{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "employment-hero",
    "name": "Employment Hero Payroll",
    "vendor": "Employment Hero Pty Ltd",
    "vendorUrl": "https://employmenthero.com",
    "kind": "http-api",
    "category": "payroll",
    "summary": "Employment Hero Payroll (formerly KeyPay) is cloud payroll for Australia, New Zealand, the United Kingdom, Singapore and Malaysia. Its REST API covers businesses, employees, timesheets, leave, pay runs and reports, with an API key or OAuth 2.0.",
    "url": "https://www.anchorterminal.com/tools/employment-hero",
    "markdownUrl": "https://www.anchorterminal.com/tools/employment-hero.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/employment-hero.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/employment-hero.json",
    "repo": "https://github.com/Thinkei/keypay-dotnet-v2",
    "license": "Proprietary service under Employment Hero's General Terms. The `KeyPayV2` .NET client is MIT",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "nuget",
        "name": "KeyPayV2"
      }
    ],
    "auth": "mixed",
    "authNotes": "Graded on the Payroll API. A user with a payroll login generates an API key under My Account, with no partner review, and sends it as the HTTP Basic username with a blank password. The key acts with that user's access, and Change API Key invalidates the old one. OAuth 2.0 is the other route. A support request with the application's name, callback URL and logo returns a client ID and secret, and the authorisation code grant at `/oauth/authorise` and `/oauth/token` returns a 24-hour access token and a 28-day refresh token. The spec names `read` and `write` scopes, and the guide's sample token shows an empty scope.",
    "pricing": "paid",
    "pricingNotes": "No charge for API calls was found. Access comes with an Employment Hero Payroll subscription. The Australian pricing page lists the Payroll plan at $10 with conditions, a minimum of 10 users and billing by user count, with prices stated as AUD ex. GST in the page's disclaimers. Employment Unlimited, which includes Payroll, is priced through sales. No free tier, trial or sandbox for Payroll was found on the pages read, so an agent starts only where a paying account exists (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the API guides, the five Swagger files or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 6,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://api.keypay.com.au/",
    "openapi": "https://api.keypay.com.au/swagger-au.json",
    "capabilities": [
      "payroll.run",
      "payroll.employees",
      "payroll.embedded",
      "payroll.tax-filing",
      "payroll.contractors",
      "hr.time-off"
    ],
    "tags": [
      "hosted",
      "payroll",
      "api-key",
      "oauth",
      "openapi",
      "webhooks",
      "dotnet",
      "white-label",
      "australia",
      "new-zealand",
      "uk",
      "singapore",
      "malaysia",
      "status-page"
    ],
    "lastRelease": "2026-10-08",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 50.4,
      "grade": "D",
      "agentReady": false,
      "rank": 591,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 6,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 53,
        "maintenance": 68,
        "payments": 10,
        "reliability": 65,
        "schema": 51,
        "security": 46,
        "transparency": 60
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 65,
          "points": 13,
          "reason": "Read with the hosted lines. https://status.employmenthero.com is a Statuspage with Login, Create Pay Run, Finalise Pay Run and Create Employee components for each of five payroll regions and incident history. No component names the Payroll API (20). Between 10 July and 8 October 2026 it lists two payroll incidents. On 21 July pay runs did not load employee data for businesses with a deleted leave category still referenced in a pay run, marked major and resolved in 2 hours 3 minutes. On 2 September employees could not be removed from a pay run, marked no impact, with a fix posted 5 minutes after the notice. One major that touched a subset of businesses sits between the minor and one-major lines (15 of 30). Four further incidents in the window are on HR Software, a separate product. 5 requests a second per API key per IP address (15). The usage guide says only to space calls out. Our unauthenticated test saw a 429 with `retry-after: 1` and `x-rate-limit` headers, which the docs don't describe, and no idempotency keys were found (5 of 15). No SLA found in the General Terms or the docs (0). The API is at v2 with no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 51,
          "points": 8.29,
          "reason": "A Swagger 2.0 file for each of five regions, public and without a login, 728 operations and 460 definitions for Australia (25). No llms.txt or Markdown twin on the documentation site. employmenthero.com/llms.txt indexes marketing pages only (0). 713 of 728 Australian operations have a description, most of one sentence, such as noting OData support or that a pay run can't be finalised while calculations run. None say when not to use an operation (8 of 20). Every request body references a named model and 269 of 4,461 properties carry enums, but only 13 of 460 definitions list required fields and dates are plain date-time strings (9 of 15). The guides have curl and HTTP examples for both auth routes and OData. 711 of 728 operations document a 200 response, 131 a 400 and 136 a 404, with a `ProblemDetails` model, and no example bodies (5 of 15). The path carries v2. No API changelog was found, and the .NET client documents one set of breaking changes (4 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 53,
          "points": 8.61,
          "reason": "`$top` caps lists at 100 and `$select` trims fields on the Employee API only. Summary endpoints exist for pay runs (15 of 25). OData `$skip`, `$top`, `$orderby` and `$filter` on most GET operations (20). Some operations return `ProblemDetails`. 401 and 429 answered our test as plain text, and the docs have no error catalogue (8 of 20). No idempotency keys. Employees and several other resources can be looked up by `externalId`, which lets a caller check before repeating a create. This is an HTTP API with no MCP annotations to read (4 of 20). One official client, for .NET. Creating a pay run needs a pay schedule, a period end and a paid date (6 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 46,
          "points": 8.05,
          "reason": "An API key generated under My Account, sent as the Basic auth username, and replaced with Change API Key. It carries its user's access. OAuth 2.0 authorisation code grant with 24-hour access tokens, 28-day refresh tokens and a revoke endpoint. The spec names `read` and `write` scopes, while the guide's sample token shows an empty scope (22 of 30). Business access can be Restricted to employee groups and locations, a user can be created as `apiOnly`, and pay runs have an approval start endpoint. Nothing holds a finalise call for confirmation (10 of 20). The API returns notes and other text written by employees and managers, with no guidance on treating it as untrusted (3 of 15). Employee audit and pay run audit reports are in the spec, and responses carry `x-correlation-id`. No per-call log for the operator was found (5 of 15). security.txt is valid until 31 December 2026 and links a Vulnerability Disclosure Policy v1.2. The trust centre is script-drawn and unread, so certifications and any bounty are unconfirmed (6 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 10,
          "points": 1.25,
          "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). The Australian pricing page lists the Payroll plan at $10 with conditions and a minimum of 10 users, and says prices are AUD ex. GST in its plan disclaimers. That is public plan pricing with no per-call charge (10). No free tier or trial for Payroll was found on the pages read. The two-week free trial in the partner guide is for an HR organisation (0). A person signs up and generates the key in the browser (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 68,
          "points": 5.95,
          "reason": "The .NET client repository, generated from the API, has a build commit on 8 October 2026, and the swagger files were last modified on 28 August 2026 (30). The repository has commits on 52 separate days since 10 July, and NuGet shows 62 package versions published in the same period (20). Closed service with no API changelog. The developer forum's front page shows spam topics and API questions from 2024 and 2025 with no replies (4 of 15). One current official client. NuGet stops at 3.0.0.969 from 2 September while the repository is at build 3.0.0.1025 (10 of 15). The client repository has no CI workflow, and its test folder holds a sample application (4 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 60,
          "points": 5.25,
          "note": "editorial 49, provenance 71",
          "reason": "Closed service. General Terms effective 15 June 2026 name Employment Hero Pty Ltd and cover access through its APIs. The .NET client is MIT (15 of 30). The privacy policy (3 June 2026) and the DPA (15 June 2026) agree on processor and controller roles, say personal data is not used to train AI models, and name storage in Australia, Ireland and Canada. Retention is 'as long as necessary' under an internal policy, with no periods (20 of 30). No deprecation policy or dated notices were found for the Payroll API (2 of 20). The DPA gives data centre locations by region and 30 days to object to a new sub-processor. The sub-processor list sits on a trust centre our reader could not read (12 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`$top` caps lists at 100 and `$select` trims fields on the Employee API only. Summary endpoints exist for pay runs (15 of 25). OData `$skip`, `$top`, `$orderby` and `$filter` on most GET operations (20). Some operations return `ProblemDetails`. 401 and 429 answered our test as plain text, and the docs have no error catalogue (8 of 20). No idempotency keys. Employees and several other resources can be looked up by `externalId`, which lets a caller check before repeating a create. This is an HTTP API with no MCP annotations to read (4 of 20). One official client, for .NET. Creating a pay run needs a pay schedule, a period end and a paid date (6 of 15).",
          "maintenance": "The .NET client repository, generated from the API, has a build commit on 8 October 2026, and the swagger files were last modified on 28 August 2026 (30). The repository has commits on 52 separate days since 10 July, and NuGet shows 62 package versions published in the same period (20). Closed service with no API changelog. The developer forum's front page shows spam topics and API questions from 2024 and 2025 with no replies (4 of 15). One current official client. NuGet stops at 3.0.0.969 from 2 September while the repository is at build 3.0.0.1025 (10 of 15). The client repository has no CI workflow, and its test folder holds a sample application (4 of 10).",
          "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). The Australian pricing page lists the Payroll plan at $10 with conditions and a minimum of 10 users, and says prices are AUD ex. GST in its plan disclaimers. That is public plan pricing with no per-call charge (10). No free tier or trial for Payroll was found on the pages read. The two-week free trial in the partner guide is for an HR organisation (0). A person signs up and generates the key in the browser (0).",
          "reliability": "Read with the hosted lines. https://status.employmenthero.com is a Statuspage with Login, Create Pay Run, Finalise Pay Run and Create Employee components for each of five payroll regions and incident history. No component names the Payroll API (20). Between 10 July and 8 October 2026 it lists two payroll incidents. On 21 July pay runs did not load employee data for businesses with a deleted leave category still referenced in a pay run, marked major and resolved in 2 hours 3 minutes. On 2 September employees could not be removed from a pay run, marked no impact, with a fix posted 5 minutes after the notice. One major that touched a subset of businesses sits between the minor and one-major lines (15 of 30). Four further incidents in the window are on HR Software, a separate product. 5 requests a second per API key per IP address (15). The usage guide says only to space calls out. Our unauthenticated test saw a 429 with `retry-after: 1` and `x-rate-limit` headers, which the docs don't describe, and no idempotency keys were found (5 of 15). No SLA found in the General Terms or the docs (0). The API is at v2 with no beta label (10).",
          "schema": "A Swagger 2.0 file for each of five regions, public and without a login, 728 operations and 460 definitions for Australia (25). No llms.txt or Markdown twin on the documentation site. employmenthero.com/llms.txt indexes marketing pages only (0). 713 of 728 Australian operations have a description, most of one sentence, such as noting OData support or that a pay run can't be finalised while calculations run. None say when not to use an operation (8 of 20). Every request body references a named model and 269 of 4,461 properties carry enums, but only 13 of 460 definitions list required fields and dates are plain date-time strings (9 of 15). The guides have curl and HTTP examples for both auth routes and OData. 711 of 728 operations document a 200 response, 131 a 400 and 136 a 404, with a `ProblemDetails` model, and no example bodies (5 of 15). The path carries v2. No API changelog was found, and the .NET client documents one set of breaking changes (4 of 15).",
          "security": "An API key generated under My Account, sent as the Basic auth username, and replaced with Change API Key. It carries its user's access. OAuth 2.0 authorisation code grant with 24-hour access tokens, 28-day refresh tokens and a revoke endpoint. The spec names `read` and `write` scopes, while the guide's sample token shows an empty scope (22 of 30). Business access can be Restricted to employee groups and locations, a user can be created as `apiOnly`, and pay runs have an approval start endpoint. Nothing holds a finalise call for confirmation (10 of 20). The API returns notes and other text written by employees and managers, with no guidance on treating it as untrusted (3 of 15). Employee audit and pay run audit reports are in the spec, and responses carry `x-correlation-id`. No per-call log for the operator was found (5 of 15). security.txt is valid until 31 December 2026 and links a Vulnerability Disclosure Policy v1.2. The trust centre is script-drawn and unread, so certifications and any bounty are unconfirmed (6 of 20).",
          "transparency": "Closed service. General Terms effective 15 June 2026 name Employment Hero Pty Ltd and cover access through its APIs. The .NET client is MIT (15 of 30). The privacy policy (3 June 2026) and the DPA (15 June 2026) agree on processor and controller roles, say personal data is not used to train AI models, and name storage in Australia, Ireland and Canada. Retention is 'as long as necessary' under an internal policy, with no periods (20 of 30). No deprecation policy or dated notices were found for the Payroll API (2 of 20). The DPA gives data centre locations by region and 30 days to object to a new sub-processor. The sub-processor list sits on a trust centre our reader could not read (12 of 20)."
        },
        "sources": [
          {
            "what": "documentation index and regional spec list",
            "url": "https://api.keypay.com.au/",
            "seen": "2026-10-08"
          },
          {
            "what": "API home guide, base URL and forum link",
            "url": "https://api.keypay.com.au/guides/Home.html",
            "seen": "2026-10-08"
          },
          {
            "what": "API key authentication",
            "url": "https://api.keypay.com.au/guides/BasicAuth.html",
            "seen": "2026-10-08"
          },
          {
            "what": "OAuth 2.0 guide, token lifetimes and credential request",
            "url": "https://api.keypay.com.au/guides/OAuth2.html",
            "seen": "2026-10-08"
          },
          {
            "what": "usage limits",
            "url": "https://api.keypay.com.au/guides/Usage.html",
            "seen": "2026-10-08"
          },
          {
            "what": "OData filtering and paging",
            "url": "https://api.keypay.com.au/guides/ODataFiltering.html",
            "seen": "2026-10-08"
          },
          {
            "what": "single sign-on guide",
            "url": "https://api.keypay.com.au/guides/SSO.html",
            "seen": "2026-10-08"
          },
          {
            "what": "Swagger 2.0 file, Australia",
            "url": "https://api.keypay.com.au/swagger-au.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Swagger 2.0 file, United Kingdom",
            "url": "https://api.keypay.com.au/swagger-uk.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Swagger 2.0 file, New Zealand",
            "url": "https://api.keypay.com.au/swagger-nz.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Swagger 2.0 file, Singapore",
            "url": "https://api.keypay.com.au/swagger-sg.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Swagger 2.0 file, Malaysia",
            "url": "https://api.keypay.com.au/swagger-my.json",
            "seen": "2026-10-08"
          },
          {
            "what": "finalise pay run reference",
            "url": "https://api.keypay.com.au/australia/reference/pay-run/au-pay-run-finalise--post.html",
            "seen": "2026-10-08"
          },
          {
            "what": "create pay run reference",
            "url": "https://api.keypay.com.au/australia/reference/pay-run/au-pay-run--post.html",
            "seen": "2026-10-08"
          },
          {
            "what": "unauthenticated call to the API (401, 429 and headers)",
            "url": "https://api.yourpayroll.com.au/api/v2/user",
            "seen": "2026-10-08"
          },
          {
            "what": "status incidents",
            "url": "https://status.employmenthero.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "status components",
            "url": "https://status.employmenthero.com/api/v2/components.json",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing page, Australian edition",
            "url": "https://employmenthero.com/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "General Terms, effective 15 June 2026",
            "url": "https://employmenthero.com/legals/terms-conditions/",
            "seen": "2026-10-08"
          },
          {
            "what": "privacy policy, effective 3 June 2026",
            "url": "https://employmenthero.com/legals/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "Data Processing Addendum, effective 15 June 2026",
            "url": "https://employmenthero.com/legals/privacy-policy/data-processing/",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://employmenthero.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "trust centre (title only, script-drawn)",
            "url": "https://trust.employmenthero.com/",
            "seen": "2026-10-08"
          },
          {
            "what": ".NET client versions on NuGet",
            "url": "https://api.nuget.org/v3/registration5-semver1/keypayv2/index.json",
            "seen": "2026-10-08"
          },
          {
            "what": ".NET client repository, commits and README",
            "url": "https://github.com/Thinkei/keypay-dotnet-v2",
            "seen": "2026-10-08"
          },
          {
            "what": "developer forum front page",
            "url": "https://developers.yourpayroll.com.au/",
            "seen": "2026-10-08"
          },
          {
            "what": "HR API partner guides, trial and separate API",
            "url": "https://developer.employmenthero.com/partner-guides",
            "seen": "2026-10-08"
          },
          {
            "what": "HR API reference, separate rate limits",
            "url": "https://developer.employmenthero.com/api-references",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for employmenthero.com",
            "url": "https://rdap.org/domain/employmenthero.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the trust centre at trust.employmenthero.com and its sub-processor page are script-drawn and showed our reader a title only, so certifications, penetration testing, any bounty and the sub-processor list are unconfirmed",
          "unchecked: the body of the Vulnerability Disclosure Policy v1.2 linked from security.txt, a Google document that showed our reader its title only",
          "unchecked: the official MCP registry search answered 500, so presence of any Employment Hero server there is unconfirmed. No MCP server was found on the vendor's pages read",
          "unchecked: open issues and replies on Thinkei/keypay-dotnet-v2, which aren't in a git clone. The GitHub API reports one open issue",
          "Whether Employment Hero Payroll has a free trial or sandbox of its own. None was found on the pricing page or the API docs, and the free trial in the partner guide is for an HR organisation",
          "The unit behind the Payroll plan's $10. The page shows the figure with a 10-user minimum and billing by user count, and states AUD ex. GST in plan disclaimers, but the per-user wording sits in script-drawn tooltips we did not read in full",
          "Whether OAuth tokens can be limited to `read`. The spec names `read` and `write` scopes under an implicit flow, while the guide describes the authorisation code grant and shows an empty scope",
          "Which API host serves each region. The docs name api.yourpayroll.com.au, the client README uses a United Kingdom host, and api.yourpayroll.co.uk, api.yourpayroll.io and api.nzpayroll.co.nz each answered 401 to our test",
          "Whether a customer agreement includes an SLA. None is in the public General Terms",
          "The 429 `retry-after` header and `x-rate-limit` headers were seen on unauthenticated calls and aren't in the docs, so their behaviour for authenticated calls is unconfirmed",
          "The registrant of yourpayroll.com.au and keypay.com.au. RDAP names only the registrar",
          "The star count is for Thinkei/keypay-dotnet-v2. The API has no public repository of its own"
        ]
      },
      "negative": 0,
      "verdict": "Five public Swagger 2.0 files describe 660 to 821 operations per region, and any payroll user can generate an API key without a partner review. The key carries its user's whole access, no idempotency keys or API changelog were found, and the only official client is for .NET.",
      "bestFor": "An agent acting for an employer or bureau already on Employment Hero Payroll in Australia, New Zealand, the United Kingdom, Singapore or Malaysia, and white label partners who create businesses through the brand endpoints.",
      "strengths": [
        "Public Swagger 2.0 file for each of five regions, 728 operations for Australia and 821 for the United Kingdom, downloadable without a login",
        "A payroll user generates an API key under My Account with no partner review, and Change API Key invalidates the old one",
        "OData `$filter`, `$orderby`, `$top` and `$skip` on most GET operations, with `$top` capped at 100",
        "Pay run endpoints cover create, recalculate, warnings, approval start, finalise and unlock, so a run can be checked before it is finalised",
        "The .NET client is regenerated from the API, with commits on 52 separate days between 10 July and 8 October 2026"
      ],
      "weaknesses": [
        "An API key carries the whole access of the user who generated it. No per-key scopes were found",
        "No idempotency keys in the spec or guides, and 5 requests a second per key and IP address is the only documented limit",
        "No changelog, versioning policy or deprecation policy was found for the Payroll API",
        "Only 13 of 460 schema definitions in the Australian spec list required fields, and 711 of 728 operations document a 200 response and little else",
        "The developer forum's recent topics include spam, and several API questions from 2024 and 2025 show no replies"
      ],
      "agentNotes": [
        "Send the API key as the Basic auth username with a blank password, for example `curl -u {api_key}: https://api.yourpayroll.com.au/api/v2/user`",
        "Pick the Swagger file for the business's region (`swagger-au.json`, `swagger-nz.json`, `swagger-uk.json`, `swagger-sg.json`, `swagger-my.json`). Paths and models differ by region",
        "Stay under 5 requests a second per key and IP address. A 429 answered our test with `retry-after: 1`",
        "Page lists with `$skip` and `$top` (100 at most). Filter property names are capitalised, unlike the camelCase JSON",
        "Read `GET /api/v2/business/{businessId}/payrun/{payRunId}/warnings` before `POST .../finalise`. Finalise can lodge with the tax office and publish pay slips in the same call"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "D",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 50.4
        }
      ],
      "editorialScores": {
        "ergonomics": 53,
        "maintenance": 68,
        "payments": 10,
        "reliability": 65,
        "schema": 51,
        "security": 46,
        "transparency": 49
      },
      "provenanceScore": 71
    },
    "connect": {
      "install": "Install-Package KeyPayV2",
      "http": "curl -u {api_key}: https://api.yourpayroll.com.au/api/v2/user"
    },
    "letme": {
      "capability": "https://letme.dev/payroll.run",
      "tool": "https://letme.dev/employment-hero"
    },
    "notable": [
      "The docs site lists a Swagger 2.0 file per region, and each downloads without a login. Operations per file, 728 Australia, 660 New Zealand, 821 United Kingdom, 695 Singapore, 679 Malaysia (https://api.keypay.com.au/)",
      "All operations are prefixed by https://api.yourpayroll.com.au/api/v2, and a white label uses its own host such as https://keypay.yourpayroll.com.au (https://api.keypay.com.au/guides/Home.html)",
      "OAuth 2.0 client credentials are issued after a support request with the application's name, callback URL and logo. Access tokens last 24 hours and refresh tokens 28 days (https://api.keypay.com.au/guides/OAuth2.html)",
      "The usage guide limits the API to 5 requests per second per API key per IP address (https://api.keypay.com.au/guides/Usage.html)",
      "`POST /api/v2/business/{businessId}/payrun/{payRunId}/finalise` takes options to lodge the pay run, publish pay slips and export journals, each Manual, Immediate or Scheduled (https://api.keypay.com.au/australia/reference/pay-run/au-pay-run-finalise--post.html)",
      "Brand, reseller and white label endpoints create businesses and users, and three single sign-on endpoints return a one-use URL valid for 5 minutes for embedding the payroll screens (https://api.keypay.com.au/guides/SSO.html)",
      "Employment Hero's HR platform has a separate API with its own documentation, OAuth flow and rate limits, which this listing does not grade (https://developer.employmenthero.com/api-references)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "Surface graded",
        "value": "Employment Hero Payroll API (REST, JSON), formerly KeyPay. Base https://api.yourpayroll.com.au/api/v2. The separate HR API at developer.employmenthero.com is not graded here"
      },
      {
        "label": "Regions",
        "value": "Australia (728 operations), New Zealand (660), United Kingdom (821), Singapore (695), Malaysia (679), one Swagger 2.0 file each"
      },
      {
        "label": "Payroll coverage",
        "value": "Businesses, employees, contractors, bank accounts, super funds, pay schedules, pay runs (66 operations in the Australian spec), timesheets, rosters, leave requests, expenses, awards, reports (41), webhooks (7) and employee self-service (111)"
      },
      {
        "label": "Pay run steps",
        "value": "Create, recalculate, read warnings and totals, start the approval process, finalise, unlock. Finalise options include `lodgePayRun`, `lodgePayRunInTestMode`, `publishPaySlips` and `exportJournals`"
      },
      {
        "label": "Credentials",
        "value": "API key from My Account, sent as the Basic auth username with a blank password. OAuth 2.0 authorisation code grant at `/oauth/authorise` and `/oauth/token`, 24-hour access tokens, 28-day refresh tokens, and `POST /oauth/token/revoke`. The spec names `read` and `write` scopes"
      },
      {
        "label": "Access steps",
        "value": "API key is self-serve for any user with a payroll login. OAuth client ID and secret come from a support request"
      },
      {
        "label": "Rate limits",
        "value": "5 requests a second per API key per IP address. Our unauthenticated test saw `x-rate-limit-limit`, `x-rate-limit-remaining` and `x-rate-limit-reset` headers, and a 429 with `retry-after: 1`. The docs don't describe these headers"
      },
      {
        "label": "Pagination and filtering",
        "value": "OData v3 `$skip`, `$top` (100 by default and at most), `$orderby` and `$filter` on most GET operations. `$select` on the Employee API only. `$expand` not supported"
      },
      {
        "label": "Errors",
        "value": "Some operations document 400, 404 and 409 with a `ProblemDetails` body (`type`, `title`, `status`, `detail`, `instance`). 401 and 429 answered our test as plain text"
      },
      {
        "label": "Webhooks",
        "value": "Seven operations under `/api/v2/business/{businessId}/webhookregistrations`, with a test call"
      },
      {
        "label": "SDK",
        "value": "`KeyPayV2` on NuGet for .NET Standard 2.0, MIT, 574 versions, latest 3.0.0.969 on 2 September 2026. Source in Thinkei/keypay-dotnet-v2, generated from the API, last build commit 3.0.0.1025 on 8 October 2026"
      },
      {
        "label": "Status",
        "value": "https://status.employmenthero.com with Login, Create Pay Run, Finalise Pay Run and Create Employee components for each of five payroll regions. No component names the Payroll API"
      },
      {
        "label": "Data locations",
        "value": "Per the DPA of 15 June 2026, APAC data in Australia, United Kingdom payroll data primarily in Ireland, Canadian payroll data primarily in Canada"
      }
    ],
    "provenance": {
      "legalEntity": "Employment Hero Pty Ltd",
      "domain": "employmenthero.com",
      "domainRegistered": "2012-05-02",
      "endpointOnVendorDomain": false,
      "terms": "https://employmenthero.com/legals/terms-conditions/",
      "privacy": "https://employmenthero.com/legals/privacy-policy/",
      "statusPage": "https://status.employmenthero.com",
      "changelog": "",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The General Terms (effective 15 June 2026) name Employment Hero Pty Ltd and its affiliates, and define the EH Platform to include products reached through its APIs. They are the platform terms, and no separate API terms were found.",
        "The privacy policy is effective 3 June 2026 and points to a Data Processing Addendum effective 15 June 2026 at https://employmenthero.com/legals/privacy-policy/data-processing/.",
        "The API answers at api.yourpayroll.com.au and the documentation at api.keypay.com.au, both off employmenthero.com. RDAP for yourpayroll.com.au names the registrar only, so we could not confirm the registrant.",
        "https://employmenthero.com/.well-known/security.txt gives vuln@employmenthero.com, a policy link and an expiry of 31 December 2026.",
        "RDAP for employmenthero.com gives a registration date of 2012-05-02 and GoDaddy.com, LLC as registrar.",
        "No changelog for the Payroll API was found on the documentation site."
      ],
      "score": 71,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Employment Hero Pty Ltd",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "employmenthero.com, registered 2012-05-02 (14 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": " is not on employmenthero.com",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 1 clause that costs points",
          "points": 7.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.employmenthero.com",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://employmenthero.com/legals/terms-conditions/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 12675,
          "points": 7.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "6.1 If you are based in Australia, or any region not mentioned below – the EH Platform Terms will be governed by the laws of New South Wales, Australia, and the parties will be subject to the exclusive jurisdiction of the courts of New South Wales, Australia",
              "says": "The law of New South Wales, with disputes in the courts of New South Wales, Australia"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "Our liability for breach of any such non-excludable warranty, guarantee or other right is limited to (at our option) either replacing or paying the cost of replacing the relevant service (unless the law requires otherwise)."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "If the change to the EH Platform or the EH Platform Terms is unacceptable to you, you may stop using the EH Platform, cancel your Subscription or terminate your account in accordance with the EH Platform Terms."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "For any upgrade or downgrade in your plan or Subscription level (which must be made with at least 30 days notice), you will be invoiced for the new rate on your next billing cycle.",
              "says": "Gives 30 days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "If you don’t agree with these General Terms, then you must not use the EH Platform."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": true,
              "quote": "AI Services are not subject to any service level commitments that apply to other EH Platform services."
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "develop, support or use software, scripts, robots or any other means or processes to scrape or otherwise copy information from the EH Platform in a way that breaches another EH Platform Rule or our EH Platform Terms;",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The customer is solely responsible for the outcome of any action the vendor's AI functions suggest or carry out once the customer approves it or lets it run.",
              "quote": "You are solely responsible for the outcomes of any AI Action that you (as an Organisation or as a User) approve, confirm, initiate, or allow to execute."
            },
            {
              "date": "2026-10-08",
              "text": "Users must not share login credentials with anyone else or let more than one individual use a single user account.",
              "quote": "share your login credentials with any other person or allow multiple individuals to access the EH Platform using a single User Account;"
            },
            {
              "date": "2026-10-08",
              "text": "The liability limit does not apply to liabilities arising from the customer's indemnities or from the customer's breach of the platform rules.",
              "quote": "The exclusion of liability under clause 28 does not apply to liabilities arising out of your indemnification obligations in these General Terms or your breach of the EH Platform Rules."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://employmenthero.com/legals/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 9336,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "This Privacy Policy explains how we collect, use, and share your Personal Data, and the data protection rights that apply to you."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "We retain data for as long as necessary to provide our Services and in accordance with our internal Data Retention Policy.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Location information including specific location information you provide us via your device using GPS, wireless, or Bluetooth technology, including IP addresses and information about your internet service provider, computer and device information like device, application, or browser type and version, and location info…"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We may share certain data such as device identifiers and usage data with advertising and analytics partners in ways that may constitute ‘sharing’ under the CCPA for cross-context behavioural advertising."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You have a right to opt out of direct marketing at any time."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you are a parent or guardian and believe your child has provided us with Personal Data, or if you become aware that a minor has accessed our Services, please contact us at privacy@employmenthero.com.",
              "says": "privacy@employmenthero.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "…section 5 above) for the purposes described in section 7 above to another country by relying on the EU Standard Contractual Clauses for the transfers from the EU, or the International Data Transfer Agreement or International Data Transfer Addendum to the EU Standard Contractual Clauses for the transfers from the UK, o…",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "We may share certain data such as device identifiers and usage data with advertising and analytics partners in ways that may constitute ‘sharing’ under the CCPA for cross-context behavioural advertising."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/employment-hero.json",
    "live": {
      "slug": "employment-hero",
      "vendorStatus": {
        "page": "https://status.employmenthero.com",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T21:57:53.884983357Z"
      },
      "updatedAt": "2026-10-08T21:57:53.884983357Z"
    }
  }
}
