound to that user's role. No per-key scopes were found (22 of 30). The MCP server has read-only mode, toolset and tool filters and optional confirmation for destructive tools. The API requires a succeeded preview before approval and gates SSNs and account numbers behind the separately approved Sensitive Data API. No read-only API key was found (15 of 20). The MCP server's instructions tell the model to confirm before writes that affect payroll or money movement. No guidance on untrusted text in records was found (6 of 15). GET /logs with filters, `X-Request-Log-Id`, Console API logs for 14 days, last activity per key, and sensitive-data access logged (14 of 15). SOC 2 Type II, a bug bounty through Federacy and regular penetration tests per the security page. No security.txt (17 of 20).",
          "transparency": "Closed service. Terms of service (3 September 2021), a Sandbox User Agreement and employer terms are published. The partner agreement that governs API use is not. The MCP server and CLI are MIT (17 of 30). The privacy policy (effective 18 April 2024) says information is kept as long as needed, with no periods. The security page mentions a DPA, of which no public copy was found. The documentation states what request logs redact and that Console shows 14 days (12 of 30). Breaking changes ship as dated versions with a written definition of what counts as breaking, and a migration guide covers the legacy Tax Filings API. No notice period or removal dates were found (9 of 20). No sub-processor list or hosting locations were found on the security, privacy or terms pages (0)."
        },
        "sources": [
          {
            "what": "documentation index for agents",
            "url": "https://docs.checkhq.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "authentication",
            "url": "https://docs.checkhq.com/reference/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "rate limits and 429 handling",
            "url": "https://docs.checkhq.com/docs/rate-limiting",
            "seen": "2026-10-08"
          },
          {
            "what": "idempotent requests",
            "url": "https://docs.checkhq.com/docs/idempotent-requests",
            "seen": "2026-10-08"
          },
          {
            "what": "pagination",
            "url": "https://docs.checkhq.com/docs/pagination",
            "seen": "2026-10-08"
          },
          {
            "what": "errors and error codes",
            "url": "https://docs.checkhq.com/reference/error-codes",
            "seen": "2026-10-08"
          },
          {
            "what": "request logs",
            "url": "https://docs.checkhq.com/docs/request-logs",
            "seen": "2026-10-08"
          },
          {
            "what": "payroll preview and approval",
            "url": "https://docs.checkhq.com/docs/payroll-preview-and-approval",
            "seen": "2026-10-08"
          },
          {
            "what": "approve a payroll reference",
            "url": "https://docs.checkhq.com/reference/approve-payroll",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox and production differences",
            "url": "https://docs.checkhq.com/docs/understanding-sandbox-and-production-environments",
            "seen": "2026-10-08"
          },
          {
            "what": "versioning and API upgrades",
            "url": "https://docs.checkhq.com/page/api-changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "hosted MCP server",
            "url": "https://docs.checkhq.com/docs/hosted-remote",
            "seen": "2026-10-08"
          },
          {
            "what": "integration partner OAuth guide",
            "url": "https://docs.checkhq.com/docs/check-oauth-integrations",
            "seen": "2026-10-08"
          },
          {
            "what": "sensitive data API",
            "url": "https://docs.checkhq.com/docs/sensitive-data-api",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server and CLI source, usage terms, CI",
            "url": "https://github.com/check-technologies/mcp-server-check",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.checkhq.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "security page",
            "url": "https://www.checkhq.com/company/security",
            "seen": "2026-10-08"
          },
          {
            "what": "product changelog",
            "url": "https://www.checkhq.com/resources/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "terms of service",
            "url": "https://www.checkhq.com/company/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "sandbox user agreement",
            "url": "https://www.checkhq.com/company/sandbox-user-agreement",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy",
            "url": "https://www.checkhq.com/company/privacy",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=checkhq",
            "seen": "2026-10-08"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.org/domain/checkhq.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: live API behaviour. We had no sandbox key, so limits, errors and the preview flow are as documented, apart from a 403 `not_authenticated` response and `X-Request-Log-Id` header seen on an unauthenticated request",
          "unchecked: whether a single OpenAPI file can be downloaded. docs.checkhq.com/openapi and /openapi.json answered 429 to our reader, and the reference pages embed one operation each",
          "unchecked: the partner agreement, the DPA and any SLA in it. None is published",
          "unchecked: per-key scopes or read-only API keys in Console, which sits behind a login",
          "unchecked: the Federacy bug bounty terms, which sit behind a sign-in at federacy.com/check",
          "unchecked: replies on the MCP repository's 10 open issues and pull requests, which aren't in the git clone",
          "Changelog entries older than the first page (81 pages) were not read, so the count of entries in the last 90 days is a minimum of four"
        ]
      },
      "negative": 0,
      "verdict": "Graded as embedded payroll through a partner API key, not access to an existing employer's payroll account. The API has idempotency keys on writes, a required preview before approval and queryable request logs. No price is public, a sandbox key comes through Check's sales team, and one API key carries the whole partner account.",
      "bestFor": "A software platform that wants to sell US payroll inside its own product and can sign a partnership, with Check handling tax calculation, money movement and filings.",
      "strengths": [
        "`X-Idempotency-Key` is accepted on writes and stored for 24 hours, and a 429 carries `Retry-After` with `RateLimit-Limit` and `RateLimit-Remaining` on every authenticated response",
        "A payroll must have a succeeded preview before approval, and `preview_started_at` makes approval fail with 409 `preview_superseded` if the preview is stale",
        "Every response carries `X-Request-Log-Id`, and GET /logs returns request logs with SSNs, bank account numbers and the `Authorization` header redacted",
        "The MCP server starts with three meta-tools over 270 tools, with read-only mode, toolset filters and optional confirmation for destructive tools",
        "llms.txt indexes the documentation, and each page is served as Markdown with an OpenAPI 3.1 fragment per operation"
      ],
      "weaknesses": [
        "No public price and no self-serve signup. The documentation says to request an API key through Check's sales contact",
        "An API key carries the whole partner account. No per-key scopes or read-only keys were found in the reviewed documentation",
        "No official SDK in a general programming language was found. The CLI and MCP server install from a git clone, not from PyPI",
        "No SLA is published. The terms of service make no representation about uptime unless agreed in writing",
        "No sub-processor list, hosting location or published DPA text was found, and the privacy policy states no retention periods"
      ],
      "agentNotes": [
        "Use https://sandbox.checkhq.com with the sandbox key and https://api.checkhq.com with the production key. A key is not valid across environments",
        "Preview a payroll before approving it, then pass `preview_started_at` to POST /payrolls/{id}/approve so a stale preview fails with 409",
        "Send `X-Idempotency-Key` on every write. Keys expire after 24 hours, so list the resource before retrying later than that",
        "On 429 wait for `Retry-After`. The limit is 10 requests a second in sandbox and for partners paying fewer than 1,000 payees a month, with 100 concurrent requests",
        "Connect the MCP server with `?read_only=true` or `X-MCP-Readonly: true` unless writes are intended. In production, approving a payroll moves money"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 67.5
        }
      ],
      "editorialScores": {
        "ergonomics": 83,
        "maintenance": 72,
        "payments": 5,
        "reliability": 80,
        "schema": 78,
        "security": 74,
        "transparency": 38
      },
      "provenanceScore": 86
    },
    "connect": {
      "http": "curl -X POST https://sandbox.checkhq.com/companies \\\n  -H 'Content-Type: application/json' \\\n  -H 'Authorization: Bearer \u003cAPI_KEY\u003e' \\\n  -d '{\"address\": {\"line1\": \"20 W 34th St\", \"postal_code\": \"10001\", \"city\": \"New York\", \"state\": \"NY\"}, \"start_date\": \"2020-05-20\", \"trade_name\": \"Good Web Design\", \"legal_name\": \"Good Web Design, Inc.\"}'",
      "claudeCode": "claude mcp add --transport http check https://mcp.sandbox.checkhq.com/check/mcp \\\n  --header \"Authorization: Bearer your-api-key-here\"",
      "config": {
        "mcpServers": {
          "check": {
            "type": "url",
            "url": "https://mcp.sandbox.checkhq.com/check/mcp"
          }
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/payroll.run",
      "tool": "https://letme.dev/check-payroll"
    },
    "notable": [
      "The API creates companies, workplaces, employees and contractors, builds payrolls from payroll items and contractor payments, previews and approves them, and exposes paystubs, payments, tax filings and W-2 statements (https://docs.checkhq.com/llms.txt)",
      "Payrolls with up to 500 payroll items and 500 contractor payments preview synchronously, and up to 2,500 of each asynchronously, as of API version 2025-01-01 (https://docs.checkhq.com/docs/payroll-preview-and-approval)",
      "The hosted MCP server at https://mcp.checkhq.com/check/mcp and https://mcp.sandbox.checkhq.com/check/mcp accepts a Console OAuth login or an API key, and exposes 270 tools in 18 toolsets through three meta-tools (https://docs.checkhq.com/docs/hosted-remote)",
      "Check's MCP Usage Terms label the MCP server beta and say it may change or be discontinued at any time (https://github.com/check-technologies/mcp-server-check/blob/main/TERMS_OF_SERVICE.md)",
      "Rate limits scale with payees paid in the prior month, from 10 to 80 requests a second, with 100 concurrent requests per partner (https://docs.checkhq.com/docs/rate-limiting)",
      "Sandbox relaxes production rules. EIN and bank account verification succeed automatically, and payroll can run while onboarding steps are still blocking (https://docs.checkhq.com/docs/understanding-sandbox-and-production-environments)",
      "The security page lists SOC 2 Type II, money transmitter licences in 50 US states and DC, and a bug bounty run through Federacy (https://www.checkhq.com/company/security)",
      "status.checkhq.com lists three incidents between 10 July and 8 October 2026. The Usage API was unavailable for about 100 minutes on 9 September, and two notices on 31 July and 4 September concerned deposits delayed at receiving banks (https://status.checkhq.com/history)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "Surface graded",
        "value": "The REST API used by a software platform under an embedded-payroll partnership, with the hosted MCP server as a second route to the same endpoints. Check has no API for reaching an existing employer's payroll account outside a partner platform"
      },
      {
        "label": "Base URLs",
        "value": "https://sandbox.checkhq.com (sandbox) and https://api.checkhq.com (production). MCP at https://mcp.sandbox.checkhq.com/check/mcp and https://mcp.checkhq.com/check/mcp"
      },
      {
        "label": "Credentials",
        "value": "Partner API key as a Bearer token, one per environment. Unused keys expire, last activity is shown, and IP restrictions are available through the account team. Integration partners receive OAuth access and refresh tokens limited to one employer and one permission level. Hosted MCP also accepts a Console OAuth login"
      },
      {
        "label": "Payroll flow",
        "value": "Create a payroll, add payroll items and contractor payments, preview (synchronous up to 500 of each, asynchronous up to 2,500), approve, and reopen a pending payroll to edit it. Approval needs a succeeded preview"
      },
      {
        "label": "Rate limits",
        "value": "10, 20, 40 or 80 requests a second by payees paid in the prior month (under 1,000, 1,000 to 10,000, 10,000 to 50,000, 50,000 and over), 100 concurrent requests, 10 a second in sandbox. 429 with `Retry-After`"
      },
      {
        "label": "Pagination",
        "value": "Cursor pagination with `next` and `previous` URLs. Default page size 25, with `limit` up to 100 or 500 on 19 listed endpoints"
      },
      {
        "label": "Idempotency",
        "value": "`X-Idempotency-Key` header. The first response is stored for 24 hours and replayed, including 500 errors"
      },
      {
        "label": "Errors",
        "value": "JSON envelope with `type`, `message` and optional `input_errors` carrying `field` and `field_path`. A published table of error types (https://docs.checkhq.com/reference/error-codes)"
      },
      {
        "label": "Versioning",
        "value": "Dated versions through the `Check-Version` header, with an account default. Six versions since 2021-01-15, the latest 2025-01-01 (https://docs.checkhq.com/page/api-changelog)"
      },
      {
        "label": "Logs",
        "value": "GET /logs and GET /logs/{id}, `X-Request-Log-Id` on every response, and an API Logs tab in Console covering 14 days"
      },
      {
        "label": "MCP server and CLI",
        "value": "check-technologies/mcp-server-check, MIT, Python 3.10 or later, version 0.1.0, installed from a git clone with uv. 270 tools in 18 toolsets behind `search_tools`, `run_tool` and `list_toolsets`. Read-only mode, toolset and tool filters, and `CHECK_CONFIRM_DESTRUCTIVE`"
      },
      {
        "label": "Sensitive data",
        "value": "SSNs and bank account numbers are returned only by the Sensitive Data API, which needs Check's approval, MFA for all users and additional terms"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II per checkhq.com/company/security. Bug bounty through Federacy. Money transmitter licences in 50 US states and DC"
      },
      {
        "label": "Status",
        "value": "status.checkhq.com on Atlassian Statuspage with four components (API, Console, Onboard, Payments)"
      }
    ],
    "provenance": {
      "legalEntity": "Check Technologies, Inc.",
      "domain": "checkhq.com",
      "domainRegistered": "2006-10-28",
      "endpointOnVendorDomain": true,
      "terms": "https://www.checkhq.com/company/terms",
      "privacy": "https://www.checkhq.com/company/privacy",
      "statusPage": "https://status.checkhq.com",
      "changelog": "https://www.checkhq.com/resources/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The privacy policy (effective 18 April 2024) names Check Technologies, Inc., 228 Park Ave. S, PMB 14961, New York, NY 10003. The site footer also names Check Payments LLC (NMLS #2103307).",
        "The terms of service are dated 3 September 2021. Sandbox use is also governed by a Sandbox User Agreement at checkhq.com/company/sandbox-user-agreement.",
        "www.checkhq.com/.well-known/security.txt and checkhq.com/.well-known/security.txt return 404. The security page sends vulnerability reports to a bug bounty at federacy.com/check.",
        "The API answers at api.checkhq.com and sandbox.checkhq.com, and the hosted MCP server at mcp.checkhq.com and mcp.sandbox.checkhq.com.",
        "RDAP for checkhq.com gives a registration date of 2006-10-28 and Squarespace Domains II LLC as registrar."
      ],
      "score": 86,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Check Technologies, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "checkhq.com, registered 2006-10-28 (19 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.checkhq.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 7.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.checkhq.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.checkhq.com/company/terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2021-09-03",
          "words": 3833,
          "points": 7.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: September 3, 2021",
              "says": "Last updated 2021-09-03"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "Any dispute between the parties that is not subject to arbitration or cannot be heard in small claims court will be resolved in the state or federal courts of New York and the United States, respectively, sitting in Borough of Manhattan.",
              "says": "Disputes go to the courts of New York"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "…arising out of or relating to these Terms or the Services, regardless of the form of the action, will not exceed the amounts you have paid to us for use of the Services in the six (6) month period immediately preceding the events giving rise to the applicable claim.",
              "says": "Capped at the fees paid in the 6 months before the claim"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "Any use of the Services other than as specifically authorized herein, without our prior written permission, is strictly prohibited, will terminate the license granted herein and violate our intellectual property rights."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you do not agree to these Terms, you may not use the Services."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "Except as otherwise agreed by us in writing, we make no representations or warranties about the uptime or availability of the Services."
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Use any data mining, robots or similar data gathering or extraction methods designed to scrape or extract data from the Services;",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Except as otherwise agreed by us in writing, we reserve the right to modify the Services or to suspend or stop providing all or portions of the Services at any time."
            },
            {
              "key": "old",
              "label": "Has not been updated for three years or more",
              "found": true,
              "quote": "Last updated: September 3, 2021"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Check takes a perpetual, irrevocable and sublicensable licence over User Content and over any name, username or likeness supplied with it.",
              "quote": "You grant us a perpetual, irrevocable, nonexclusive, royalty-free, worldwide, fully paid, and sublicensable license to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, publicly perform and display your User Content"
            },
            {
              "date": "2026-10-08",
              "text": "Developing or using an application that interacts with the Services requires Check's prior written consent.",
              "quote": "Develop or use any applications that interact with the Services without our prior written consent;"
            },
            {
              "date": "2026-10-08",
              "text": "Total liability is capped at the amounts paid to Check in the six months before the events behind the claim.",
              "quote": "will not exceed the amounts you have paid to us for use of the Services in the six (6) month period immediately preceding the events giving rise to the applicable claim."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.checkhq.com/company/privacy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2024-04-18",
          "words": 3859,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective Date: April 18, 2024",
              "says": "Last updated 2024-04-18"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy describes how Check collects, uses, and discloses information we collect from and about you in connection with your access to or use of Check’s websites and our products and services, as well as your related interactions with us (collectively referred to herein as the “Services”)."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We will delete or de-identify information when it is no longer needed to fulfill these purposes unless a longer retention period is required to comply with applicable laws."
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "…activities, we may also receive information about you from our business partners, financial service providers, identity verification services, and publicly available sources (e.g., name, address, phone number, country), as necessary to confirm your identity and prevent fraud."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "…and/or hashed email addresses) to unaffiliated third parties we collaborate with or that provide online targeted advertising that we think may be of value to you, or to assist us with analytics."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "If you do not wish to have this information used for the purpose of serving you interest-based ads, you may opt-out of certain advertising networks by using the links provided above or by following the instructions in the “Your Rights and Choices” section below."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "You can also submit a request to opt out of our disclosures of information for these activities that are not cookie and pixel based by emailing us at privacy@checkhq.com.",
              "says": "privacy@checkhq.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "These disclosures may be considered a “sale” or the processing/sharing of information for targeted advertising purposes under applicable law."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/check-payroll.json",
    "live": {
      "slug": "check-payroll",
      "probe": {
        "target": "https://api.checkhq.com",
        "method": "get",
        "lastAt": "2026-10-08T17:36:32.936658386Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 1040,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 728,
        "p95ms24h": 1040,
        "samples24h": 25,
        "samples30d": 25,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 25,
            "ok": 25
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.checkhq.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T17:38:15.489912499Z"
      },
      "githubStars": 18,
      "securityTxt": {
        "url": "https://checkhq.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:31.878118114Z"
      },
      "updatedAt": "2026-10-08T17:38:15.489912499Z"
    }
  }
}
