{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "zeal",
    "name": "Zeal",
    "vendor": "Puzzl Group Inc.",
    "vendorUrl": "https://www.zeal.com",
    "kind": "http-api",
    "category": "payroll",
    "summary": "Zeal is an embedded payroll API for US staffing platforms, labour marketplaces and workforce software. Partners create employer companies, onboard W-2 employees and 1099 contractors, create pay cheques and contractor payments, preview payroll and pull reports.",
    "url": "https://www.anchorterminal.com/tools/zeal",
    "markdownUrl": "https://www.anchorterminal.com/tools/zeal.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/zeal.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/zeal.json",
    "repo": "https://github.com/zeal-corp/typescript-sdk",
    "license": "Proprietary service. The npm SDK declares MIT. The SDK repositories on GitHub carry no licence file",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://api.zeal.com",
    "packages": [
      {
        "registry": "npm",
        "name": "@zeal-api/sdk"
      },
      {
        "registry": "pypi",
        "name": "zeal-api-sdk"
      }
    ],
    "auth": "api-key",
    "authNotes": "API keys, issued only to Zeal partners. Zeal's team creates the partner account after a demo request, then the Partner Dashboard at app.zeal.com shows one Test API key, one Production API key and the `partnerID`. Every call sends `Authorization: Bearer {apiKey}`, and most also need a `companyID`. A key covers every employer company under the partner, has no scopes, and is rolled from the dashboard, which invalidates the old key at once. Production payroll is switched on by Zeal (error code 0 until then). The agent chat and MCP endpoints need a key that Zeal has Agent-enabled. This is embedded-payroll partner access. An employer has no separate API route into its own Zeal payroll account.",
    "pricing": "paid",
    "pricingNotes": "No public prices. www.zeal.com/pricing returns 404 and every call to action asks for a demo. A test environment that moves no money exists, but its key comes only after Zeal creates a partner account, so an agent cannot start without a sales contact. No free tier or self-serve trial was found (checked 2026-10-08).",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in llms-full.txt, the OpenAPI specs or the marketing site (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 0,
      "npmWeekly": 8,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.zeal.com",
    "llmsTxt": "https://docs.zeal.com/llms.txt",
    "openapi": "https://docs.zeal.com/openapi/zeal-api.json",
    "capabilities": [
      "payroll.run",
      "payroll.embedded",
      "payroll.employees",
      "payroll.contractors",
      "payroll.tax-filing",
      "hr.onboarding"
    ],
    "tags": [
      "hosted",
      "api-key",
      "openapi",
      "llms-txt",
      "typescript",
      "python",
      "webhooks",
      "sandbox",
      "sales-led",
      "partner-only",
      "us-only",
      "soc2",
      "mcp"
    ],
    "lastRelease": "2026-07-31",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 45.4,
      "grade": "E",
      "agentReady": false,
      "rank": 658,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 8,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 63,
        "maintenance": 61,
        "payments": 0,
        "reliability": 42,
        "schema": 68,
        "security": 34,
        "transparency": 51
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 42,
          "points": 8.4,
          "reason": "Read with the hosted rubric, on the partner REST API. No status page found. None is linked from the site, the docs or the help centre, and status.zeal.com did not complete a TLS handshake on 8 October 2026 (0). With no page there is no readable incident history (5). The rate limit is published as 100 requests a second in both Test and Production (15). The error page recommends exponential backoff on 429 and an `x-idempotency-key` header is honoured for 24 hours, but no Retry-After header is documented (12 of 15). No SLA found on the public site (0). The core REST API is generally available. Endpoints marked Early Access and the agent and MCP endpoints are enabled per partner (10). Total 42."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 68,
          "points": 11.05,
          "reason": "Three public OpenAPI 3.1 specs at docs.zeal.com/openapi, the main one with 128 paths and 177 operations (25). docs.zeal.com/llms.txt, llms-full.txt (514 KB) and a Markdown copy of every page (10). 99 of 177 operations carry a description, 18 have no summary and 5 are titled \"Copy of\", and pages rarely say when not to use an endpoint (10 of 20). 359 `required` lists and 120 enums, with 212 of 228 parameters described, against 82 objects with no declared properties and string-typed dates (10 of 15). 2,088 examples in the spec and a table of 116 numbered error codes with HTTP statuses. 429 is not declared in the spec (13 of 15). The API has no version in the path or a header, the spec version is a fixed 1.0, and the changelog URL the site links to returns 404 (0). Total 68."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 63,
          "points": 10.24,
          "reason": "Responses can't be trimmed by field. `limit` is on a few list endpoints and one webhook has a lite form with IDs only (8 of 25). Cursor pagination with `start_at`, `limit` and `meta.next`, on some endpoints only, with filters by company, employee, date and status (10 of 20). Errors come as `{message, code}` with 116 documented codes, several of which name the fix, such as code 89 for a date past the 2 PM cut-off (17 of 20). `x-idempotency-key` for 24 hours on writes, and the SDKs retry 408, 429 and 5xx twice with backoff. The spec declares the header nowhere (16 of 20). TypeScript and Python SDKs at 0.2.1, generated with Fern and not mentioned in the docs. Most calls need both `companyID` and, at partner level, `partnerID`, and previews and reports are asynchronous jobs (12 of 15). Total 63."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 34,
          "points": 5.95,
          "reason": "One Test key and one Production key per partner account, sent as a Bearer header, rollable from the dashboard with the old key invalidated at once. A key reaches every employer company under the partner and has no scopes, so we scored between one all-powerful key and plain revocable keys (15 of 30). No read-only key. `approval_required` holds a cheque or contractor payment until `approved` is set, and the Test environment moves no money (8 of 20). The API returns names, addresses and metadata written by workers and employers, and the agent and MCP endpoints return model-written text, with no guidance on untrusted content found (3 of 15). No audit log or per-call log was found in the docs (0). The legal page states SOC 2 Type II, AWS hosting, TLS 1.2 and AES-256, with no report, trust centre, disclosure policy, bounty or security.txt (8 of 20). Total 34."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 0,
          "points": 0,
          "reason": "Read with the hosted rubric. No x402, MPP or L402 (0). No price is published. www.zeal.com/pricing returns 404 and the site asks for a demo (0). No free tier or self-serve trial. Test keys exist only after Zeal's team creates a partner account (0). A person has to contact sales and log in to the Partner Dashboard for a key (0). Total 0."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 61,
          "points": 5.34,
          "reason": "With the changelog returning 404, the newest dated public release is the Python SDK zeal-api-sdk 0.2.1 on 31 July 2026, 69 days before the check (20 of 30). npm shows @zeal-api/sdk 0.1.0, 0.2.0 and 0.2.1 on 28, 29 and 30 July 2026, three releases inside 90 days, all in one week (20). A closed service with a help centre and support@zeal.com, and no working public changelog or community channel (5 of 25). Official SDKs in two languages, both at 0.2.1 and not referenced by the docs (12 of 15). The SDK repositories hold tests and a Dependabot branch but no CI workflow, and the Python package declares no licence (4 of 10). Total 61."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 51,
          "points": 4.46,
          "note": "editorial 38, provenance 64",
          "reason": "Editorial half only. A closed service. The public terms are a website Terms of Use and Payroll Terms between Puzzl Group Inc. and a partner's client. The partner agreement is not public (12 of 30). The privacy notice, last updated 16 January 2026, keeps data as long as necessary with no periods, lists vendor categories only, and still gives a privacy@joinpuzzl address in one place. The Payroll Terms let Puzzl use aggregate or de-identified data for its own purposes. No DPA found (12 of 30). One dated deprecation, the `garnishment` deduction type with a sunset of 15 October 2026, and no written policy (8 of 20). AWS hosting and Bangor Savings Bank are named. No sub-processor list or data location statement found (6 of 20). Total 38."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Responses can't be trimmed by field. `limit` is on a few list endpoints and one webhook has a lite form with IDs only (8 of 25). Cursor pagination with `start_at`, `limit` and `meta.next`, on some endpoints only, with filters by company, employee, date and status (10 of 20). Errors come as `{message, code}` with 116 documented codes, several of which name the fix, such as code 89 for a date past the 2 PM cut-off (17 of 20). `x-idempotency-key` for 24 hours on writes, and the SDKs retry 408, 429 and 5xx twice with backoff. The spec declares the header nowhere (16 of 20). TypeScript and Python SDKs at 0.2.1, generated with Fern and not mentioned in the docs. Most calls need both `companyID` and, at partner level, `partnerID`, and previews and reports are asynchronous jobs (12 of 15). Total 63.",
          "maintenance": "With the changelog returning 404, the newest dated public release is the Python SDK zeal-api-sdk 0.2.1 on 31 July 2026, 69 days before the check (20 of 30). npm shows @zeal-api/sdk 0.1.0, 0.2.0 and 0.2.1 on 28, 29 and 30 July 2026, three releases inside 90 days, all in one week (20). A closed service with a help centre and support@zeal.com, and no working public changelog or community channel (5 of 25). Official SDKs in two languages, both at 0.2.1 and not referenced by the docs (12 of 15). The SDK repositories hold tests and a Dependabot branch but no CI workflow, and the Python package declares no licence (4 of 10). Total 61.",
          "payments": "Read with the hosted rubric. No x402, MPP or L402 (0). No price is published. www.zeal.com/pricing returns 404 and the site asks for a demo (0). No free tier or self-serve trial. Test keys exist only after Zeal's team creates a partner account (0). A person has to contact sales and log in to the Partner Dashboard for a key (0). Total 0.",
          "reliability": "Read with the hosted rubric, on the partner REST API. No status page found. None is linked from the site, the docs or the help centre, and status.zeal.com did not complete a TLS handshake on 8 October 2026 (0). With no page there is no readable incident history (5). The rate limit is published as 100 requests a second in both Test and Production (15). The error page recommends exponential backoff on 429 and an `x-idempotency-key` header is honoured for 24 hours, but no Retry-After header is documented (12 of 15). No SLA found on the public site (0). The core REST API is generally available. Endpoints marked Early Access and the agent and MCP endpoints are enabled per partner (10). Total 42.",
          "schema": "Three public OpenAPI 3.1 specs at docs.zeal.com/openapi, the main one with 128 paths and 177 operations (25). docs.zeal.com/llms.txt, llms-full.txt (514 KB) and a Markdown copy of every page (10). 99 of 177 operations carry a description, 18 have no summary and 5 are titled \"Copy of\", and pages rarely say when not to use an endpoint (10 of 20). 359 `required` lists and 120 enums, with 212 of 228 parameters described, against 82 objects with no declared properties and string-typed dates (10 of 15). 2,088 examples in the spec and a table of 116 numbered error codes with HTTP statuses. 429 is not declared in the spec (13 of 15). The API has no version in the path or a header, the spec version is a fixed 1.0, and the changelog URL the site links to returns 404 (0). Total 68.",
          "security": "One Test key and one Production key per partner account, sent as a Bearer header, rollable from the dashboard with the old key invalidated at once. A key reaches every employer company under the partner and has no scopes, so we scored between one all-powerful key and plain revocable keys (15 of 30). No read-only key. `approval_required` holds a cheque or contractor payment until `approved` is set, and the Test environment moves no money (8 of 20). The API returns names, addresses and metadata written by workers and employers, and the agent and MCP endpoints return model-written text, with no guidance on untrusted content found (3 of 15). No audit log or per-call log was found in the docs (0). The legal page states SOC 2 Type II, AWS hosting, TLS 1.2 and AES-256, with no report, trust centre, disclosure policy, bounty or security.txt (8 of 20). Total 34.",
          "transparency": "Editorial half only. A closed service. The public terms are a website Terms of Use and Payroll Terms between Puzzl Group Inc. and a partner's client. The partner agreement is not public (12 of 30). The privacy notice, last updated 16 January 2026, keeps data as long as necessary with no periods, lists vendor categories only, and still gives a privacy@joinpuzzl address in one place. The Payroll Terms let Puzzl use aggregate or de-identified data for its own purposes. No DPA found (12 of 30). One dated deprecation, the `garnishment` deduction type with a sunset of 15 October 2026, and no written policy (8 of 20). AWS hosting and Bangor Savings Bank are named. No sub-processor list or data location statement found (6 of 20). Total 38."
        },
        "sources": [
          {
            "what": "API introduction, base URL, environments and error format",
            "url": "https://docs.zeal.com/reference/introduction/introduction",
            "seen": "2026-10-08"
          },
          {
            "what": "Authentication, key rolling and webhook secret",
            "url": "https://docs.zeal.com/reference/introduction/authentication-and-keys",
            "seen": "2026-10-08"
          },
          {
            "what": "Rate limiting",
            "url": "https://docs.zeal.com/reference/introduction/rate-limiting",
            "seen": "2026-10-08"
          },
          {
            "what": "Idempotency",
            "url": "https://docs.zeal.com/reference/introduction/idempotency",
            "seen": "2026-10-08"
          },
          {
            "what": "Pagination",
            "url": "https://docs.zeal.com/reference/introduction/pagination",
            "seen": "2026-10-08"
          },
          {
            "what": "Error codes",
            "url": "https://docs.zeal.com/reference/introduction/error-codes",
            "seen": "2026-10-08"
          },
          {
            "what": "Early Access endpoints",
            "url": "https://docs.zeal.com/reference/introduction/early-access-endpoints",
            "seen": "2026-10-08"
          },
          {
            "what": "Account setup and API keys",
            "url": "https://docs.zeal.com/docs/account-setup-and-api-keys",
            "seen": "2026-10-08"
          },
          {
            "what": "Introduction to payroll runs",
            "url": "https://docs.zeal.com/docs/introduction-to-payroll-runs",
            "seen": "2026-10-08"
          },
          {
            "what": "Preview payroll guide",
            "url": "https://docs.zeal.com/docs/preview-payroll-guide",
            "seen": "2026-10-08"
          },
          {
            "what": "FAQs (coverage, tax engine, year-end forms)",
            "url": "https://docs.zeal.com/docs/faqs",
            "seen": "2026-10-08"
          },
          {
            "what": "Main OpenAPI spec, including /mcp and /agents/chat",
            "url": "https://docs.zeal.com/openapi/zeal-api.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Docs index for agents",
            "url": "https://docs.zeal.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Full docs text",
            "url": "https://docs.zeal.com/llms-full.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Changelog URL (404)",
            "url": "https://docs.zeal.com/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "Home page and navigation",
            "url": "https://www.zeal.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "Marketing llms.txt (RTF)",
            "url": "https://www.zeal.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Legal page with privacy, security, terms and payroll terms",
            "url": "https://www.zeal.com/legal",
            "seen": "2026-10-08"
          },
          {
            "what": "Pricing URL (404)",
            "url": "https://www.zeal.com/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt (404)",
            "url": "https://www.zeal.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Help centre",
            "url": "https://support.zeal.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "API root and unauthenticated response",
            "url": "https://api.zeal.com/companies",
            "seen": "2026-10-08"
          },
          {
            "what": "TypeScript SDK repository",
            "url": "https://github.com/zeal-corp/typescript-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK repository",
            "url": "https://github.com/zeal-corp/python-sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry entry",
            "url": "https://registry.npmjs.org/@zeal-api/sdk",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI entry",
            "url": "https://pypi.org/pypi/zeal-api-sdk/json",
            "seen": "2026-10-08"
          },
          {
            "what": "Domain registration (RDAP)",
            "url": "https://rdap.verisign.com/com/v1/domain/zeal.com",
            "seen": "2026-10-08"
          },
          {
            "what": "Official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=zeal",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: whether status.zeal.com is a live status page. It did not complete a TLS handshake from our network, and no status link was found on the site",
          "unchecked: weekly downloads for zeal-api-sdk on PyPI. pypistats returned no data",
          "The tools, schemas and annotations behind the /mcp endpoint. The spec names four tools and says access needs an Agent-enabled key from Zeal",
          "Prices, any SLA and the partner agreement, none of which are public",
          "Whether the Partner Dashboard keeps an audit log of API calls",
          "The date of the last API change. The changelog URL returns 404 and the API root shows only a build hash",
          "Whether Zeal has a SOC 2 report or sub-processor list available under NDA"
        ]
      },
      "negative": 0,
      "verdict": "Graded on the partner REST API at api.zeal.com, which is the only access route. Three OpenAPI specs, llms.txt, a test environment that moves no money, a preview endpoint and a per-cheque approval flag are documented. Access starts with a demo request, prices are not published, each environment has one unscoped key, and no status page or working changelog was found.",
      "bestFor": "A US staffing platform, marketplace or workforce product that will sign a partnership and run payroll for many employers under its own brand, including daily and on-demand pay.",
      "strengths": [
        "Public OpenAPI 3.1 specs with 177 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page",
        "Test keys run payroll end to end with no money moved and no tax filings, in an environment separate from production",
        "Preview endpoints return the gross-to-net breakdown before processing, and `approval_required` holds a cheque until `approved` is set",
        "`x-idempotency-key` header honoured for 24 hours, and 116 numbered error codes with messages",
        "Fern-generated TypeScript and Python SDKs (0.2.1, July 2026) that retry 408, 429 and 5xx with backoff"
      ],
      "weaknesses": [
        "No self-serve signup. Zeal's team creates the partner account after a demo request, and no price is published",
        "One test key and one production key per partner account, with no scopes and no read-only key",
        "No status page found, and the changelog linked from the home page and llms.txt returns 404",
        "The API has no version in the path or a header, and the main spec has 18 operations with no summary",
        "Webhooks carry the shared secret itself in `Puzzl-Signature`, not a signature of the payload",
        "No security.txt, disclosure policy, sub-processor list or DPA found on the public site"
      ],
      "agentNotes": [
        "Use the Test API key until a person has approved live payroll. Error code 0 (403) means the account has no production access",
        "Send `companyID` on almost every call and `partnerID` on partner-level calls, in the body for POST and PATCH and the query for GET",
        "Create cheques with `approval_required: true`, run POST /preview/checks, then PATCH /employeeCheck with `approved: true`. Without the flag Zeal processes pending cheques automatically",
        "Send `x-idempotency-key` on every create so a retry within 24 hours doesn't pay twice",
        "Previews and reports are jobs. Keep the `job_id` and poll GET /preview or GET /reports, or wait for the Job Queue webhook",
        "Check dates must be bank days and submitted before 2 PM Pacific two bank days ahead, or the call fails with code 89"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "E",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 45.4
        }
      ],
      "editorialScores": {
        "ergonomics": 63,
        "maintenance": 61,
        "payments": 0,
        "reliability": 42,
        "schema": 68,
        "security": 34,
        "transparency": 38
      },
      "provenanceScore": 64
    },
    "connect": {
      "install": "npm i -s @zeal-api/sdk",
      "http": "curl --request GET \\\n     --url 'https://api.zeal.com/companies?partnerID=YOUR_PARTNER_ID' \\\n     --header 'Accept: application/json' \\\n     --header 'Authorization: Bearer YOUR_API_KEY'"
    },
    "letme": {
      "capability": "https://letme.dev/payroll.run",
      "tool": "https://letme.dev/zeal"
    },
    "notable": [
      "Access is by partnership. The setup guide says to contact Zeal to create a Partner Account, and Zeal's integration team leads the setup (https://docs.zeal.com/docs/account-setup-and-api-keys)",
      "Test keys process payroll end to end with no money moved and no real tax filings (https://docs.zeal.com/reference/introduction/authentication-and-keys)",
      "Zeal processes pending cheques automatically before the cheque date unless `approval_required` is set and the cheque is left unapproved (https://docs.zeal.com/reference/employee-checks/employee-checks/employee-check-object)",
      "The spec at docs.zeal.com/openapi/zeal-api.json lists an MCP Streamable HTTP endpoint at /mcp and POST /agents/chat, both gated on an Agent-enabled API key (https://docs.zeal.com/openapi/zeal-api.json)",
      "The changelog linked from the home page and from www.zeal.com/llms.txt returned 404 on 8 October 2026 (https://docs.zeal.com/changelog)",
      "www.zeal.com/llms.txt is served as an RTF document with RTF control codes, while docs.zeal.com/llms.txt is plain Markdown (https://www.zeal.com/llms.txt)",
      "The `garnishment` deduction type is marked deprecated with a sunset of 15 October 2026 in favour of the Garnishments API (https://docs.zeal.com/llms-full.txt)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "Access route graded",
        "value": "Embedded-payroll partnership. A software platform becomes a Zeal partner and holds the keys for every employer company it creates. Zeal has no API for an employer to reach an existing payroll account of its own outside a partner"
      },
      {
        "label": "API",
        "value": "REST at https://api.zeal.com with no version in the path, JSON in and out. The main OpenAPI 3.1 spec has 128 paths and 177 operations (91 POST, 58 GET, 19 PATCH, 8 DELETE, 1 PUT)"
      },
      {
        "label": "Environments",
        "value": "Test and Production, each with its own key and separate data. Test processes payroll with no money moved and no tax filings. Responses carry `testMode`"
      },
      {
        "label": "Credentials",
        "value": "One Test API key and one Production API key per partner account, sent as a Bearer token, rolled from the API page of the Partner Dashboard. No scopes"
      },
      {
        "label": "Preview and approval",
        "value": "POST /preview/checks, /preview/checkDate and /preview/checkData start a job, GET /preview returns the breakdown. `approval_required` on a cheque or contractor payment blocks processing until `approved` is true"
      },
      {
        "label": "Rate limits",
        "value": "100 requests a second in both modes, then 429. The error page recommends exponential backoff. No Retry-After header is documented"
      },
      {
        "label": "Idempotency",
        "value": "`x-idempotency-key` request header, honoured for 24 hours, in both modes"
      },
      {
        "label": "Pagination",
        "value": "Cursor with `start_at` and `limit` on some list endpoints, with `meta.next` and `meta.previous` links. Not every endpoint pages"
      },
      {
        "label": "Errors",
        "value": "`{success:false, errors:[{message, code}]}` with 116 numbered codes mapped to HTTP statuses. An unauthenticated call returned a `correlationId` on 8 October 2026"
      },
      {
        "label": "Webhooks",
        "value": "27 reference pages covering company, employee, contractor, cheque, payment, shift, report job, paperwork, bank account and garnishment events. URLs are set per event in the dashboard. `Puzzl-Signature` carries the shared secret"
      },
      {
        "label": "SDKs",
        "value": "@zeal-api/sdk 0.2.1 on npm (30 July 2026, MIT) and zeal-api-sdk 0.2.1 on PyPI (31 July 2026), both generated with Fern. The docs site does not mention them"
      },
      {
        "label": "Agents and MCP",
        "value": "The spec lists POST /agents/chat and an MCP Streamable HTTP endpoint at /mcp with four tools (ask_PayrollSpecialistAgent, ask_HrSpecialistAgent, ask_ReportingSpecialistAgent, ask_MigrationsSpecialistAgent). Both need an Agent-enabled key that Zeal's team switches on. No guide page found"
      },
      {
        "label": "Coverage",
        "value": "United States only, all 50 states. W-2 employees and 1099 contractors. Zeal says it files and pays payroll taxes and issues W-2 and 1099 forms"
      },
      {
        "label": "Early Access",
        "value": "Endpoints marked Early Access (I-9, custom paperwork, paycards, customer accounts, employee requirements) are enabled per partner contract"
      },
      {
        "label": "Security claims",
        "value": "SOC 2 Type II, AWS hosting, TLS 1.2 in transit and AES-256 at rest, per the security tab of zeal.com/legal. No report or trust centre is linked"
      }
    ],
    "provenance": {
      "legalEntity": "Puzzl Group Inc.",
      "domain": "zeal.com",
      "domainRegistered": "1995-07-03",
      "endpointOnVendorDomain": true,
      "terms": "https://www.zeal.com/legal?tab=terms-of-service",
      "privacy": "https://www.zeal.com/legal?tab=privacy-policy",
      "statusPage": "",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The legal page names Puzzl Group Inc., a Delaware corporation, 80 Langton Street, San Francisco, CA 94103. Its privacy notice was last updated on 16 January 2026.",
        "The API answers at https://api.zeal.com and docs at docs.zeal.com (hosted on Mintlify). The help centre at support.zeal.com runs on Pylon.",
        "www.zeal.com/.well-known/security.txt and docs.zeal.com/.well-known/security.txt return 404.",
        "No status page is linked from the site, the docs or the help centre. status.zeal.com did not complete a TLS handshake on 8 October 2026.",
        "The changelog URL the site advertises, https://docs.zeal.com/changelog, returns 404, so the field is left empty.",
        "The legal page says banking services come from Bangor Savings Bank, Member FDIC.",
        "RDAP for zeal.com gives a registration date of 1995-07-03 and GoDaddy.com, LLC as registrar."
      ],
      "score": 64,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Puzzl Group Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "zeal.com, registered 1995-07-03 (31 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "api.zeal.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
          "points": 5.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 7 of the 8 things a reader expects",
          "points": 9.3,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.zeal.com/legal?tab=terms-of-service",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-01-16",
          "words": 16886,
          "points": 5.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated January 16, 2026",
              "says": "Last updated 2026-01-16"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "These Terms shall be governed by and construed in accordance with the laws of the State of California including all matters of construction, validity, performance, and enforcement and without giving effect to the principles of conflict of laws.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "IN NO EVENT WILL WE OR OUR DIRECTORS, EMPLOYEES, OR AGENTS BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, EXEMPLARY, INCIDENTAL, SPECIAL, OR PUNITIVE DAMAGES, INCLUDING LOST PROFIT, LOST REVENUE, LOSS OF DATA, OR OTHER DAMAGES ARISING FROM YOUR USE OF THE SITE, EVEN IF WE HAVE BEEN ADVISE…",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "In Short: You may review, change, or terminate your account at any time."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "We will alert you about any changes by updating the “Last updated” date of these Terms of Use, and you waive any right to receive specific notice of each such change.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "(3) you will not access the Site through automated or non-human means, whether through a bot, script or otherwise;"
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.automated",
              "label": "Restricts automated access",
              "found": true,
              "quote": "(viii) attempt to access or search the Software or download content from the Software using any engine, software, tool, agent, device or mechanism (including spiders, robots, crawlers, data mining tools or the like)",
              "costsPoints": true
            },
            {
              "key": "terms.nonotice",
              "label": "Says the terms or the service can change without notice",
              "found": true,
              "quote": "Because the Services are evolving over time, Puzzl or Partner may change or discontinue all or any part of the Services, at any time and without notice, at Puzzl’s or Partner’s sole discretion.",
              "costsPoints": true
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "Liability for breach of the service agreement is limited to the greater of the additional charges assessed against the client or 1,000 US dollars, plus tax interest or penalties caused by the breach.",
              "quote": "(I) FOR PUZZL TO REMIT TO THE APPROPRIATE PAYEE OF CLIENT THE GREATER OF: (A) THE AMOUNT OF ADDITIONAL CHARGES ASSESSED AGAINST CLIENT UNDER THIS AGREEMENT OR (B) ONE THOUSAND ($1,000) U.S. DOLLARS;"
            },
            {
              "date": "2026-10-08",
              "text": "The client grants an irrevocable licence under which Puzzl may compile aggregate or de-identified data from Client Data and use it for its own purposes.",
              "quote": "(ii) compile and use for Puzzl’s own purposes aggregate or de identified data, statistics, measurements or other metrics derived from Client Data and Client’s use of the Services, which do not identify Client or Client’s Employees (“Aggregate Data”)."
            },
            {
              "date": "2026-10-08",
              "text": "The client irrevocably permits Puzzl to use the client's signature on file for tax filings, administrative filings and corrections, and Puzzl is not obliged to tell the client when it does.",
              "quote": "While Puzzl will use commercially reasonable efforts to inform Client of such permitted usage of Client’s signature on file, Client agree that company is not obligated to do so."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.zeal.com/legal?tab=privacy-policy",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-01-16",
          "words": 16886,
          "points": 9.3,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated January 16, 2026",
              "says": "Last updated 2026-01-16"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "In Short: We collect personal information about you from a variety of sources."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this privacy notice and as otherwise required or permitted by law.",
              "says": "For as long as needed, with no period named"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "When you request us to share certain information with third parties, such as through your use of social media widgets or login integrations."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We do not “sell” such Personal Information about you to third parties and have not done so in the past 12 months."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "If you have questions or comments about your privacy rights, you may email us at privacy@zeal.com."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "If you have any questions or concerns about this privacy notice, or our practices with regards to your personal information, please contact us at privacy@zeal.com.",
              "says": "privacy@zeal.com"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "After a request to end an account, Zeal deactivates or deletes it from active databases but may keep some information for fraud prevention, troubleshooting, investigations, enforcement and legal requirements.",
              "quote": "However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our Terms of Use and/or comply with applicable legal requirements."
            },
            {
              "date": "2026-10-08",
              "text": "The notice states that the website is for residents of the United States only.",
              "quote": "This website is for US residents only."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/zeal.json",
    "live": {
      "slug": "zeal",
      "probe": {
        "target": "https://api.zeal.com",
        "method": "get",
        "lastAt": "2026-10-08T19:53:07.16387972Z",
        "lastOk": true,
        "lastStatus": 200,
        "lastMs": 626,
        "authRequired": false,
        "uptime24h": 98,
        "uptime30d": 98,
        "p50ms24h": 604,
        "p95ms24h": 700,
        "samples24h": 50,
        "samples30d": 50,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 50,
            "ok": 49
          }
        ]
      },
      "versions": [
        {
          "registry": "npm",
          "name": "@zeal-api/sdk",
          "version": "0.2.1",
          "seenAt": "2026-10-08T16:35:37.1323379Z"
        },
        {
          "registry": "pypi",
          "name": "zeal-api-sdk",
          "version": "0.2.1",
          "released": "2026-07-31",
          "seenAt": "2026-10-08T16:35:39.815769205Z"
        }
      ],
      "githubStars": 0,
      "npmWeekly": 8,
      "pypiWeekly": 4,
      "securityTxt": {
        "url": "https://zeal.com/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:30.40067532Z"
      },
      "pages": [
        {
          "url": "https://www.zeal.com/legal?tab=privacy-policy",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:31:44.751983613Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "ca2c8021bf60"
        },
        {
          "url": "https://www.zeal.com/legal?tab=terms-of-service",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-08T18:31:46.842036275Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "ca2c8021bf60"
        }
      ],
      "updatedAt": "2026-10-08T19:53:07.16387972Z"
    }
  }
}
