{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "hibob",
    "name": "HiBob",
    "vendor": "Hi Bob Ltd.",
    "vendorUrl": "https://www.hibob.com",
    "kind": "http-api",
    "category": "hr",
    "summary": "Bob is HiBob's HR platform for employee records, time off, attendance, tasks, documents and hiring. Agents reach it through a REST API authenticated with service users, 30 webhook events and a hosted MCP server that uses OAuth.",
    "url": "https://www.anchorterminal.com/tools/hibob",
    "markdownUrl": "https://www.anchorterminal.com/tools/hibob.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hibob.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hibob.json",
    "license": "Proprietary service under HiBob's customer subscription terms and API Terms of Use",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.hibob.com/v1",
    "packages": [],
    "auth": "mixed",
    "authNotes": "Access is granted by a customer's Bob admin, with no self-serve route for outsiders. Customer-built integrations use a service user, an ID and token sent as HTTP Basic, which starts with no permissions and gains them through a permission group (product areas, fields by View, View history and Edit, and which employees). OAuth 2.0 authorisation code apps are open only to approved Marketplace and technology partners through the Developer Portal, with 28 scopes, an audience the customer chooses at install, 5-minute access tokens and 30-day refresh tokens. The hosted MCP server uses OAuth as the signed-in employee and follows that person's Bob permissions.",
    "pricing": "paid",
    "pricingNotes": "No public prices. HiBob quotes per employee by company size and chosen modules, and the pricing page asks for a demo or a custom quote. No free tier or trial was found. The API sandbox at api.sandbox.hibob.com is available only to accounts that have bought the Sandbox module, so an agent cannot start without a customer contract (https://www.hibob.com/pricing-plans, checked 2026-10-07).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the developer docs, the API terms or the pricing page (checked 2026-10-07).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-07"
    },
    "docsUrl": "https://apidocs.hibob.com",
    "llmsTxt": "https://apidocs.hibob.com/llms.txt",
    "capabilities": [
      "hr.employees",
      "hr.time-off",
      "hr.org",
      "hr.onboarding",
      "hr.documents"
    ],
    "tags": [
      "hosted",
      "enterprise",
      "sales-led",
      "api-key",
      "oauth",
      "mcp",
      "llms-txt",
      "openapi",
      "webhooks",
      "sandbox",
      "status-page",
      "bug-bounty",
      "soc2"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 57,
      "grade": "C",
      "agentReady": false,
      "rank": 429,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 4,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 47,
        "maintenance": 59,
        "payments": 0,
        "reliability": 67,
        "schema": 78,
        "security": 68,
        "transparency": 71
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 67,
          "points": 13.4,
          "reason": "Graded on the public REST API. Statuspage at status.hibob.io with 46 components, Public API among them (20). Nine incidents between 9 July and 7 October 2026. Three were major or critical on single modules (employee work tables failing to update for 4 hours 26 minutes on 31 August, Talent for 1 hour 9 minutes on 26 August, Workforce Planning on 4 August), and the Public API component is named once, for 2 hours 6 minutes of slowness on 3 August, which we scored between minor only and one major outage (12). Per-endpoint limits are published, such as 50 a minute on people search and 10 on employee updates (15). 429 carries Retry-After and X-RateLimit headers and the docs ask for backoff on 429 and 500, but no idempotency keys were found for writes (10). No SLA found, and the subscription terms disclaim uninterrupted service (0). The API is generally available, while the OAuth MCP server is in gradual rollout (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 78,
          "points": 12.68,
          "reason": "Each endpoint and webhook page embeds an OpenAPI 3.1.1 definition in its Markdown version. No single downloadable spec was found (20). llms.txt and a .md twin of every page (10). Endpoint descriptions state permissions, supported user types and a list of critical behaviours such as no pagination and silent omission, though not when to choose another endpoint (15). Inputs are typed with enums (humanReadable APPEND or REPLACE) and limits (400 fields), but field IDs are free strings resolved through metadata endpoints (10). Request examples and documented 400, 403, 429 and default responses, with error bodies that differ by module (11). A /v1 path and a dated changelog with an RSS feed, with no per-entry dates in the Markdown twins (12)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 47,
          "points": 7.64,
          "reason": "The `fields` array sizes people responses, but people search returns every matching employee in one response (13). Cursor pagination with a limit up to 200 covers bulk tables, workforce planning and the job catalogue only, and people search filters accept only `root.id` and `root.email` with equals (10). Status codes and recovery advice are documented (no retry on 400, stop on 401 and 403), but fields without permission vanish from a 200 response with no warning (12). No idempotency keys. 304 signals an unchanged record, and the MCP tool annotations could not be read (6). Few required parameters on reads. No official SDK found in the reviewed documentation (6)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 68,
          "points": 11.9,
          "reason": "Service users are separate, revocable credentials with no permissions by default and rights granted per feature, per field and per employee population. They travel as HTTP Basic. OAuth with 28 scopes, 5-minute access tokens and a customer-chosen audience exists for approved partners, and the MCP server uses OAuth as the signed-in employee (25). Field-level View and Edit make read-only service users possible. No confirmation step for terminate or delete calls was found (14). The API returns text written by employees, and no injection guidance was found. The MCP documentation was unreadable (2). Bob has an API audit log linked from the docs, whose article we could not open (10). SOC 2 Type II, ISO 27001:2022, ISO 27018:2019, third-party penetration tests and a Bugcrowd bounty. security.txt could not be checked (17)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 0,
          "points": 0,
          "reason": "No x402, MPP or L402 (0). Prices are by quote only (0). No free tier or trial found, and the sandbox is a purchased module (0). Credentials come from a customer's admin in the Bob interface, with no programmatic route (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 59,
          "points": 5.16,
          "reason": "The newest developer changelog entry is dated 7 October 2026 (30). Ten entries between 21 July and 7 October, including new Employee Tables endpoints on 17 August and a Skills API on 5 August (20). A dated changelog with RSS and a support desk. No public issue tracker or developer forum was found (9). No official SDKs found, and the MCP registry could not be reached to check for an entry (0). No public packages or CI to assess (0)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 71,
          "points": 6.21,
          "note": "editorial 58, provenance 83",
          "reason": "Closed service with public API Terms of Use and customer subscription terms revised January 2026 (15). The subscription terms promise deletion of personal data within 30 days of termination and let HiBob use anonymised, aggregated customer data freely. The privacy policy excludes data processed for customers, and the DPA sits behind a DocuSign link we could not read (15). Past deprecations carried dates and four to seven months' notice (2023 and 2024), but the deprecations page was last updated in May 2025 and the API terms promise notice only where commercially reasonable (10). The sub-processor list (November 2025) names providers, purposes and locations, including OpenAI and Azure OpenAI for optional functions, and hosting is stated as AWS Ireland with Frankfurt for recovery (18)."
        }
      ],
      "assessment": {
        "date": "2026-10-07",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "The `fields` array sizes people responses, but people search returns every matching employee in one response (13). Cursor pagination with a limit up to 200 covers bulk tables, workforce planning and the job catalogue only, and people search filters accept only `root.id` and `root.email` with equals (10). Status codes and recovery advice are documented (no retry on 400, stop on 401 and 403), but fields without permission vanish from a 200 response with no warning (12). No idempotency keys. 304 signals an unchanged record, and the MCP tool annotations could not be read (6). Few required parameters on reads. No official SDK found in the reviewed documentation (6).",
          "maintenance": "The newest developer changelog entry is dated 7 October 2026 (30). Ten entries between 21 July and 7 October, including new Employee Tables endpoints on 17 August and a Skills API on 5 August (20). A dated changelog with RSS and a support desk. No public issue tracker or developer forum was found (9). No official SDKs found, and the MCP registry could not be reached to check for an entry (0). No public packages or CI to assess (0).",
          "payments": "No x402, MPP or L402 (0). Prices are by quote only (0). No free tier or trial found, and the sandbox is a purchased module (0). Credentials come from a customer's admin in the Bob interface, with no programmatic route (0).",
          "reliability": "Graded on the public REST API. Statuspage at status.hibob.io with 46 components, Public API among them (20). Nine incidents between 9 July and 7 October 2026. Three were major or critical on single modules (employee work tables failing to update for 4 hours 26 minutes on 31 August, Talent for 1 hour 9 minutes on 26 August, Workforce Planning on 4 August), and the Public API component is named once, for 2 hours 6 minutes of slowness on 3 August, which we scored between minor only and one major outage (12). Per-endpoint limits are published, such as 50 a minute on people search and 10 on employee updates (15). 429 carries Retry-After and X-RateLimit headers and the docs ask for backoff on 429 and 500, but no idempotency keys were found for writes (10). No SLA found, and the subscription terms disclaim uninterrupted service (0). The API is generally available, while the OAuth MCP server is in gradual rollout (10).",
          "schema": "Each endpoint and webhook page embeds an OpenAPI 3.1.1 definition in its Markdown version. No single downloadable spec was found (20). llms.txt and a .md twin of every page (10). Endpoint descriptions state permissions, supported user types and a list of critical behaviours such as no pagination and silent omission, though not when to choose another endpoint (15). Inputs are typed with enums (humanReadable APPEND or REPLACE) and limits (400 fields), but field IDs are free strings resolved through metadata endpoints (10). Request examples and documented 400, 403, 429 and default responses, with error bodies that differ by module (11). A /v1 path and a dated changelog with an RSS feed, with no per-entry dates in the Markdown twins (12).",
          "security": "Service users are separate, revocable credentials with no permissions by default and rights granted per feature, per field and per employee population. They travel as HTTP Basic. OAuth with 28 scopes, 5-minute access tokens and a customer-chosen audience exists for approved partners, and the MCP server uses OAuth as the signed-in employee (25). Field-level View and Edit make read-only service users possible. No confirmation step for terminate or delete calls was found (14). The API returns text written by employees, and no injection guidance was found. The MCP documentation was unreadable (2). Bob has an API audit log linked from the docs, whose article we could not open (10). SOC 2 Type II, ISO 27001:2022, ISO 27018:2019, third-party penetration tests and a Bugcrowd bounty. security.txt could not be checked (17).",
          "transparency": "Closed service with public API Terms of Use and customer subscription terms revised January 2026 (15). The subscription terms promise deletion of personal data within 30 days of termination and let HiBob use anonymised, aggregated customer data freely. The privacy policy excludes data processed for customers, and the DPA sits behind a DocuSign link we could not read (15). Past deprecations carried dates and four to seven months' notice (2023 and 2024), but the deprecations page was last updated in May 2025 and the API terms promise notice only where commercially reasonable (10). The sub-processor list (November 2025) names providers, purposes and locations, including OpenAI and Azure OpenAI for optional functions, and hosting is stated as AWS Ireland with Frankfurt for recovery (18)."
        },
        "sources": [
          {
            "what": "developer docs index (llms.txt)",
            "url": "https://apidocs.hibob.com/llms.txt",
            "seen": "2026-10-07"
          },
          {
            "what": "API reference index",
            "url": "https://apidocs.hibob.com/reference/llms.txt",
            "seen": "2026-10-07"
          },
          {
            "what": "service users and permissions",
            "url": "https://apidocs.hibob.com/docs/api-service-users",
            "seen": "2026-10-07"
          },
          {
            "what": "authorisation header",
            "url": "https://apidocs.hibob.com/reference/authorization",
            "seen": "2026-10-07"
          },
          {
            "what": "rate limiting and WAF blocking",
            "url": "https://apidocs.hibob.com/reference/rate-limiting",
            "seen": "2026-10-07"
          },
          {
            "what": "people endpoints and their limits",
            "url": "https://apidocs.hibob.com/reference/people",
            "seen": "2026-10-07"
          },
          {
            "what": "people search, embedded OpenAPI",
            "url": "https://apidocs.hibob.com/reference/post_people-search.md",
            "seen": "2026-10-07"
          },
          {
            "what": "pagination",
            "url": "https://apidocs.hibob.com/reference/pagination-1",
            "seen": "2026-10-07"
          },
          {
            "what": "error handling",
            "url": "https://apidocs.hibob.com/reference/error-handling",
            "seen": "2026-10-07"
          },
          {
            "what": "OAuth 2.0 for partners",
            "url": "https://apidocs.hibob.com/reference/oauth-20",
            "seen": "2026-10-07"
          },
          {
            "what": "webhooks v2",
            "url": "https://apidocs.hibob.com/reference/getting-started-webhooks",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP server note and OAuth changelog entry",
            "url": "https://apidocs.hibob.com/changelog/developer-docs-update-bob-mcp-server-now-uses-oauth",
            "seen": "2026-10-07"
          },
          {
            "what": "MCP product page",
            "url": "https://www.hibob.com/mcp-beta",
            "seen": "2026-10-07"
          },
          {
            "what": "changelog feed",
            "url": "https://apidocs.hibob.com/changelog.rss",
            "seen": "2026-10-07"
          },
          {
            "what": "API changes and deprecations",
            "url": "https://apidocs.hibob.com/page/api-changes-deprecations",
            "seen": "2026-10-07"
          },
          {
            "what": "API Terms of Use",
            "url": "https://apidocs.hibob.com/docs/api-terms-of-use",
            "seen": "2026-10-07"
          },
          {
            "what": "status incidents",
            "url": "https://status.hibob.io/api/v2/incidents.json",
            "seen": "2026-10-07"
          },
          {
            "what": "pricing",
            "url": "https://www.hibob.com/pricing-plans",
            "seen": "2026-10-07"
          },
          {
            "what": "security page",
            "url": "https://www.hibob.com/privacy/security",
            "seen": "2026-10-07"
          },
          {
            "what": "customer subscription terms",
            "url": "https://www.hibob.com/privacy/customer-subscription-terms",
            "seen": "2026-10-07"
          },
          {
            "what": "privacy policy",
            "url": "https://www.hibob.com/privacy/privacy-policy",
            "seen": "2026-10-07"
          },
          {
            "what": "subsidiaries and sub-processors",
            "url": "https://www.hibob.com/privacy/hibob-subsidiaries-and-sub-processors",
            "seen": "2026-10-07"
          },
          {
            "what": "domain registration (RDAP)",
            "url": "https://rdap.org/domain/hibob.com",
            "seen": "2026-10-07"
          }
        ],
        "openQuestions": [
          "unchecked: the help centre article on the MCP server (server URL, tool list, annotations, confirmation of writes), which returned 403",
          "unchecked: www.hibob.com/.well-known/security.txt, which returned a Cloudflare block page",
          "unchecked: the DPA text, which sits behind a DocuSign link",
          "unchecked: the official MCP registry, which did not answer from our shell",
          "unchecked: the help centre article on API audit logs and on rotating service user tokens",
          "Whether a time off request can be approved or declined through the public API. No such endpoint is in the reference index, and the MCP tool list was unreadable",
          "Whether API access or the MCP server costs extra on top of the core subscription",
          "Whether an SLA exists in order forms",
          "apidocs.hibob.com served a bot check to curl after about 25 requests. Later pages were read through WebFetch"
        ]
      },
      "negative": 0,
      "verdict": "Service users start with no permissions and gain view or edit rights per field, and the docs are served as Markdown with an OpenAPI definition on each endpoint page. There is no public price, trial or free sandbox, so an agent needs a paying customer's admin to issue credentials. No idempotency keys or official SDKs were found.",
      "bestFor": "An agent working inside a company that already runs Bob and needs field-level control over employee data, time off requests, documents and tasks.",
      "strengths": [
        "Service users have no permissions by default, and view, edit and history rights are granted per category or field through permission groups",
        "llms.txt index and a Markdown twin of every docs page, with an OpenAPI 3.1.1 definition embedded in each endpoint page",
        "Per-endpoint rate limits are published, and 429 responses carry Retry-After and X-RateLimit headers",
        "Webhooks v2 retry with exponential backoff for up to three days, with signed requests",
        "SOC 2 Type II, ISO 27001:2022, ISO 27018:2019 and a Bugcrowd bug bounty listed on the security page"
      ],
      "weaknesses": [
        "No public price, free tier or trial. The sandbox is a purchased module",
        "People search has no pagination and returns every matching employee in one response",
        "Fields without permission or with invalid IDs are dropped from a 200 response with no warning",
        "No idempotency keys and no official SDK found in the reviewed documentation",
        "MCP setup and tool documentation sit in the help centre, which returned 403 to our reader"
      ],
      "agentNotes": [
        "Send `Authorization: Basic base64(SERVICE-USER-ID:TOKEN)` to https://api.hibob.com/v1. Ask the Bob admin to put the service user in a permission group first, because it starts with none",
        "Request only the fields needed in `fields` on POST /people/search (maximum 400). The call returns all matching employees at once, so batch by `root.id` in large companies",
        "Compare returned fields with requested ones. Missing permission or a wrong field ID yields 200 with the field omitted",
        "Stop on 401 or 403. More than 50 in 10 seconds blocks the IP for 5 minutes",
        "Back off on 429 using Retry-After. Writes such as update, create and terminate employee allow 10 calls a minute, and no idempotency key exists, so check state before retrying a write"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 57
        }
      ],
      "editorialScores": {
        "ergonomics": 47,
        "maintenance": 59,
        "payments": 0,
        "reliability": 67,
        "schema": 78,
        "security": 68,
        "transparency": 58
      },
      "provenanceScore": 83
    },
    "connect": {
      "http": "curl -X POST \"https://api.hibob.com/v1/people/search\" \\\n  -u \"$BOB_SERVICE_USER_ID:$BOB_SERVICE_USER_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"fields\":[\"root.id\",\"root.email\",\"work.department\"]}'"
    },
    "letme": {
      "capability": "https://letme.dev/hr.employees",
      "tool": "https://letme.dev/hibob"
    },
    "notable": [
      "Customer integrations authenticate with a service user ID and token over HTTP Basic. OAuth 2.0 apps are for approved Marketplace and technology partners only (https://apidocs.hibob.com/reference/oauth-20)",
      "The hosted MCP server moved to OAuth per employee on 30 June 2026 in a gradual rollout, and its setup and tool documentation are kept only in the Bob help centre (https://apidocs.hibob.com/changelog/developer-docs-update-bob-mcp-server-now-uses-oauth)",
      "POST /people/search returns all matching employees in one response with no pagination, and omits fields the service user cannot read without a warning (https://apidocs.hibob.com/reference/post_people-search)",
      "Every docs page has a Markdown version at the same URL plus .md, indexed at llms.txt, and endpoint pages embed their OpenAPI 3.1.1 definition (https://apidocs.hibob.com/llms.txt)",
      "status.hibob.io lists nine incidents between 9 July and 7 October 2026, three of them major or critical on single modules. The Public API component is named in one, 2 hours 6 minutes of slowness on 3 August (https://status.hibob.io/history)",
      "The API terms let HiBob change rate limits without notice and say advance notice of deprecations is given where commercially reasonable (https://apidocs.hibob.com/docs/api-terms-of-use)",
      "Pricing is by quote, based on employee count and modules, with no trial on the pricing page (https://www.hibob.com/pricing-plans)"
    ],
    "area": "business",
    "details": [
      {
        "label": "Surface graded",
        "value": "The public REST API at https://api.hibob.com/v1 with service-user credentials. The hosted MCP server is noted but its tool documentation could not be read"
      },
      {
        "label": "API coverage",
        "value": "265 reference entries across employee data, employee and custom tables, time off, attendance and projects, tasks, reports, documents, goals, skills, job catalogue, employers, workforce planning and hiring, 30 of them webhook events"
      },
      {
        "label": "Credentials",
        "value": "Service user ID and token over HTTP Basic for customer integrations. OAuth 2.0 authorisation code for approved Marketplace partners, with 5-minute access tokens, 30-day refresh tokens and 28 scopes such as employee_data:read and timeoff:write"
      },
      {
        "label": "Permissions",
        "value": "Service users start with none. Permission groups grant product areas, people's data by category or field (View, View history, Edit) and the set of employees covered. Sensitive fields need both View and Edit to be returned"
      },
      {
        "label": "MCP server",
        "value": "Hosted, released 28 April 2026 with service users and moved to OAuth per employee from June 2026 in a gradual rollout. HiBob lists ChatGPT, Claude.ai, Claude Desktop and Cursor as clients. An admin enables it in Bob"
      },
      {
        "label": "Rate limits",
        "value": "Per endpoint per minute. People search 50, read employee by ID 100, update, create and terminate employee 10 each, public profiles 40. The Docs API has none at present. More than 50 responses of 401 or 403 in 10 seconds blocks the IP for 5 minutes"
      },
      {
        "label": "Errors",
        "value": "400, 401, 403, 404, 429 and 500 documented with JSON bodies whose shape varies by module. 429 carries Retry-After, X-RateLimit-Limit and X-RateLimit-Remaining. 304 means the submitted data matched the record"
      },
      {
        "label": "Pagination",
        "value": "Cursor and limit (default 50, maximum 200) on bulk table, workforce planning and job catalogue endpoints. People search and read by ID are not paginated"
      },
      {
        "label": "Webhooks",
        "value": "v2 events for employees, time off, tasks, documents and workforce planning. Payloads carry identifiers and changed-field metadata only. Signed, retried with exponential backoff for up to 3 days, then the webhook is deactivated"
      },
      {
        "label": "Time off",
        "value": "Submit and cancel requests, read balances, policies, who's out and request changes, and create balance adjustments. No approve or decline endpoint is listed in the reference index"
      },
      {
        "label": "Sandbox",
        "value": "https://api.sandbox.hibob.com/v1, available only to accounts that have bought the Sandbox module"
      },
      {
        "label": "Audit",
        "value": "Bob has an API audit log of Public API usage, linked from the developer docs. The help centre article describing it returned 403 to our reader"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II, ISO 27001:2022 and ISO 27018:2019 per hibob.com/privacy/security. Bug bounty on Bugcrowd. Hosted on AWS in Ireland with disaster recovery in Frankfurt"
      },
      {
        "label": "Status",
        "value": "status.hibob.io on Statuspage, 46 components including Public API, Sandbox, Time Off, Docs and Tasks"
      },
      {
        "label": "Sub-processors",
        "value": "List updated November 2025. AWS (EU), SingleStore (EU), Cloudinary, Cloudflare and Zendesk as core, with OpenAI and Microsoft Azure OpenAI for optional AI functions"
      }
    ],
    "provenance": {
      "legalEntity": "Hi Bob Ltd.",
      "domain": "hibob.com",
      "domainRegistered": "2010-02-25",
      "endpointOnVendorDomain": true,
      "terms": "https://apidocs.hibob.com/docs/api-terms-of-use",
      "privacy": "https://www.hibob.com/privacy/privacy-policy",
      "statusPage": "https://status.hibob.io",
      "changelog": "https://apidocs.hibob.com/changelog",
      "securityTxt": "unknown",
      "checked": "2026-10-07",
      "notes": [
        "The API Terms of Use name Hi Bob Ltd. and its subsidiaries. The privacy policy (updated 16 February 2026) names Hi Bob (UK) Limited, 5 New Street Square, London EC4A 3TW, and says it does not cover people who use Bob at a customer's direction.",
        "The customer subscription terms (revised January 2026) list contracting entities by region, among them Hi Bob, Inc., Hi Bob Ltd., Hi Bob (UK) Limited and Hi Bob (NL) B.V.",
        "The API answers at https://api.hibob.com/v1 and the sandbox at https://api.sandbox.hibob.com/v1. OAuth tokens are exchanged at https://auth.app.hibob.com/oauth2/v1/apps/token. The status page is on a separate domain, status.hibob.io.",
        "www.hibob.com/.well-known/security.txt returned a Cloudflare block page (403) to both of our fetchers, so its presence is unknown.",
        "RDAP for hibob.com gives a registration date of 2010-02-25.",
        "The data processing addendum page (updated September 2026) links to a pre-signed DocuSign document and does not show the terms."
      ],
      "score": 83,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Hi Bob Ltd.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "hibob.com, registered 2010-02-25 (16 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.hibob.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 4 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 3.4,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "status.hibob.io",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "could not be fetched",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://apidocs.hibob.com/docs/api-terms-of-use",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 2527,
          "points": 3.4,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "If a provision shall be found unenforceable by a court of law, the remaining provisions of these Terms will remain in full effect and an enforceable term will be substituted reflecting the parties’ intent as accurately as possible."
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "TO THE FULLEST EXTENT PERMITTED BY LAW, AND OTHER THAN IN THE EVENT OF WILLFUL MISCONDUCT OR GROSS NEGLIGENCE, HIBOB’S AGGREGATE LIABILITY UNDER THIS AGREEMENT SHALL NOT EXCEED $100 USD (“LIABILITY CAP”).",
              "says": "Capped at $100"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "We may suspend or terminate your access to, or use of, the APIs without notice for breach or suspected breach of these API Terms."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": false
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Except as expressly provided herein, you may not copy, translate, modify, create derivative works of, sell, lease, sublicense, distribute or publicly display any of the API Licensed Material."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "Without limiting the generality of the foregoing, you may not: (i) scrape, crawl, build a database of, or create a permanent copy of the API Licensed Material or any portion except as strictly necessary for the permitted operation of the Integrated App in accordance with these API Terms;",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "HiBob reserves the right to modify such limits at any time without notice.",
              "costsPoints": true
            },
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "We may suspend or terminate your access to, or use of, the APIs without notice for breach or suspected breach of these API Terms."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "HiBob's aggregate liability under the API terms is capped at 100 US dollars, except for wilful misconduct or gross negligence.",
              "quote": "TO THE FULLEST EXTENT PERMITTED BY LAW, AND OTHER THAN IN THE EVENT OF WILLFUL MISCONDUCT OR GROSS NEGLIGENCE, HIBOB’S AGGREGATE LIABILITY UNDER THIS AGREEMENT SHALL NOT EXCEED $100 USD (“LIABILITY CAP”)."
            },
            {
              "date": "2026-10-08",
              "text": "The API terms give read only access and no right to change API data in HiBob's platform unless expressly permitted.",
              "quote": "For clarity's sake, you have no right to change any of the API data within HiBob’s platform unless expressly permitted in the applicable HiBob documents or without our prior written consent and shall have a “read only” access."
            },
            {
              "date": "2026-10-08",
              "text": "Any third party that is to use the API material needs HiBob's prior written consent and must agree to the API terms.",
              "quote": "You agree you will ensure you obtain HiBob’s prior written consent and will ensure that such third party agrees to the API Terms for any third party that you wish to have used the API Licensed Materials for the purposes herein"
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.hibob.com/privacy/privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "words": 8781,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We collect various types of personal data regarding our Visitors, Prospects, Community Members, and our Customers’ Admins and Recruiters."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Data Retention: We will retain your personal data for as long as it is reasonably necessary in order to establish, maintain and expand our relationship and provide you with our Services and offerings;"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "Such data is typically collected or generated through your interaction with us or our Services, through automatic means, directly from you, or via third parties (including Service Providers, as defined in Section 4 below)."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "Under some data protection laws, like the CCPA and other US state privacy laws, our disclosure of this data to third parties for targeted advertising may be considered as a “sale” or “sharing” of personal information."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "You may also submit a request to exercise your rights as explained in Section 8 below."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "as our Data Protection Officer (DPO), for monitoring and advising on HiBob’s ongoing privacy compliance and serving as a point of contact on privacy matters for individuals and supervisory authorities.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "…UK, and Switzerland (as relevant), we and the relevant data exporters and importers have entered into standard contractual clauses as approved by the European Commission (available here), the UK (available here), or Switzerland.",
              "says": "Relies on standard contractual clauses"
            }
          ],
          "toKnow": [
            {
              "key": "privacy.sells",
              "label": "Says it sells personal data or shares it for advertising",
              "found": true,
              "quote": "Under some data protection laws, like the CCPA and other US state privacy laws, our disclosure of this data to third parties for targeted advertising may be considered as a “sale” or “sharing” of personal information."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The policy does not cover people who use the product at a customer's direction, such as the customer's employees and contractors.",
              "quote": "Please note that this Privacy Policy does NOT cover our practices regarding individuals who use the Solutions at our Customer’s direction, including a Customer’s employees, staff, and contractors (“End Users”)."
            },
            {
              "date": "2026-10-08",
              "text": "De-identified data created from personal data may be used by HiBob or its business partners for any purpose.",
              "quote": "To create aggregated data, inferred non-personal data or anonymized or pseudonymized data (de-identified data), which we or our business partners may use to provide and improve our respective services, conduct research, or for any other purpose."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/hibob.json",
    "live": {
      "slug": "hibob",
      "probe": {
        "target": "https://api.hibob.com/v1",
        "method": "get",
        "lastAt": "2026-10-08T17:36:37.312372469Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 98,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 106,
        "p95ms24h": 157,
        "samples24h": 25,
        "samples30d": 25,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 25,
            "ok": 25
          }
        ]
      },
      "vendorStatus": {
        "page": "https://status.hibob.io",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-08T17:24:34.678682095Z"
      },
      "securityTxt": {
        "url": "https://hibob.com/.well-known/security.txt",
        "state": "unknown",
        "checkedAt": "2026-10-08T15:39:05.839381908Z"
      },
      "updatedAt": "2026-10-08T17:36:37.312372469Z"
    }
  }
}
