{
  "data": {
    "category": {
      "area": "business",
      "capabilities": [
        "hr.employees",
        "hr.time-off",
        "hr.org",
        "hr.onboarding",
        "hr.documents"
      ],
      "description": "Systems of record for employees, with an interface an agent can use to read and update employee data, time off, the organisation chart and onboarding tasks. Compared on API coverage, field-level permissions, webhooks and how access is granted.",
      "json": "https://www.anchorterminal.com/categories/hr.json",
      "name": "HR \u0026 employee operations",
      "slug": "hr",
      "test": "One test company of ten employees in each listing. The same tasks run through its API (read the directory, update a field, request and approve time off, start an onboarding task). We check field permissions, the audit record and events. In this run listings are graded from public evidence against the published checklist.",
      "title": "HR systems and employee records for AI agents",
      "toolCount": 4,
      "tools": [
        "deel",
        "bamboohr",
        "rippling",
        "hibob"
      ],
      "url": "https://www.anchorterminal.com/categories/hr"
    },
    "tools": [
      {
        "slug": "deel",
        "name": "Deel",
        "vendor": "Deel, Inc.",
        "vendorUrl": "https://www.deel.com",
        "kind": "http-api",
        "category": "hr",
        "summary": "Deel is a global HR, payroll and employer-of-record platform. Its REST API and hosted MCP server let an agent read and update people records, time off, organisation structure, onboarding, contracts and compliance documents.",
        "url": "https://www.anchorterminal.com/tools/deel",
        "markdownUrl": "https://www.anchorterminal.com/tools/deel.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/deel.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/deel.json",
        "repo": "https://github.com/letsdeel/deel-cli",
        "license": "Proprietary service under Deel's platform terms. The Deel CLI on GitHub is MIT",
        "transports": [
          "http",
          "streamable-http",
          "sse"
        ],
        "remoteUrl": "https://api.letsdeel.com/rest",
        "packages": [
          {
            "registry": "npm",
            "name": "@deel-org/cli"
          },
          {
            "registry": "npm",
            "name": "@deel-developers/deel"
          }
        ],
        "auth": "mixed",
        "authNotes": "Self-serve for an existing Deel customer. An admin creates an organisation or personal token in the Developer Centre (More, Developer, Access Tokens), choosing scopes and what sensitive data it can read, or registers an OAuth 2 app. No partner or sales approval is documented for a company's own data. Publishing to the Deel App Store has its own submission step, and worker tokens need the Embedded partnership. The MCP server takes OAuth with PKCE and dynamic client registration, or a personal token. Scopes follow `{resource}:read` and `{resource}:write`.",
        "pricing": "paid",
        "pricingNotes": "No separate API charge was found. Access comes with a Deel account, priced per person a month. Deel HR is $5 (Core), $19 (Advanced) or $29 (Elite) per employee, contractor management $49 per contractor and EOR $599 per employee. No free plan is on the pricing page, whose buttons book a demo. The quickstart says a sandbox can be created from the Developer Centre after signing up at app.deel.com. We didn't sign up, so whether that needs a card or a contract is unconfirmed (https://www.deel.com/pricing/, checked 2026-10-07).",
        "priceSummary": "$5 / seat-mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-07).",
          "endpoints": []
        },
        "toolCount": 86,
        "popularity": {
          "githubStars": null,
          "npmWeekly": 17,
          "pypiWeekly": null,
          "asOf": "2026-10-07"
        },
        "docsUrl": "https://developer.deel.com",
        "llmsTxt": "https://developer.deel.com/llms.txt",
        "openapi": "https://developer.deel.com/openapi/endpoints-5.json",
        "capabilities": [
          "hr.employees",
          "hr.time-off",
          "hr.org",
          "hr.onboarding",
          "hr.documents"
        ],
        "tags": [
          "hosted",
          "official",
          "mcp",
          "closed-source",
          "oauth",
          "openapi",
          "llms-txt",
          "webhooks",
          "sandbox",
          "scim",
          "typescript",
          "status-page",
          "soc2",
          "sales-led"
        ],
        "lastRelease": "2026-10-05",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 69.1,
          "grade": "B",
          "agentReady": false,
          "rank": 158,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 1,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 65,
            "maintenance": 70,
            "payments": 30,
            "reliability": 88,
            "schema": 85,
            "security": 64,
            "transparency": 69
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-07"
          },
          "negative": 0,
          "verdict": "The API has 506 operations in public OpenAPI 3.1 specs, about 90 read and write OAuth scopes, a sandbox and a dated versioning policy with one year of deprecation notice. The limit is 5 requests a second for a whole organisation, and the legal documents load only with JavaScript, so data handling terms weren't read.",
          "bestFor": "A company that already runs HR, contractors, EOR or payroll on Deel and wants an agent to read the directory, update personal information, file and review time off, follow onboarding and fetch compliance documents.",
          "strengths": [
            "Public OpenAPI 3.1 specs with 506 operations and 55 webhook events, plus llms.txt and a Markdown copy of every docs page",
            "OAuth 2 with PKCE and dynamic client registration, about 90 scopes split into read and write, and single-use refresh tokens",
            "Date-based versions with at least one year stable, one year deprecated, and `Deprecation` and `Sunset` response headers",
            "Changelog with 20 dated entries between 2 September and 5 October 2026",
            "Sandbox at api-staging.letsdeel.com with sample data, simulated payments and no emails sent to workers"
          ],
          "weaknesses": [
            "5 requests a second shared by every token in an organisation, with no rate limit headers on REST responses per the rate limits page",
            "The OpenAPI links in the docs index return 404. The working specs sit under developer.deel.com/openapi/",
            "The idempotency guide covers POST and PATCH, but the spec declares the `Idempotency-Key` header on one operation",
            "TypeScript SDK last published on 13 March 2025, and no Python SDK found",
            "Privacy policy, DPA and platform terms render only with JavaScript, and no public sub-processor list or SLA was read"
          ],
          "agentNotes": [
            "Queue calls to stay under 5 requests a second for the whole organisation. Other integrations on the same account share the limit",
            "Send `X-Version: 2026-01-01` on REST calls, and watch `X-State`, `Deprecation` and `Sunset` response headers",
            "Send a UUID `Idempotency-Key` on POST and PATCH. Only retry a 5xx on a write when the request carried one",
            "Test against https://api-staging.letsdeel.com/rest with a sandbox token. Production and sandbox tokens aren't interchangeable",
            "Request read scopes only (people:read, time-off:read) for a read-only agent. Rejecting a time-off request is irreversible"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 69.1
            }
          ],
          "editorialScores": {
            "ergonomics": 65,
            "maintenance": 70,
            "payments": 30,
            "reliability": 88,
            "schema": 85,
            "security": 64,
            "transparency": 43
          },
          "provenanceScore": 94
        },
        "connect": {
          "install": "npm install -g @deel-org/cli",
          "http": "curl -X GET 'https://api.letsdeel.com/rest/contracts' \\\n  -H 'Authorization: Bearer YOUR-TOKEN-HERE' \\\n  -H 'X-Version: 2026-01-01'",
          "config": {
            "mcpServers": {
              "deel": {
                "url": "https://api.letsdeel.com/mcp"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/hr.employees",
          "tool": "https://letme.dev/deel"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Deel HR Core",
            "unit": "seat-month",
            "usd": 5,
            "note": "per employee"
          },
          {
            "item": "Deel HR Advanced",
            "unit": "seat-month",
            "usd": 19,
            "note": "per employee"
          },
          {
            "item": "Deel HR Elite",
            "unit": "seat-month",
            "usd": 29,
            "note": "per employee"
          },
          {
            "item": "Contractor management",
            "unit": "seat-month",
            "usd": 49,
            "note": "per contractor"
          },
          {
            "item": "Employer of record",
            "unit": "seat-month",
            "usd": 599,
            "note": "per EOR employee"
          }
        ],
        "provenance": {
          "legalEntity": "Deel, Inc.",
          "domain": "deel.com",
          "domainRegistered": "1998-04-21",
          "endpointOnVendorDomain": true,
          "terms": "https://www.deel.com/legal/platform-terms-of-service",
          "privacy": "https://www.deel.com/legal/privacy-policy/",
          "statusPage": "https://status.deel.com",
          "changelog": "https://developer.deel.com/api/changelog",
          "securityTxt": "valid",
          "checked": "2026-10-07",
          "notes": [
            "The entity name comes from the copyright line of the MIT licence in letsdeel/deel-cli (Copyright (c) 2026 Deel, Inc.). The legal pages on deel.com returned no document text without JavaScript, so the contracting entity in the terms wasn't read.",
            "The API and MCP server answer on api.letsdeel.com and the sandbox on api-staging.letsdeel.com. letsdeel.com is Deel's second domain, registered 2018-10-16 per RDAP, and the docs on developer.deel.com name it.",
            "https://www.deel.com/.well-known/security.txt gives a Contact and Policy of https://www.deel.com/security and expires on 21 July 2027. api.letsdeel.com and app.deel.com return 404 for the same path.",
            "RDAP for deel.com gives a registration date of 1998-04-21.",
            "trust.deel.com is a JavaScript application and returned no readable content."
          ],
          "score": 94
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/deel.json",
        "live": {
          "slug": "deel",
          "probe": {
            "target": "https://api.letsdeel.com/rest",
            "method": "get",
            "lastAt": "2026-10-08T19:08:44.680881352Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 84,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 103,
            "p95ms24h": 224,
            "samples24h": 42,
            "samples30d": 42,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 42,
                "ok": 42
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.deel.com",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-08T17:50:33.060832245Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "letsdeel/deel-cli",
              "version": "v0.2.0",
              "released": "2026-09-24",
              "seenAt": "2026-10-08T16:08:05.333667497Z"
            },
            {
              "registry": "npm",
              "name": "@deel-developers/deel",
              "version": "2.1.56",
              "seenAt": "2026-10-08T16:08:05.112276669Z"
            },
            {
              "registry": "npm",
              "name": "@deel-org/cli",
              "version": "0.2.0",
              "seenAt": "2026-10-08T16:08:01.624087654Z"
            }
          ],
          "githubStars": 0,
          "npmWeekly": 17,
          "securityTxt": {
            "url": "https://deel.com/.well-known/security.txt",
            "state": "valid",
            "expires": "2027-07-21T00:00:00.000Z",
            "checkedAt": "2026-10-08T15:38:48.747560221Z"
          },
          "pages": [
            {
              "url": "https://developer.deel.com/api/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-08T18:17:10.934265548Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "541eae2b1eb3"
            },
            {
              "url": "https://www.deel.com/pricing/",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-08T18:27:22.883042038Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "79b3e637c08d"
            },
            {
              "url": "https://www.deel.com/legal/privacy-policy/",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-08T18:27:20.979435538Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "f7a94d8b42c7"
            },
            {
              "url": "https://www.deel.com/legal/platform-terms-of-service",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-08T18:27:18.776153643Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "a1f1b096748e"
            }
          ],
          "updatedAt": "2026-10-08T19:08:44.680881352Z"
        }
      },
      {
        "slug": "bamboohr",
        "name": "BambooHR",
        "vendor": "Bamboo HR LLC",
        "vendorUrl": "https://www.bamboohr.com",
        "kind": "http-api",
        "category": "hr",
        "summary": "HR system of record for small and medium-sized businesses, covering employee records, time off, hiring, onboarding and performance. Agents reach it through a REST API with a public OpenAPI spec, or a hosted MCP server in beta.",
        "url": "https://www.anchorterminal.com/tools/bamboohr",
        "markdownUrl": "https://www.anchorterminal.com/tools/bamboohr.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/bamboohr.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/bamboohr.json",
        "repo": "https://github.com/BambooHR/bhr-api-php",
        "license": "Proprietary service under BambooHR's terms of service and developer terms. The official PHP SDK on GitHub is MIT",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://{companyDomain}.bamboohr.com/api/v1",
        "packages": [
          {
            "registry": "packagist",
            "name": "bamboohr/api"
          }
        ],
        "auth": "mixed",
        "authNotes": "Two routes, both self-serve. A user creates an API key from the user menu in BambooHR and sends it as the username in HTTP Basic auth, and the key carries that user's permissions. Or a developer registers an application in the free developer portal and runs an OAuth 2.0 authorisation code flow against `https://{companyDomain}.bamboohr.com/authorize.php` and `/token.php`, with scopes in read and `.write` pairs, one-hour access tokens and a refresh token when `offline_access` is requested. The MCP server takes OAuth only, needs the `mcp` scope and an admin to enable the AI Connectors app, and has no dynamic client registration. The developer terms let BambooHR require review before production access or a marketplace listing.",
        "pricing": "paid",
        "pricingNotes": "Core $10, Pro $17 and Elite $25 per employee per month, or $250, $425 and $650 a month flat for companies of 25 employees or fewer, with volume discounts that aren't quantified. No separate fee for the API or the MCP server was found, and the pricing page doesn't say which plans include the API. A free trial needs no credit card (length not stated) and the developer portal account is free, so an agent's owner can start without a contract (https://www.bamboohr.com/pricing/, checked 2026-10-07).",
        "priceSummary": "$10 / seat-mo",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI spec or the pricing page (checked 2026-10-07).",
          "endpoints": []
        },
        "toolCount": 56,
        "popularity": {
          "githubStars": 34,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-07"
        },
        "docsUrl": "https://documentation.bamboohr.com",
        "llmsTxt": "https://documentation.bamboohr.com/llms.txt",
        "openapi": "https://openapi.bamboohr.io/main/latest/docs/openapi/public-openapi.yaml",
        "capabilities": [
          "hr.employees",
          "hr.time-off",
          "hr.org",
          "hr.onboarding",
          "hr.documents",
          "recruiting.applications",
          "recruiting.jobs"
        ],
        "tags": [
          "hosted",
          "paid",
          "free-trial",
          "oauth",
          "api-key",
          "mcp",
          "openapi",
          "llms-txt",
          "webhooks",
          "php",
          "status-page",
          "soc2"
        ],
        "lastRelease": "2026-08-26",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 61.7,
          "grade": "C",
          "agentReady": false,
          "rank": 319,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 2,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 61,
            "maintenance": 62,
            "payments": 35,
            "reliability": 50,
            "schema": 88,
            "security": 64,
            "transparency": 74
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-07"
          },
          "negative": 0,
          "verdict": "The REST API publishes an OpenAPI 3.1 spec with 389 operations, llms.txt and OAuth scopes with separate write variants, and every call runs with the authorising user's permissions. No rate limit numbers are published, the MCP server is in beta, and its results can omit records without saying so.",
          "bestFor": "An agent working inside one company's BambooHR account on directory lookups, time off, reports and goals, with the user's own permissions as the limit.",
          "strengths": [
            "Public OpenAPI 3.1 spec with 389 operations, plus llms.txt and a Markdown copy of every docs page",
            "OAuth 2.0 with read and `.write` scopes per data area, such as `employee:job` and `time_off:requests.write`",
            "Every API and MCP call runs with the permissions of the user who authorised it, down to field level",
            "Dated API changelog with 14 entries between 23 July and 26 August 2026",
            "Free trial with no card, and plan prices per employee published without a login"
          ],
          "weaknesses": [
            "No rate limit numbers in the reviewed documentation. The terms reserve the right to throttle",
            "The MCP server is in beta, loads 56 tools and has no dynamic client registration",
            "Restricted records and fields can be dropped from MCP and API results with no marker",
            "PHP is the only maintained official SDK. The .NET and Java SDKs are marked unmaintained",
            "No security.txt, and the SOC 2 report sits in a trust centre behind registration and an NDA"
          ],
          "agentNotes": [
            "Treat a short or empty result as what this caller may see. `list_employees` drops employees when a filter or sort field is restricted",
            "Honour `Retry-After` on 429. Rate-limited calls returned 503 before 16 September 2026, so handle both",
            "Ask for read scopes only unless the task writes. Write access needs the matching `.write` scope",
            "Request `offline_access` to receive a refresh token. Access tokens last one hour",
            "Use `list-employees` with `fields`, `filter` and cursor paging in place of the unpaginated directory endpoint"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 61.7
            }
          ],
          "editorialScores": {
            "ergonomics": 61,
            "maintenance": 62,
            "payments": 35,
            "reliability": 50,
            "schema": 88,
            "security": 64,
            "transparency": 64
          },
          "provenanceScore": 83
        },
        "connect": {
          "install": "composer require bamboohr/api",
          "http": "curl -i -u \"{API Key}:x\" \"https://{companyDomain}.bamboohr.com/api/v1/employees/directory\""
        },
        "letme": {
          "capability": "https://letme.dev/hr.employees",
          "tool": "https://letme.dev/bamboohr"
        },
        "area": "business",
        "unitPrices": [
          {
            "item": "Core plan",
            "unit": "seat-month",
            "usd": 10,
            "note": "per employee; $250 a month flat for 25 employees or fewer"
          },
          {
            "item": "Pro plan",
            "unit": "seat-month",
            "usd": 17,
            "note": "per employee; $425 a month flat for 25 employees or fewer"
          },
          {
            "item": "Elite plan",
            "unit": "seat-month",
            "usd": 25,
            "note": "per employee; $650 a month flat for 25 employees or fewer"
          }
        ],
        "provenance": {
          "legalEntity": "Bamboo HR LLC",
          "domain": "bamboohr.com",
          "domainRegistered": "2009-07-23",
          "endpointOnVendorDomain": true,
          "terms": "https://www.bamboohr.com/legal/developer-terms-of-service",
          "privacy": "https://www.bamboohr.com/legal/privacy-policy",
          "statusPage": "https://status.bamboohr.com",
          "changelog": "https://documentation.bamboohr.com/docs/past-changes-to-the-api",
          "securityTxt": "none",
          "checked": "2026-10-07",
          "notes": [
            "The developer terms (last updated February 2026) and the terms of service (last updated 18 September 2026) name Bamboo HR LLC of Draper, Utah, under Utah law.",
            "Each customer's API and MCP server answer on its own bamboohr.com subdomain. The OpenAPI spec is served from openapi.bamboohr.io.",
            "www.bamboohr.com/.well-known/security.txt and /security.txt return 404.",
            "The privacy notice is dated September 2025 and the data processing agreement was last updated 3 June 2022.",
            "RDAP for bamboohr.com gives a registration date of 2009-07-23 and Amazon Registrar, Inc. as registrar."
          ],
          "score": 83
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/bamboohr.json",
        "live": {
          "slug": "bamboohr",
          "probe": {
            "target": "https://{companyDomain}.bamboohr.com/api/v1",
            "method": "get",
            "lastAt": "2026-10-08T19:08:40.361789808Z",
            "lastOk": false,
            "lastStatus": 0,
            "lastMs": 0,
            "lastNote": "invalid character \"{\" in host name",
            "authRequired": false,
            "uptime24h": 0,
            "uptime30d": 0,
            "p50ms24h": 0,
            "p95ms24h": 0,
            "samples24h": 42,
            "samples30d": 42,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 42,
                "ok": 0
              }
            ],
            "outages": [
              {
                "start": "2026-10-08T15:28:56.936598984Z",
                "end": "0001-01-01T00:00:00Z",
                "note": "invalid character \"{\" in host name"
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.bamboohr.com",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-08T17:50:23.675113949Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "BambooHR/bhr-api-php",
              "version": "v2.0.1",
              "released": "2025-12-09",
              "seenAt": "2026-10-08T16:01:43.024945444Z"
            }
          ],
          "githubStars": 34,
          "securityTxt": {
            "url": "https://bamboohr.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-08T15:38:37.569543491Z"
          },
          "pages": [
            {
              "url": "https://documentation.bamboohr.com/docs/past-changes-to-the-api",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-08T18:19:54.999704896Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "f7d3d57fae58"
            },
            {
              "url": "https://www.bamboohr.com/pricing/",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-08T18:26:28.829581312Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "9575868f63fe"
            },
            {
              "url": "https://www.bamboohr.com/legal/privacy-policy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-08T18:26:26.88829507Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "f0516cf3582f"
            },
            {
              "url": "https://www.bamboohr.com/legal/developer-terms-of-service",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-08T18:26:24.778039851Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "ac9c7f26d76a"
            }
          ],
          "updatedAt": "2026-10-08T19:08:40.361789808Z"
        }
      },
      {
        "slug": "rippling",
        "name": "Rippling",
        "vendor": "People Center, Inc. dba Rippling",
        "vendorUrl": "https://www.rippling.com",
        "kind": "http-api",
        "category": "hr",
        "summary": "Rippling is a workforce platform for HR, payroll, IT and spend. Its REST Platform API v2 reads and writes worker, time off and organisation data with scoped Bearer tokens. A first-party MCP server runs as the signed-in employee.",
        "url": "https://www.anchorterminal.com/tools/rippling",
        "markdownUrl": "https://www.anchorterminal.com/tools/rippling.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/rippling.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/rippling.json",
        "license": "Proprietary service under Rippling's customer terms and Developer Terms of Use. The JavaScript SDK on npm is Apache-2.0",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://rest.ripplingapis.com",
        "packages": [
          {
            "registry": "npm",
            "name": "@rippling/rippling-sdk"
          }
        ],
        "auth": "mixed",
        "authNotes": "A Rippling customer creates API tokens in Tools \u003e Developer \u003e API Tokens and sends them as `Authorization: Bearer` to https://rest.ripplingapis.com. A token's access is the overlap of its chosen scopes (162 listed, most split into read and read-write) and its owner's permission profile. It is shown once, can't change owner, and is revoked when the owner is terminated or after 30 days unused. App Shop partners must use OAuth 2.0 (authorisation code with refresh, one token per customer company) and get a partner account only after applying and being approved. The Rippling MCP signs in as the employee, after an admin assigns tools in MCP Gateway.",
        "pricing": "paid",
        "pricingNotes": "No public prices. rippling.com/pricing says most products are billed per employee per month and asks for a quote, with no free tier or trial found. Reference pages name the package an endpoint needs, such as API Tier 1, with no price shown. Partners pay nothing to use the API or list in the App Shop, but must apply, and their customers need the Identity \u0026 Access Management package. Approved partners get a test company, and the API can create sandboxes. Rippling MCP tool calls need a Rippling AI trial or subscription (checked 2026-10-07).",
        "priceSummary": "Paid",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in llms.txt, the REST API essentials pages or the pricing page (checked 2026-10-07).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": null,
          "npmWeekly": 3633,
          "pypiWeekly": null,
          "asOf": "2026-10-07"
        },
        "docsUrl": "https://developer.rippling.com/documentation/rest-api",
        "llmsTxt": "https://developer.rippling.com/llms.txt",
        "capabilities": [
          "hr.employees",
          "hr.time-off",
          "hr.org",
          "hr.onboarding",
          "hr.documents",
          "recruiting.candidates"
        ],
        "tags": [
          "hosted",
          "enterprise",
          "api-key",
          "oauth",
          "mcp",
          "llms-txt",
          "typescript",
          "webhooks",
          "sales-led",
          "status-page",
          "soc2",
          "iso27001"
        ],
        "lastRelease": "2026-10-07",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 60.8,
          "grade": "C",
          "agentReady": false,
          "rank": 341,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 3,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 75,
            "maintenance": 74,
            "payments": 5,
            "reliability": 62,
            "schema": 73,
            "security": 90,
            "transparency": 51
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-07"
          },
          "negative": -3,
          "negativeNotes": [
            "2026-05-21 and 2026-06-17. The changelog labels 14 changes breaking since October 2025, among them `draft_hire_id` removed from POST /draft-hires/ responses on 21 May 2026 and `candidate_id` made required on GET /candidate-applications/ on 17 June 2026, while the reference still shows a single version, 2024-08-01. The versioning page says a breaking change requires a version update. Each change is documented on the day, so the smallest deduction applies (https://developer.rippling.com/documentation/rest-api/essentials/changelog)."
          ],
          "verdict": "API tokens carry any of 162 scopes and can never see more than their owner, and hires and worker changes land as drafts for a person to review. There is no public price, trial or self-serve signup, and status.rippling.com shows five incidents marked critical between 16 July and 29 September 2026.",
          "bestFor": "An agent working for a company already on Rippling that needs scoped reads of people, organisation and time off data, and writes that wait for human review.",
          "strengths": [
            "API tokens are limited to chosen scopes (162 listed) and to the owner's permission profile, and are revoked after 30 days unused",
            "Hires and worker changes are created as drafts for review in Rippling, and leave requests follow the normal approval flow",
            "Dated changelog with 141 entries since 6 August 2025, 46 of them between 9 July and 28 September 2026, each labelled breaking or not",
            "llms.txt with integration guidance for agents, cursor pagination, filter, expand and order_by on list endpoints",
            "SOC 1 and SOC 2 Type II, ISO 27001, ISO 27018, ISO 42001 and CSA STAR Level 2 listed, with a paid vulnerability reporting programme"
          ],
          "weaknesses": [
            "No public price, free tier or trial. rippling.com/pricing is a quote form, and endpoints name a paid package such as API Tier 1",
            "Five incidents marked critical and three marked major on status.rippling.com between 16 July and 29 September 2026",
            "The changelog labels 14 changes breaking since October 2025 while the reference still shows one version, 2024-08-01",
            "No downloadable OpenAPI file found, and the documentation site renders only with JavaScript",
            "One official SDK, JavaScript at 0.2.0-alpha.106, and the documented @rippling/rippling-sdk-mcp package returned 404 on npm"
          ],
          "agentNotes": [
            "Call https://rest.ripplingapis.com with a Bearer token and pin `Rippling-Api-Version`. Use V1 at api.rippling.com only for resources that exist nowhere else",
            "Treat a null field as possibly hidden. Check `__meta.redacted_fields`, the token's scopes and whether `expand` was sent",
            "Follow `next_link` until it is null. The default page is 50 records and a `limit` above 100 returns 400",
            "Stay under 300 requests per IP in any 10 seconds. Going over rejects every request for the next 10 seconds",
            "Send an `Idempotency-Key` on POST /hires/ and POST /draft-transitions/, then poll the request until it reaches a final status"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 60.8
            }
          ],
          "editorialScores": {
            "ergonomics": 75,
            "maintenance": 74,
            "payments": 5,
            "reliability": 62,
            "schema": 73,
            "security": 90,
            "transparency": 33
          },
          "provenanceScore": 69
        },
        "connect": {
          "install": "npm install @rippling/rippling-sdk",
          "http": "curl -X GET 'https://rest.ripplingapis.com/companies/' \\\n  -H 'Accept: application/json' \\\n  -H 'Authorization: Bearer YOUR_API_TOKEN'"
        },
        "letme": {
          "capability": "https://letme.dev/hr.employees",
          "tool": "https://letme.dev/rippling"
        },
        "area": "business",
        "provenance": {
          "legalEntity": "People Center, Inc. dba Rippling",
          "domain": "rippling.com",
          "domainRegistered": "2002-02-25",
          "endpointOnVendorDomain": false,
          "terms": "https://app.rippling.com/legal",
          "privacy": "https://app.rippling.com/legal/privacy",
          "statusPage": "https://status.rippling.com",
          "changelog": "https://developer.rippling.com/documentation/rest-api/essentials/changelog",
          "securityTxt": "none",
          "checked": "2026-10-07",
          "notes": [
            "The Vulnerability Reporting Terms and Conditions, last updated 21 August 2024, name People Center, Inc. dba Rippling and its affiliates.",
            "The v2 API answers at rest.ripplingapis.com, a separate domain from rippling.com that the vendor's llms.txt and quickstart name. V1 and the OAuth token exchange use api.rippling.com and app.rippling.com.",
            "www.rippling.com/.well-known/security.txt returns 404. Reports go through the form at rippling.com/vulnerability-reporting or to security@rippling.com.",
            "The terms, privacy notice, DPA and Developer Terms of Use sit on app.rippling.com, which returned only a JavaScript application to our reader, so their text is unread.",
            "RDAP for rippling.com gives a registration date of 2002-02-25."
          ],
          "score": 69
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/rippling.json",
        "live": {
          "slug": "rippling",
          "probe": {
            "target": "https://rest.ripplingapis.com",
            "method": "get",
            "lastAt": "2026-10-08T19:08:57.461180771Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 240,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 293,
            "p95ms24h": 718,
            "samples24h": 42,
            "samples30d": 42,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 42,
                "ok": 42
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.rippling.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-08T19:06:58.003612062Z"
          },
          "versions": [
            {
              "registry": "npm",
              "name": "@rippling/rippling-sdk",
              "version": "0.2.0-alpha.106",
              "seenAt": "2026-10-08T16:27:45.404049579Z"
            }
          ],
          "npmWeekly": 3633,
          "securityTxt": {
            "url": "https://rippling.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-08T15:38:49.166690021Z"
          },
          "pages": [
            {
              "url": "https://developer.rippling.com/documentation/rest-api/essentials/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-08T18:17:17.596835563Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "e3b0c44298fc"
            },
            {
              "url": "https://app.rippling.com/legal/privacy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-08T18:15:21.558708711Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "8a3694d85aaa"
            },
            {
              "url": "https://app.rippling.com/legal",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-08T18:15:19.356857643Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "8a3694d85aaa"
            }
          ],
          "updatedAt": "2026-10-08T19:08:57.461180771Z"
        }
      },
      {
        "slug": "hibob",
        "name": "HiBob",
        "vendor": "Hi Bob Ltd.",
        "vendorUrl": "https://www.hibob.com",
        "kind": "http-api",
        "category": "hr",
        "summary": "Bob is HiBob's HR platform for employee records, time off, attendance, tasks, documents and hiring. Agents reach it through a REST API authenticated with service users, 30 webhook events and a hosted MCP server that uses OAuth.",
        "url": "https://www.anchorterminal.com/tools/hibob",
        "markdownUrl": "https://www.anchorterminal.com/tools/hibob.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hibob.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hibob.json",
        "license": "Proprietary service under HiBob's customer subscription terms and API Terms of Use",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://api.hibob.com/v1",
        "packages": [],
        "auth": "mixed",
        "authNotes": "Access is granted by a customer's Bob admin, with no self-serve route for outsiders. Customer-built integrations use a service user, an ID and token sent as HTTP Basic, which starts with no permissions and gains them through a permission group (product areas, fields by View, View history and Edit, and which employees). OAuth 2.0 authorisation code apps are open only to approved Marketplace and technology partners through the Developer Portal, with 28 scopes, an audience the customer chooses at install, 5-minute access tokens and 30-day refresh tokens. The hosted MCP server uses OAuth as the signed-in employee and follows that person's Bob permissions.",
        "pricing": "paid",
        "pricingNotes": "No public prices. HiBob quotes per employee by company size and chosen modules, and the pricing page asks for a demo or a custom quote. No free tier or trial was found. The API sandbox at api.sandbox.hibob.com is available only to accounts that have bought the Sandbox module, so an agent cannot start without a customer contract (https://www.hibob.com/pricing-plans, checked 2026-10-07).",
        "priceSummary": "Paid",
        "where": "hosted",
        "x402": {
          "level": "no",
          "evidence": "No x402, MPP or L402 in the developer docs, the API terms or the pricing page (checked 2026-10-07).",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": null,
          "npmWeekly": null,
          "pypiWeekly": null,
          "asOf": "2026-10-07"
        },
        "docsUrl": "https://apidocs.hibob.com",
        "llmsTxt": "https://apidocs.hibob.com/llms.txt",
        "capabilities": [
          "hr.employees",
          "hr.time-off",
          "hr.org",
          "hr.onboarding",
          "hr.documents"
        ],
        "tags": [
          "hosted",
          "enterprise",
          "sales-led",
          "api-key",
          "oauth",
          "mcp",
          "llms-txt",
          "openapi",
          "webhooks",
          "sandbox",
          "status-page",
          "bug-bounty",
          "soc2"
        ],
        "lastRelease": "2026-10-07",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 57,
          "grade": "C",
          "agentReady": false,
          "rank": 429,
          "ranked": true,
          "rankOf": 629,
          "categoryRank": 4,
          "methodology": "0.4",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 47,
            "maintenance": 59,
            "payments": 0,
            "reliability": 67,
            "schema": 78,
            "security": 68,
            "transparency": 71
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-07"
          },
          "negative": 0,
          "verdict": "Service users start with no permissions and gain view or edit rights per field, and the docs are served as Markdown with an OpenAPI definition on each endpoint page. There is no public price, trial or free sandbox, so an agent needs a paying customer's admin to issue credentials. No idempotency keys or official SDKs were found.",
          "bestFor": "An agent working inside a company that already runs Bob and needs field-level control over employee data, time off requests, documents and tasks.",
          "strengths": [
            "Service users have no permissions by default, and view, edit and history rights are granted per category or field through permission groups",
            "llms.txt index and a Markdown twin of every docs page, with an OpenAPI 3.1.1 definition embedded in each endpoint page",
            "Per-endpoint rate limits are published, and 429 responses carry Retry-After and X-RateLimit headers",
            "Webhooks v2 retry with exponential backoff for up to three days, with signed requests",
            "SOC 2 Type II, ISO 27001:2022, ISO 27018:2019 and a Bugcrowd bug bounty listed on the security page"
          ],
          "weaknesses": [
            "No public price, free tier or trial. The sandbox is a purchased module",
            "People search has no pagination and returns every matching employee in one response",
            "Fields without permission or with invalid IDs are dropped from a 200 response with no warning",
            "No idempotency keys and no official SDK found in the reviewed documentation",
            "MCP setup and tool documentation sit in the help centre, which returned 403 to our reader"
          ],
          "agentNotes": [
            "Send `Authorization: Basic base64(SERVICE-USER-ID:TOKEN)` to https://api.hibob.com/v1. Ask the Bob admin to put the service user in a permission group first, because it starts with none",
            "Request only the fields needed in `fields` on POST /people/search (maximum 400). The call returns all matching employees at once, so batch by `root.id` in large companies",
            "Compare returned fields with requested ones. Missing permission or a wrong field ID yields 200 with the field omitted",
            "Stop on 401 or 403. More than 50 in 10 seconds blocks the IP for 5 minutes",
            "Back off on 429 using Retry-After. Writes such as update, create and terminate employee allow 10 calls a minute, and no idempotency key exists, so check state before retrying a write"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 0,
          "avgRating": 0,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.4",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 57
            }
          ],
          "editorialScores": {
            "ergonomics": 47,
            "maintenance": 59,
            "payments": 0,
            "reliability": 67,
            "schema": 78,
            "security": 68,
            "transparency": 58
          },
          "provenanceScore": 83
        },
        "connect": {
          "http": "curl -X POST \"https://api.hibob.com/v1/people/search\" \\\n  -u \"$BOB_SERVICE_USER_ID:$BOB_SERVICE_USER_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"fields\":[\"root.id\",\"root.email\",\"work.department\"]}'"
        },
        "letme": {
          "capability": "https://letme.dev/hr.employees",
          "tool": "https://letme.dev/hibob"
        },
        "area": "business",
        "provenance": {
          "legalEntity": "Hi Bob Ltd.",
          "domain": "hibob.com",
          "domainRegistered": "2010-02-25",
          "endpointOnVendorDomain": true,
          "terms": "https://apidocs.hibob.com/docs/api-terms-of-use",
          "privacy": "https://www.hibob.com/privacy/privacy-policy",
          "statusPage": "https://status.hibob.io",
          "changelog": "https://apidocs.hibob.com/changelog",
          "securityTxt": "unknown",
          "checked": "2026-10-07",
          "notes": [
            "The API Terms of Use name Hi Bob Ltd. and its subsidiaries. The privacy policy (updated 16 February 2026) names Hi Bob (UK) Limited, 5 New Street Square, London EC4A 3TW, and says it does not cover people who use Bob at a customer's direction.",
            "The customer subscription terms (revised January 2026) list contracting entities by region, among them Hi Bob, Inc., Hi Bob Ltd., Hi Bob (UK) Limited and Hi Bob (NL) B.V.",
            "The API answers at https://api.hibob.com/v1 and the sandbox at https://api.sandbox.hibob.com/v1. OAuth tokens are exchanged at https://auth.app.hibob.com/oauth2/v1/apps/token. The status page is on a separate domain, status.hibob.io.",
            "www.hibob.com/.well-known/security.txt returned a Cloudflare block page (403) to both of our fetchers, so its presence is unknown.",
            "RDAP for hibob.com gives a registration date of 2010-02-25.",
            "The data processing addendum page (updated September 2026) links to a pre-signed DocuSign document and does not show the terms."
          ],
          "score": 83
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/hibob.json",
        "live": {
          "slug": "hibob",
          "probe": {
            "target": "https://api.hibob.com/v1",
            "method": "get",
            "lastAt": "2026-10-08T19:08:48.897742247Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 241,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 105,
            "p95ms24h": 158,
            "samples24h": 42,
            "samples30d": 42,
            "days": [
              {
                "date": "2026-10-08",
                "probes": 42,
                "ok": 42
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.hibob.io",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-08T19:06:42.148353457Z"
          },
          "securityTxt": {
            "url": "https://hibob.com/.well-known/security.txt",
            "state": "unknown",
            "checkedAt": "2026-10-08T15:39:05.839381908Z"
          },
          "pages": [
            {
              "url": "https://apidocs.hibob.com/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-08T18:15:14.469649765Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "981f915fbe41"
            },
            {
              "url": "https://www.hibob.com/pricing-plans",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-08T18:28:16.10467361Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "ac07b0d6702c"
            },
            {
              "url": "https://www.hibob.com/privacy/privacy-policy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-08T18:28:18.345425875Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "1bf3ce3c5701"
            },
            {
              "url": "https://apidocs.hibob.com/docs/api-terms-of-use",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-08T18:15:16.937981436Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "d6b463c8c703"
            }
          ],
          "updatedAt": "2026-10-08T19:08:48.897742247Z"
        }
      }
    ]
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/categories/hr",
    "json": "https://www.anchorterminal.com/categories/hr.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/categories/hr.md",
    "slim": "https://www.anchorterminal.com/categories/hr.min.md"
  },
  "markdown": "Systems of record for employees, with an interface an agent can use to read and update employee data, time off, the organisation chart and onboarding tasks. Compared on API coverage, field-level permissions, webhooks and how access is granted.\n\n- Tools ranked: 4 · agent-ready (BB or better): 0 · accept x402: 0 · hosted endpoints: 4 · desk reviews by the panel: 0\n- JSON: https://www.anchorterminal.com/api/v1/tools.json (list) · https://www.anchorterminal.com/api/v1/rankings.json (ranked) · https://www.anchorterminal.com/api/v1/x402.json (payable) · https://www.anchorterminal.com/api/v1/capabilities.json (by capability)\n- Grades run AA, A, BB, B, C, D, E, F · methodology: https://www.anchorterminal.com/benchmark/\n\n- Capabilities in this category: hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents\n- https://letme.dev/hr.employees picks the top-graded tool in this list and says how to call it direct; calling through letme comes later (https://www.anchorterminal.com/letme/index.md)\n\n## Ranking\n\n| # | Tool | Vendor | Kind | Category | Grade | Score | Confidence | x402 | Auth | Where | Reviews | Page |\n| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |\n| 158 | Deel | Deel, Inc. | HTTP API | HR | B | 69.1 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/deel.md |\n| 319 | BambooHR | Bamboo HR LLC | HTTP API | HR | C | 61.7 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/bamboohr.md |\n| 341 | Rippling | People Center, Inc. dba Rippling | HTTP API | HR | C | 60.8 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/rippling.md |\n| 429 | HiBob | Hi Bob Ltd. | HTTP API | HR | C | 57 | medium | no | OAuth or key | hosted | none | https://www.anchorterminal.com/tools/hibob.md |\n\nScores are from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/), with Performance and Task success pending. p95 latency and context cost come from our probes, which haven't run yet.\n\n## Summaries\n\n### 158. Deel, B (69.1)\n\nDeel is a global HR, payroll and employer-of-record platform. Its REST API and hosted MCP server let an agent read and update people records, time off, organisation structure, onboarding, contracts and compliance documents. The API has 506 operations in public OpenAPI 3.1 specs, about 90 read and write OAuth scopes, a sandbox and a dated versioning policy with one year of deprecation notice. The limit is 5 requests a second for a whole organisation, and the legal documents load only with JavaScript, so data handling terms weren't read.\n\n- Page: https://www.anchorterminal.com/tools/deel · Markdown: https://www.anchorterminal.com/tools/deel.md · JSON: https://www.anchorterminal.com/api/v1/tools/deel.json\n- Capabilities: hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents · endpoint: `https://api.letsdeel.com/rest`\n\n### 319. BambooHR, C (61.7)\n\nHR system of record for small and medium-sized businesses, covering employee records, time off, hiring, onboarding and performance. Agents reach it through a REST API with a public OpenAPI spec, or a hosted MCP server in beta. The REST API publishes an OpenAPI 3.1 spec with 389 operations, llms.txt and OAuth scopes with separate write variants, and every call runs with the authorising user's permissions. No rate limit numbers are published, the MCP server is in beta, and its results can omit records without saying so.\n\n- Page: https://www.anchorterminal.com/tools/bamboohr · Markdown: https://www.anchorterminal.com/tools/bamboohr.md · JSON: https://www.anchorterminal.com/api/v1/tools/bamboohr.json\n- Capabilities: hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents, recruiting.applications, recruiting.jobs · endpoint: `https://{companyDomain}.bamboohr.com/api/v1`\n\n### 341. Rippling, C (60.8)\n\nRippling is a workforce platform for HR, payroll, IT and spend. Its REST Platform API v2 reads and writes worker, time off and organisation data with scoped Bearer tokens. A first-party MCP server runs as the signed-in employee. API tokens carry any of 162 scopes and can never see more than their owner, and hires and worker changes land as drafts for a person to review. There is no public price, trial or self-serve signup, and status.rippling.com shows five incidents marked critical between 16 July and 29 September 2026.\n\n- Page: https://www.anchorterminal.com/tools/rippling · Markdown: https://www.anchorterminal.com/tools/rippling.md · JSON: https://www.anchorterminal.com/api/v1/tools/rippling.json\n- Capabilities: hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents, recruiting.candidates · endpoint: `https://rest.ripplingapis.com`\n\n### 429. HiBob, C (57)\n\nBob is HiBob's HR platform for employee records, time off, attendance, tasks, documents and hiring. Agents reach it through a REST API authenticated with service users, 30 webhook events and a hosted MCP server that uses OAuth. Service users start with no permissions and gain view or edit rights per field, and the docs are served as Markdown with an OpenAPI definition on each endpoint page. There is no public price, trial or free sandbox, so an agent needs a paying customer's admin to issue credentials. No idempotency keys or official SDKs were found.\n\n- Page: https://www.anchorterminal.com/tools/hibob · Markdown: https://www.anchorterminal.com/tools/hibob.md · JSON: https://www.anchorterminal.com/api/v1/tools/hibob.json\n- Capabilities: hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents · endpoint: `https://api.hibob.com/v1`\n\n## How we test this category\n\nOne test company of ten employees in each listing. The same tasks run through its API (read the directory, update a field, request and approve time off, start an onboarding task). We check field permissions, the audit record and events. In this run listings are graded from public evidence against the published checklist. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence.\n\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "HR \u0026 employee operations",
        "url": ""
      }
    ],
    "description": "4 HR \u0026 employee operations ranked by the Anchor benchmark. Leader Deel (B). Systems of record for employees, with an interface an agent can use to read and update employee data, time off, the organisation chart and onboarding tasks. Compared on API coverage, field-level permissions, webhooks and how access is granted.",
    "facts": [
      "Deel B",
      "BambooHR C",
      "Rippling C"
    ],
    "h1": "HR systems and employee records for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/categories-hr.png",
    "path": "/categories/hr",
    "published": "",
    "section": "tools",
    "title": "HR systems and employee records for AI agents, ranked",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/categories/hr"
  },
  "tokens": {
    "markdown": 1700,
    "slim": 330
  },
  "version": 1
}
