{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "gusto",
    "name": "Gusto",
    "vendor": "Gusto, Inc.",
    "vendorUrl": "https://gusto.com",
    "kind": "http-api",
    "category": "payroll",
    "summary": "Gusto Embedded Payroll is a REST API for running US payroll inside another product, covering company and worker onboarding, payroll calculation and submission, tax filing and contractor payments. Production access needs a partnership with Gusto. A demo environment is self-serve.",
    "url": "https://www.anchorterminal.com/tools/gusto",
    "markdownUrl": "https://www.anchorterminal.com/tools/gusto.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/gusto.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/gusto.json",
    "repo": "https://github.com/Gusto/gusto-typescript-client",
    "license": "Proprietary service under Gusto's API Policy and Developer Terms of Service. The API clients on GitHub are MIT, and the React SDK and the Gusto CLI are Apache-2.0",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "npm",
        "name": "@gusto/embedded-api"
      },
      {
        "registry": "npm",
        "name": "@gusto/embedded-react-sdk"
      },
      {
        "registry": "pypi",
        "name": "gusto-embedded"
      }
    ],
    "auth": "oauth",
    "authNotes": "Graded on the Embedded Payroll API, which needs a partnership. A developer signs up at dev.gusto.com, creates an organisation and an application, and gets a client ID and secret for the demo environment. POST /oauth/token with `grant_type` system_access returns a two-hour system token for partner-level calls, and creating a partner-managed company returns an access and refresh token pair for that company alone. Scopes are assigned by Gusto, and production keys follow commercial, security and implementation reviews. Access to an existing employer's Gusto account is separate. Partner apps use the App Integrations API with the OAuth 2.0 authorisation code grant after Production Pre-Approval and a security review. A customer's own company is reached through the Gusto CLI or the Gusto MCP server, which sign in by OAuth with dynamic client registration and PKCE.",
    "pricing": "paid",
    "pricingNotes": "No price could be read. gusto.com and embedded.gusto.com answered our reader with a bot check, and the developer docs carry no figures. The introduction says commercial conversations are required before production, and an invoices endpoint returns the active companies used to calculate a partner's invoice. The demo environment is open to any developer with a Developer Portal account, with generated demo companies and no contract (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the API reference or the llms.txt index (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 2,
      "npmWeekly": 24731,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.gusto.com/embedded-payroll/docs/introduction",
    "llmsTxt": "https://docs.gusto.com/llms.txt",
    "capabilities": [
      "payroll.run",
      "payroll.employees",
      "payroll.embedded",
      "payroll.tax-filing",
      "payroll.contractors",
      "hr.onboarding",
      "hr.time-off"
    ],
    "tags": [
      "hosted",
      "payroll",
      "oauth",
      "partner-approval",
      "sandbox",
      "llms-txt",
      "webhooks",
      "typescript",
      "python",
      "java",
      "csharp",
      "ruby",
      "mcp",
      "cli",
      "status-page"
    ],
    "lastRelease": "2026-10-01",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 63.3,
      "grade": "B",
      "agentReady": false,
      "rank": 283,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 3,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 82,
        "maintenance": 76,
        "payments": 15,
        "reliability": 58,
        "schema": 86,
        "security": 60,
        "transparency": 61
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 58,
          "points": 11.6,
          "reason": "Read with the hosted lines and scored on the Embedded Payroll API. https://gustoapi.statuspage.io is a status page for the Embedded API with seven components and incident history (20). It lists 11 incidents between 14 July and 5 October 2026, five marked major. One on 28 September is titled a complete outage for APIs, with a fix about 29 minutes after it opened. All calls to the payroll update endpoint returned 500 on 14 July (about 80 minutes to recovery), a single-payroll GET returned 500 on 27 July (about 97 minutes to the fix), payroll retrieval and preparation failed on 29 July (about 88 minutes), and webhooks and payroll endpoints had a partial outage on 5 October (an hour to the fix). That is several majors on the core payroll endpoints (0). 200 requests a minute per application and user, rolling window (15). 429 with `Retry-After` and three `X-RateLimit` headers, a `version` check on every PUT, and an idempotency key found on People Batch only (13 of 15). The API Policy says Gusto makes no representations about uptime, and no SLA was found (0). v2026-06-15 is marked stable (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 86,
          "points": 13.98,
          "reason": "Each of 317 reference pages serves an OpenAPI 3.1 definition for its operation as Markdown. The whole specification sits in a repository that asked for credentials, so there is no single public file (20 of 25). llms.txt for the site and per project, and every guide has a Markdown twin (10). Operation descriptions state what happens, the scope needed and when to poll, and guides walk through payroll step by step. Few say when not to use an endpoint (15 of 20). Enums on status, type and include parameters, formats and patterns on fields such as `ssn`, and required fields listed. Dates are plain strings (13 of 15). Curl examples in guides, example error bodies per category and per endpoint. One guide's JavaScript sample uses older parameters than its curl sample (13 of 15). Dated versions, a version upgrade guide with breaking changes by version, and a changelog (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 82,
          "points": 13.33,
          "reason": "`include` chooses which parts of a payroll come back, and `page` and `per` size lists. No field selection (18 of 25). Page and cursor pagination with total headers, date and status filters, and `sort_by` with a per-endpoint allowlist (20). Errors carry `error_key`, `category` and `metadata`, with 18 documented categories and a list of payroll blockers. Messages are display text and may change (18 of 20). A `version` on every PUT with 409 on conflict, delta updates, and 202 with polling on calculate and submit. Idempotency keys were found on one endpoint, and this is an HTTP API with no MCP annotations to read (14 of 20). Five official API clients (TypeScript, Python, Java, C#, Ruby), all labelled beta, and payroll setup needs many calls before a first run (12 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 60,
          "points": 10.5,
          "reason": "OAuth-style tokens with resource:action scopes. A system token comes from the client ID and secret, each company has its own access and refresh pair, access tokens last two hours and refresh tokens rotate on use. Secrets travel in the body or the `Authorization` header. Scopes are assigned by Gusto per application, not chosen per token (27 of 30). Read and write scopes are separate and `payrolls:run` is its own scope. Calculate gives a preview and the docs recommend a review screen, but nothing in the API holds a submission for approval. A payroll can be cancelled until 3:30pm PST on its deadline (13 of 20). The API docs say free-text values are content and must not drive logic. Guidance on treating returned text as untrusted appears only in the Gusto CLI's README, a different surface (6 of 15). GET /v1/events returns 30 days of events, the Developer Portal shows webhook activity, and responses carry `x-request-id`. No per-call log was found (8 of 15). The CLI's SECURITY.md gives security@gusto.com with a two-business-day acknowledgement, and partners pass a security review. Gusto's own security page and security.txt couldn't be read, so certifications and any bounty are unconfirmed (6 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 15,
          "points": 1.88,
          "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). No price could be read. The pricing pages answered with a bot check and the docs have no figures, only a statement that commercial conversations come before production (0). The demo environment is open to any developer account with generated demo companies and no contract, and no card is mentioned. It is a sandbox, not a production tier (15 of 20). A person signs up in the Developer Portal and production keys follow reviews (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 76,
          "points": 6.65,
          "reason": "The changelog's latest entry is dated 1 October 2026, the TypeScript client 0.16.2 shipped the same day and the React SDK 0.56.5 on 7 October (30). Changelog entries on 3 August, 1 September and 1 October plus four feature entries between them, and three TypeScript client versions since 31 August (20). Closed service with a changelog, developer@gusto.com, named Technical Solutions contacts for partners and GitHub issues on the client repositories, which we couldn't read (10 of 15). The TypeScript client is current. `gusto-embedded` on PyPI stopped at 0.2.4 on 16 April 2025 though its repository has newer versioned packages, and every client is beta (10 of 15). Clients are generated by Speakeasy with generation and publish workflows. No test results are visible (6 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 61,
          "points": 5.34,
          "note": "editorial 44, provenance 77",
          "reason": "Closed service. The API Policy is published in the docs and dated 11 July 2022. The Developer Terms of Service couldn't be read. API clients are MIT, the React SDK and CLI Apache-2.0 (15 of 30). The API Policy says Gusto may monitor use and keep aggregate data, and the events endpoint keeps 30 days. The privacy policy and any DPA couldn't be read, and the docs state no retention periods for payroll data (6 of 30). Each version gets six months of full and six of limited support after deprecation, with dates in a table and `Deprecation` and `Sunset` headers (20). No sub-processor list or data locations in the docs. The product status page names AWS and Cloudflare as providers (3 of 20)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "`include` chooses which parts of a payroll come back, and `page` and `per` size lists. No field selection (18 of 25). Page and cursor pagination with total headers, date and status filters, and `sort_by` with a per-endpoint allowlist (20). Errors carry `error_key`, `category` and `metadata`, with 18 documented categories and a list of payroll blockers. Messages are display text and may change (18 of 20). A `version` on every PUT with 409 on conflict, delta updates, and 202 with polling on calculate and submit. Idempotency keys were found on one endpoint, and this is an HTTP API with no MCP annotations to read (14 of 20). Five official API clients (TypeScript, Python, Java, C#, Ruby), all labelled beta, and payroll setup needs many calls before a first run (12 of 15).",
          "maintenance": "The changelog's latest entry is dated 1 October 2026, the TypeScript client 0.16.2 shipped the same day and the React SDK 0.56.5 on 7 October (30). Changelog entries on 3 August, 1 September and 1 October plus four feature entries between them, and three TypeScript client versions since 31 August (20). Closed service with a changelog, developer@gusto.com, named Technical Solutions contacts for partners and GitHub issues on the client repositories, which we couldn't read (10 of 15). The TypeScript client is current. `gusto-embedded` on PyPI stopped at 0.2.4 on 16 April 2025 though its repository has newer versioned packages, and every client is beta (10 of 15). Clients are generated by Speakeasy with generation and publish workflows. No test results are visible (6 of 10).",
          "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). No price could be read. The pricing pages answered with a bot check and the docs have no figures, only a statement that commercial conversations come before production (0). The demo environment is open to any developer account with generated demo companies and no contract, and no card is mentioned. It is a sandbox, not a production tier (15 of 20). A person signs up in the Developer Portal and production keys follow reviews (0).",
          "reliability": "Read with the hosted lines and scored on the Embedded Payroll API. https://gustoapi.statuspage.io is a status page for the Embedded API with seven components and incident history (20). It lists 11 incidents between 14 July and 5 October 2026, five marked major. One on 28 September is titled a complete outage for APIs, with a fix about 29 minutes after it opened. All calls to the payroll update endpoint returned 500 on 14 July (about 80 minutes to recovery), a single-payroll GET returned 500 on 27 July (about 97 minutes to the fix), payroll retrieval and preparation failed on 29 July (about 88 minutes), and webhooks and payroll endpoints had a partial outage on 5 October (an hour to the fix). That is several majors on the core payroll endpoints (0). 200 requests a minute per application and user, rolling window (15). 429 with `Retry-After` and three `X-RateLimit` headers, a `version` check on every PUT, and an idempotency key found on People Batch only (13 of 15). The API Policy says Gusto makes no representations about uptime, and no SLA was found (0). v2026-06-15 is marked stable (10).",
          "schema": "Each of 317 reference pages serves an OpenAPI 3.1 definition for its operation as Markdown. The whole specification sits in a repository that asked for credentials, so there is no single public file (20 of 25). llms.txt for the site and per project, and every guide has a Markdown twin (10). Operation descriptions state what happens, the scope needed and when to poll, and guides walk through payroll step by step. Few say when not to use an endpoint (15 of 20). Enums on status, type and include parameters, formats and patterns on fields such as `ssn`, and required fields listed. Dates are plain strings (13 of 15). Curl examples in guides, example error bodies per category and per endpoint. One guide's JavaScript sample uses older parameters than its curl sample (13 of 15). Dated versions, a version upgrade guide with breaking changes by version, and a changelog (15).",
          "security": "OAuth-style tokens with resource:action scopes. A system token comes from the client ID and secret, each company has its own access and refresh pair, access tokens last two hours and refresh tokens rotate on use. Secrets travel in the body or the `Authorization` header. Scopes are assigned by Gusto per application, not chosen per token (27 of 30). Read and write scopes are separate and `payrolls:run` is its own scope. Calculate gives a preview and the docs recommend a review screen, but nothing in the API holds a submission for approval. A payroll can be cancelled until 3:30pm PST on its deadline (13 of 20). The API docs say free-text values are content and must not drive logic. Guidance on treating returned text as untrusted appears only in the Gusto CLI's README, a different surface (6 of 15). GET /v1/events returns 30 days of events, the Developer Portal shows webhook activity, and responses carry `x-request-id`. No per-call log was found (8 of 15). The CLI's SECURITY.md gives security@gusto.com with a two-business-day acknowledgement, and partners pass a security review. Gusto's own security page and security.txt couldn't be read, so certifications and any bounty are unconfirmed (6 of 20).",
          "transparency": "Closed service. The API Policy is published in the docs and dated 11 July 2022. The Developer Terms of Service couldn't be read. API clients are MIT, the React SDK and CLI Apache-2.0 (15 of 30). The API Policy says Gusto may monitor use and keep aggregate data, and the events endpoint keeps 30 days. The privacy policy and any DPA couldn't be read, and the docs state no retention periods for payroll data (6 of 30). Each version gets six months of full and six of limited support after deprecation, with dates in a table and `Deprecation` and `Sunset` headers (20). No sub-processor list or data locations in the docs. The product status page names AWS and Cloudflare as providers (3 of 20)."
        },
        "sources": [
          {
            "what": "documentation index for both projects",
            "url": "https://docs.gusto.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "introduction and production review requirement",
            "url": "https://docs.gusto.com/embedded-payroll/docs/introduction",
            "seen": "2026-10-08"
          },
          {
            "what": "quickstart, organisation, application and first calls",
            "url": "https://docs.gusto.com/embedded-payroll/docs/quickstart",
            "seen": "2026-10-08"
          },
          {
            "what": "system and company access tokens",
            "url": "https://docs.gusto.com/embedded-payroll/docs/authentication-and-authorization",
            "seen": "2026-10-08"
          },
          {
            "what": "pagination, sorting, idempotency, versions, rate limits and scopes",
            "url": "https://docs.gusto.com/embedded-payroll/docs/api-fundamentals",
            "seen": "2026-10-08"
          },
          {
            "what": "API versioning and deprecation timeline",
            "url": "https://docs.gusto.com/embedded-payroll/docs/api-versioning",
            "seen": "2026-10-08"
          },
          {
            "what": "version statuses and breaking changes by version",
            "url": "https://docs.gusto.com/embedded-payroll/docs/version-upgrade-guide",
            "seen": "2026-10-08"
          },
          {
            "what": "breaking change policy",
            "url": "https://docs.gusto.com/embedded-payroll/docs/what-is-a-breaking-change",
            "seen": "2026-10-08"
          },
          {
            "what": "error shapes and categories",
            "url": "https://docs.gusto.com/embedded-payroll/docs/error-categories",
            "seen": "2026-10-08"
          },
          {
            "what": "regular payroll steps",
            "url": "https://docs.gusto.com/embedded-payroll/docs/complete-a-regular-payroll",
            "seen": "2026-10-08"
          },
          {
            "what": "submit payroll reference with OpenAPI 3.1 definition",
            "url": "https://docs.gusto.com/embedded-payroll/reference/put-v1-companies-company_id-payrolls-payroll_id-submit",
            "seen": "2026-10-08"
          },
          {
            "what": "list payrolls reference, parameters and enums",
            "url": "https://docs.gusto.com/embedded-payroll/reference/get-v1-companies-company_id-payrolls",
            "seen": "2026-10-08"
          },
          {
            "what": "invoices endpoint",
            "url": "https://docs.gusto.com/embedded-payroll/reference/get-invoices-invoice-period",
            "seen": "2026-10-08"
          },
          {
            "what": "events endpoint, 30 days",
            "url": "https://docs.gusto.com/embedded-payroll/reference/get-events",
            "seen": "2026-10-08"
          },
          {
            "what": "webhooks, verification and retries",
            "url": "https://docs.gusto.com/embedded-payroll/docs/webhooks",
            "seen": "2026-10-08"
          },
          {
            "what": "API clients and their beta status",
            "url": "https://docs.gusto.com/embedded-payroll/docs/api-clients",
            "seen": "2026-10-08"
          },
          {
            "what": "Dev Assistant MCP",
            "url": "https://docs.gusto.com/embedded-payroll/docs/dev-assistant-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "API Policy",
            "url": "https://docs.gusto.com/embedded-payroll/page/api-policy",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://docs.gusto.com/embedded-payroll/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "App Integrations introduction and Production Pre-Approval",
            "url": "https://docs.gusto.com/app-integrations/docs/introduction",
            "seen": "2026-10-08"
          },
          {
            "what": "App Integrations compared with Gusto Embedded",
            "url": "https://docs.gusto.com/app-integrations/docs/app-integrations-vs-embedded-payroll",
            "seen": "2026-10-08"
          },
          {
            "what": "App Integrations security review",
            "url": "https://docs.gusto.com/app-integrations/docs/security-review",
            "seen": "2026-10-08"
          },
          {
            "what": "Embedded API status incidents",
            "url": "https://gustoapi.statuspage.io/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Gusto product status incidents",
            "url": "https://status.gusto.com/api/v2/incidents.json",
            "seen": "2026-10-08"
          },
          {
            "what": "TypeScript API client repository, tags and Speakeasy workflow",
            "url": "https://github.com/Gusto/gusto-typescript-client",
            "seen": "2026-10-08"
          },
          {
            "what": "React SDK repository and tags",
            "url": "https://github.com/Gusto/embedded-react-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "Gusto CLI repository, README, AGENTS.md and SECURITY.md",
            "url": "https://github.com/Gusto/gusto-cli",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP server OAuth metadata",
            "url": "https://mcp.api.gusto.com/.well-known/oauth-authorization-server",
            "seen": "2026-10-08"
          },
          {
            "what": "TypeScript client on npm",
            "url": "https://registry.npmjs.org/@gusto/embedded-api",
            "seen": "2026-10-08"
          },
          {
            "what": "Python client on PyPI",
            "url": "https://pypi.org/pypi/gusto-embedded/json",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search, no entries",
            "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=gusto",
            "seen": "2026-10-08"
          },
          {
            "what": "unauthenticated call to the demo API (401 and headers)",
            "url": "https://api.gusto-demo.com/v1/me",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: gusto.com and embedded.gusto.com answered our reader with a bot check, so pricing, the Developer Terms of Service, the privacy policy, any DPA or sub-processor list, the security page and /.well-known/security.txt weren't read",
          "unchecked: the product pages for the Gusto MCP server and Gusto CLI on gusto.com, so which plans include them and any cost are unconfirmed",
          "unchecked: the MCP server's tool list and annotations. tools/list at https://mcp.api.gusto.com returned 401 without a token",
          "unchecked: weekly downloads of gusto-embedded on PyPI. pypistats.org answered 429 three times",
          "unchecked: open issues and replies on the client repositories, which aren't in a git clone",
          "Whether a partner contract includes an SLA. The public API Policy makes no uptime commitment",
          "Whether idempotency keys are accepted on POST endpoints beyond People Batch. The fundamentals page describes them for creates without naming a header",
          "The full OpenAPI file is fetched from Gusto/Gusto-Partner-API with a token in the client workflow, and that repository asked us for credentials",
          "Incident durations are taken from update timestamps on the status page, which gives the time to a fix and not a measured outage length",
          "The star count is for Gusto/gusto-typescript-client. Gusto's main API has no single public repository"
        ]
      },
      "negative": 0,
      "verdict": "This listing covers the Embedded Payroll API. Every reference page carries an OpenAPI 3.1 definition, payroll is calculated as a preview before submission, and each API version gets 12 months of deprecation support. Production needs commercial and security approval, no price was readable, and the status page lists 11 incidents between 14 July and 5 October 2026, five marked major.",
      "bestFor": "A software platform that wants to run US payroll for its own customers and can pass Gusto's partner reviews.",
      "strengths": [
        "Each of 317 reference pages serves an OpenAPI 3.1 definition as Markdown, and llms.txt indexes both documentation projects",
        "Payroll runs in steps (prepare, calculate, submit). Calculate returns a preview with `submission_blockers` before any money moves",
        "Each API version gets 12 months of phased support after deprecation, with dates published and `Deprecation`, `Sunset` and `Link` response headers",
        "Company access tokens work for one company only, expire after two hours and rotate the refresh token on use",
        "Rate limit of 200 requests a minute per application and user, with `Retry-After` and `X-RateLimit-*` headers on responses"
      ],
      "weaknesses": [
        "Production keys need commercial, security and implementation reviews with Gusto's partnerships team, and the docs say not all use cases are supported",
        "The Embedded API status page lists 11 incidents between 14 July and 5 October 2026, five marked major, one titled a complete outage",
        "No price was readable. gusto.com and embedded.gusto.com answered our reader with a bot check, and the docs carry no figures",
        "Idempotency keys were found only on the People Batch endpoint. Other POST calls rely on the caller not repeating them",
        "The five API clients are labelled beta, and the README warns of breaking changes without notice"
      ],
      "agentNotes": [
        "Develop against https://api.gusto-demo.com. Production at https://api.gusto.com needs keys Gusto issues after its reviews",
        "Send `X-Gusto-API-Version: 2026-06-15` on every call. Without it the application's minimum version applies",
        "Send the resource's current `version` with every PUT, and only the fields to change. A stale version returns 409",
        "Calculate and submit return 202. Poll GET on the payroll until `calculated_at` is set or the status is processed, and read `submission_blockers` first",
        "For a company already on Gusto, the Embedded API is the wrong route. Use the Gusto CLI or the MCP server at https://mcp.api.gusto.com, which draft payroll but can't submit it"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 63.3
        }
      ],
      "editorialScores": {
        "ergonomics": 82,
        "maintenance": 76,
        "payments": 15,
        "reliability": 58,
        "schema": 86,
        "security": 60,
        "transparency": 44
      },
      "provenanceScore": 77
    },
    "connect": {
      "install": "npm add @gusto/embedded-api",
      "http": "curl --location --request POST 'https://api.gusto-demo.com/oauth/token' \\\n--header 'Content-Type: application/json' \\\n--data-raw '{\n  \"client_id\": \"{{client_id}}\",\n  \"client_secret\": \"{{client_secret}}\",\n  \"grant_type\": \"system_access\"\n}'"
    },
    "letme": {
      "capability": "https://letme.dev/payroll.run",
      "tool": "https://letme.dev/gusto"
    },
    "notable": [
      "The docs state that commercial, security and implementation reviews are required before partners move to production, and ask developers to contact the partnerships team before building (https://docs.gusto.com/embedded-payroll/docs/introduction)",
      "Payroll is prepared, calculated and submitted in separate calls. Calculate and submit are asynchronous and answer 202, and a submitted payroll can be cancelled until 3:30pm PST on the payroll deadline (https://docs.gusto.com/embedded-payroll/docs/complete-a-regular-payroll)",
      "API versions are dated and sent in `X-Gusto-API-Version`. v2026-06-15 is stable, v2026-02-01 reaches limited support on 15 November 2026 and v2025-06-15 is removed on 17 November 2026 (https://docs.gusto.com/embedded-payroll/docs/version-upgrade-guide)",
      "The App Integrations API reaches an existing Gusto customer's account by OAuth 2.0, can update a payroll but not run it, and issues production keys only after Production Pre-Approval and a security review (https://docs.gusto.com/app-integrations/docs/app-integrations-vs-embedded-payroll)",
      "Gusto customers connecting their own company are sent to the Gusto CLI and the Gusto MCP server. The CLI is Apache-2.0, at v0.4.0 since 29 September 2026, blocks agent-driven writes until `--confirm`, and has no command to run payroll (https://github.com/Gusto/gusto-cli)",
      "The MCP server at https://mcp.api.gusto.com publishes OAuth metadata with dynamic client registration, PKCE and 36 scopes. Its tool list needs a token (https://mcp.api.gusto.com/.well-known/oauth-authorization-server)",
      "The Dev Assistant MCP at https://embedded-payroll.readme.io/mcp searches the documentation and API reference for coding tools. It is in beta and doesn't act on payroll data (https://docs.gusto.com/embedded-payroll/docs/dev-assistant-mcp)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "Surface graded",
        "value": "Embedded Payroll API (REST, JSON), demo at https://api.gusto-demo.com and production at https://api.gusto.com, all paths under /v1. 317 reference pages in the embedded project"
      },
      {
        "label": "Payroll coverage",
        "value": "Regular and off-cycle payrolls, prepare, calculate, submit and cancel, payroll receipts, pay schedules, contractor payments, tax payments, time off policies, benefits, garnishments, forms and reports"
      },
      {
        "label": "Other Gusto surfaces",
        "value": "App Integrations API for partner apps on an existing Gusto account (update a payroll, no run). Gusto CLI and Gusto MCP server for a customer's own company (draft payroll, no submit). Dev Assistant MCP for documentation search, in beta"
      },
      {
        "label": "Credentials",
        "value": "System access token from client ID and secret (`grant_type` system_access) for partner-level calls. One access and refresh token pair per company. Access tokens last two hours. Scopes named resource:action, such as `payrolls:run`, assigned by Gusto before production"
      },
      {
        "label": "Access steps",
        "value": "Developer Portal account, organisation and application are self-serve for the demo. Production keys follow commercial, security and implementation reviews with the partnerships team"
      },
      {
        "label": "Rate limits",
        "value": "200 requests a minute per application and user, rolling 60-second window, 429 with `Retry-After`, `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset`"
      },
      {
        "label": "Pagination and sorting",
        "value": "`page` and `per` (25 by default, 100 at most on payrolls) with `X-Total-Count` and `X-Total-Pages` headers. Cursor pagination with `starting_after_uuid` and `limit` on some endpoints. `sort_by` with an allowlist per endpoint"
      },
      {
        "label": "Writes",
        "value": "PUT takes a delta plus the resource's `version` and returns 409 on a stale one. `idempotency_key` on People Batch creation. Calculate and submit answer 202 and are polled"
      },
      {
        "label": "Errors",
        "value": "JSON `errors` array with `error_key`, `category`, `message` and `metadata`. 18 documented categories, among them `payroll_blocker`, `invalid_resource_version`, `missing_oauth_scopes` and `rate_limit_exceeded`"
      },
      {
        "label": "Versioning",
        "value": "Dated versions in `X-Gusto-API-Version`, about one a quarter. Six months of full support and six of limited support after deprecation, then 406. `Deprecation`, `Sunset` and `Link` headers"
      },
      {
        "label": "Webhooks",
        "value": "Subscriptions verified with a `verification_token`, up to 16 retries over three days, and GET /v1/events with 30 days of events"
      },
      {
        "label": "SDKs",
        "value": "API clients for TypeScript (@gusto/embedded-api 0.16.2, 1 October 2026), Python, Java, C# and Ruby, generated by Speakeasy, MIT, all labelled beta. React SDK @gusto/embedded-react-sdk 0.56.5 (7 October 2026), Apache-2.0"
      },
      {
        "label": "Status",
        "value": "https://gustoapi.statuspage.io for the Embedded API (APIs, Webhooks, Embedded Flows, Developer Portal and three portals). https://status.gusto.com for the Gusto product"
      }
    ],
    "provenance": {
      "legalEntity": "Gusto, Inc.",
      "domain": "gusto.com",
      "domainRegistered": "1995-08-23",
      "endpointOnVendorDomain": true,
      "terms": "https://gusto.com/about/terms/developer-terms-of-service",
      "privacy": "",
      "statusPage": "https://gustoapi.statuspage.io",
      "changelog": "https://docs.gusto.com/embedded-payroll/changelog",
      "securityTxt": "unknown",
      "checked": "2026-10-08",
      "notes": [
        "The NOTICE file in Gusto/gusto-cli reads Copyright 2026 Gusto, Inc.",
        "Production calls go to https://api.gusto.com. The demo environment is on a separate domain, api.gusto-demo.com.",
        "The terms URL is the one named in the OpenAPI definitions on the reference pages. gusto.com answered our reader with a bot check, so the terms, the privacy policy and /.well-known/security.txt weren't read.",
        "The API Policy published in the docs is dated 11 July 2022 and refers to Gusto's Privacy Policy without a readable link.",
        "RDAP for gusto.com gives a registration date of 1995-08-23.",
        "The docs embed https://gustoapi.statuspage.io as the API status page. status.gusto.com covers the Gusto product and also lists an API component."
      ],
      "score": 77,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Gusto, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "gusto.com, registered 1995-08-23 (31 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "gusto.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Status page",
          "value": "gustoapi.statuspage.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "could not be fetched",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://gusto.com/about/terms/developer-terms-of-service",
          "state": "unreadable",
          "reason": "the page answered HTTP 403 to our reader",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "",
          "state": "none-found",
          "points": 0,
          "max": 10
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/gusto.json",
    "live": {
      "slug": "gusto",
      "vendorStatus": {
        "page": "https://gustoapi.statuspage.io",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T17:24:29.982818447Z"
      },
      "versions": [
        {
          "registry": "github",
          "name": "Gusto/gusto-typescript-client",
          "version": "gusto_embedded_v_2025_11_15/v0.3.2",
          "released": "2026-10-01",
          "seenAt": "2026-10-08T16:15:29.553541966Z"
        },
        {
          "registry": "npm",
          "name": "@gusto/embedded-api",
          "version": "0.16.2",
          "seenAt": "2026-10-08T16:15:25.588820008Z"
        },
        {
          "registry": "npm",
          "name": "@gusto/embedded-react-sdk",
          "version": "0.56.5",
          "seenAt": "2026-10-08T16:15:29.142122622Z"
        },
        {
          "registry": "pypi",
          "name": "gusto-embedded",
          "version": "0.2.4",
          "released": "2025-04-16",
          "seenAt": "2026-10-08T16:15:29.349450484Z"
        }
      ],
      "githubStars": 2,
      "npmWeekly": 24731,
      "pypiWeekly": 104,
      "securityTxt": {
        "url": "https://gusto.com/.well-known/security.txt",
        "state": "unknown",
        "checkedAt": "2026-10-08T15:38:35.992448629Z"
      },
      "updatedAt": "2026-10-08T17:24:29.982818447Z"
    }
  }
}
