{
  "data": {
    "a": {
      "slug": "hibob",
      "name": "HiBob",
      "vendor": "Hi Bob Ltd.",
      "vendorUrl": "https://www.hibob.com",
      "kind": "http-api",
      "category": "hr",
      "summary": "Bob is HiBob's HR platform for employee records, time off, attendance, tasks, documents and hiring. Agents reach it through a REST API authenticated with service users, 30 webhook events and a hosted MCP server that uses OAuth.",
      "url": "https://www.anchorterminal.com/tools/hibob",
      "markdownUrl": "https://www.anchorterminal.com/tools/hibob.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/hibob.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/hibob.json",
      "license": "Proprietary service under HiBob's customer subscription terms and API Terms of Use",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.hibob.com/v1",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is granted by a customer's Bob admin, with no self-serve route for outsiders. Customer-built integrations use a service user, an ID and token sent as HTTP Basic, which starts with no permissions and gains them through a permission group (product areas, fields by View, View history and Edit, and which employees). OAuth 2.0 authorisation code apps are open only to approved Marketplace and technology partners through the Developer Portal, with 28 scopes, an audience the customer chooses at install, 5-minute access tokens and 30-day refresh tokens. The hosted MCP server uses OAuth as the signed-in employee and follows that person's Bob permissions.",
      "pricing": "paid",
      "pricingNotes": "No public prices. HiBob quotes per employee by company size and chosen modules, and the pricing page asks for a demo or a custom quote. No free tier or trial was found. The API sandbox at api.sandbox.hibob.com is available only to accounts that have bought the Sandbox module, so an agent cannot start without a customer contract (https://www.hibob.com/pricing-plans, checked 2026-10-07).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, the API terms or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://apidocs.hibob.com",
      "llmsTxt": "https://apidocs.hibob.com/llms.txt",
      "capabilities": [
        "hr.employees",
        "hr.time-off",
        "hr.org",
        "hr.onboarding",
        "hr.documents"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "sales-led",
        "api-key",
        "oauth",
        "mcp",
        "llms-txt",
        "openapi",
        "webhooks",
        "sandbox",
        "status-page",
        "bug-bounty",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57,
        "grade": "C",
        "agentReady": false,
        "rank": 429,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 47,
          "maintenance": 59,
          "payments": 0,
          "reliability": 67,
          "schema": 78,
          "security": 68,
          "transparency": 71
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": 0,
        "verdict": "Service users start with no permissions and gain view or edit rights per field, and the docs are served as Markdown with an OpenAPI definition on each endpoint page. There is no public price, trial or free sandbox, so an agent needs a paying customer's admin to issue credentials. No idempotency keys or official SDKs were found.",
        "bestFor": "An agent working inside a company that already runs Bob and needs field-level control over employee data, time off requests, documents and tasks.",
        "strengths": [
          "Service users have no permissions by default, and view, edit and history rights are granted per category or field through permission groups",
          "llms.txt index and a Markdown twin of every docs page, with an OpenAPI 3.1.1 definition embedded in each endpoint page",
          "Per-endpoint rate limits are published, and 429 responses carry Retry-After and X-RateLimit headers",
          "Webhooks v2 retry with exponential backoff for up to three days, with signed requests",
          "SOC 2 Type II, ISO 27001:2022, ISO 27018:2019 and a Bugcrowd bug bounty listed on the security page"
        ],
        "weaknesses": [
          "No public price, free tier or trial. The sandbox is a purchased module",
          "People search has no pagination and returns every matching employee in one response",
          "Fields without permission or with invalid IDs are dropped from a 200 response with no warning",
          "No idempotency keys and no official SDK found in the reviewed documentation",
          "MCP setup and tool documentation sit in the help centre, which returned 403 to our reader"
        ],
        "agentNotes": [
          "Send `Authorization: Basic base64(SERVICE-USER-ID:TOKEN)` to https://api.hibob.com/v1. Ask the Bob admin to put the service user in a permission group first, because it starts with none",
          "Request only the fields needed in `fields` on POST /people/search (maximum 400). The call returns all matching employees at once, so batch by `root.id` in large companies",
          "Compare returned fields with requested ones. Missing permission or a wrong field ID yields 200 with the field omitted",
          "Stop on 401 or 403. More than 50 in 10 seconds blocks the IP for 5 minutes",
          "Back off on 429 using Retry-After. Writes such as update, create and terminate employee allow 10 calls a minute, and no idempotency key exists, so check state before retrying a write"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57
          }
        ],
        "editorialScores": {
          "ergonomics": 47,
          "maintenance": 59,
          "payments": 0,
          "reliability": 67,
          "schema": 78,
          "security": 68,
          "transparency": 58
        },
        "provenanceScore": 83
      },
      "connect": {
        "http": "curl -X POST \"https://api.hibob.com/v1/people/search\" \\\n  -u \"$BOB_SERVICE_USER_ID:$BOB_SERVICE_USER_TOKEN\" -H \"Content-Type: application/json\" \\\n  -d '{\"fields\":[\"root.id\",\"root.email\",\"work.department\"]}'"
      },
      "letme": {
        "capability": "https://letme.dev/hr.employees",
        "tool": "https://letme.dev/hibob"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "Hi Bob Ltd.",
        "domain": "hibob.com",
        "domainRegistered": "2010-02-25",
        "endpointOnVendorDomain": true,
        "terms": "https://apidocs.hibob.com/docs/api-terms-of-use",
        "privacy": "https://www.hibob.com/privacy/privacy-policy",
        "statusPage": "https://status.hibob.io",
        "changelog": "https://apidocs.hibob.com/changelog",
        "securityTxt": "unknown",
        "checked": "2026-10-07",
        "notes": [
          "The API Terms of Use name Hi Bob Ltd. and its subsidiaries. The privacy policy (updated 16 February 2026) names Hi Bob (UK) Limited, 5 New Street Square, London EC4A 3TW, and says it does not cover people who use Bob at a customer's direction.",
          "The customer subscription terms (revised January 2026) list contracting entities by region, among them Hi Bob, Inc., Hi Bob Ltd., Hi Bob (UK) Limited and Hi Bob (NL) B.V.",
          "The API answers at https://api.hibob.com/v1 and the sandbox at https://api.sandbox.hibob.com/v1. OAuth tokens are exchanged at https://auth.app.hibob.com/oauth2/v1/apps/token. The status page is on a separate domain, status.hibob.io.",
          "www.hibob.com/.well-known/security.txt returned a Cloudflare block page (403) to both of our fetchers, so its presence is unknown.",
          "RDAP for hibob.com gives a registration date of 2010-02-25.",
          "The data processing addendum page (updated September 2026) links to a pre-signed DocuSign document and does not show the terms."
        ],
        "score": 83
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/hibob.json",
      "live": {
        "slug": "hibob",
        "probe": {
          "target": "https://api.hibob.com/v1",
          "method": "get",
          "lastAt": "2026-10-08T18:20:31.540356072Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 122,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 106,
          "p95ms24h": 157,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.hibob.io",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T18:22:03.850656904Z"
        },
        "securityTxt": {
          "url": "https://hibob.com/.well-known/security.txt",
          "state": "unknown",
          "checkedAt": "2026-10-08T15:39:05.839381908Z"
        },
        "pages": [
          {
            "url": "https://apidocs.hibob.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:14.469649765Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "981f915fbe41"
          },
          {
            "url": "https://apidocs.hibob.com/docs/api-terms-of-use",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:16.937981436Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d6b463c8c703"
          }
        ],
        "updatedAt": "2026-10-08T18:22:03.850656904Z"
      }
    },
    "answer": "Rippling scores 60.8 (C) on agent readiness against HiBob's 57 (C), and leads in 4 of 7 scored categories. HiBob leads on reliability, schema \u0026 documentation and transparency \u0026 trust.",
    "b": {
      "slug": "rippling",
      "name": "Rippling",
      "vendor": "People Center, Inc. dba Rippling",
      "vendorUrl": "https://www.rippling.com",
      "kind": "http-api",
      "category": "hr",
      "summary": "Rippling is a workforce platform for HR, payroll, IT and spend. Its REST Platform API v2 reads and writes worker, time off and organisation data with scoped Bearer tokens. A first-party MCP server runs as the signed-in employee.",
      "url": "https://www.anchorterminal.com/tools/rippling",
      "markdownUrl": "https://www.anchorterminal.com/tools/rippling.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/rippling.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/rippling.json",
      "license": "Proprietary service under Rippling's customer terms and Developer Terms of Use. The JavaScript SDK on npm is Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://rest.ripplingapis.com",
      "packages": [
        {
          "registry": "npm",
          "name": "@rippling/rippling-sdk"
        }
      ],
      "auth": "mixed",
      "authNotes": "A Rippling customer creates API tokens in Tools \u003e Developer \u003e API Tokens and sends them as `Authorization: Bearer` to https://rest.ripplingapis.com. A token's access is the overlap of its chosen scopes (162 listed, most split into read and read-write) and its owner's permission profile. It is shown once, can't change owner, and is revoked when the owner is terminated or after 30 days unused. App Shop partners must use OAuth 2.0 (authorisation code with refresh, one token per customer company) and get a partner account only after applying and being approved. The Rippling MCP signs in as the employee, after an admin assigns tools in MCP Gateway.",
      "pricing": "paid",
      "pricingNotes": "No public prices. rippling.com/pricing says most products are billed per employee per month and asks for a quote, with no free tier or trial found. Reference pages name the package an endpoint needs, such as API Tier 1, with no price shown. Partners pay nothing to use the API or list in the App Shop, but must apply, and their customers need the Identity \u0026 Access Management package. Approved partners get a test company, and the API can create sandboxes. Rippling MCP tool calls need a Rippling AI trial or subscription (checked 2026-10-07).",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in llms.txt, the REST API essentials pages or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 3633,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://developer.rippling.com/documentation/rest-api",
      "llmsTxt": "https://developer.rippling.com/llms.txt",
      "capabilities": [
        "hr.employees",
        "hr.time-off",
        "hr.org",
        "hr.onboarding",
        "hr.documents",
        "recruiting.candidates"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "api-key",
        "oauth",
        "mcp",
        "llms-txt",
        "typescript",
        "webhooks",
        "sales-led",
        "status-page",
        "soc2",
        "iso27001"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.8,
        "grade": "C",
        "agentReady": false,
        "rank": 341,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 74,
          "payments": 5,
          "reliability": 62,
          "schema": 73,
          "security": 90,
          "transparency": 51
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-07"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-05-21 and 2026-06-17. The changelog labels 14 changes breaking since October 2025, among them `draft_hire_id` removed from POST /draft-hires/ responses on 21 May 2026 and `candidate_id` made required on GET /candidate-applications/ on 17 June 2026, while the reference still shows a single version, 2024-08-01. The versioning page says a breaking change requires a version update. Each change is documented on the day, so the smallest deduction applies (https://developer.rippling.com/documentation/rest-api/essentials/changelog)."
        ],
        "verdict": "API tokens carry any of 162 scopes and can never see more than their owner, and hires and worker changes land as drafts for a person to review. There is no public price, trial or self-serve signup, and status.rippling.com shows five incidents marked critical between 16 July and 29 September 2026.",
        "bestFor": "An agent working for a company already on Rippling that needs scoped reads of people, organisation and time off data, and writes that wait for human review.",
        "strengths": [
          "API tokens are limited to chosen scopes (162 listed) and to the owner's permission profile, and are revoked after 30 days unused",
          "Hires and worker changes are created as drafts for review in Rippling, and leave requests follow the normal approval flow",
          "Dated changelog with 141 entries since 6 August 2025, 46 of them between 9 July and 28 September 2026, each labelled breaking or not",
          "llms.txt with integration guidance for agents, cursor pagination, filter, expand and order_by on list endpoints",
          "SOC 1 and SOC 2 Type II, ISO 27001, ISO 27018, ISO 42001 and CSA STAR Level 2 listed, with a paid vulnerability reporting programme"
        ],
        "weaknesses": [
          "No public price, free tier or trial. rippling.com/pricing is a quote form, and endpoints name a paid package such as API Tier 1",
          "Five incidents marked critical and three marked major on status.rippling.com between 16 July and 29 September 2026",
          "The changelog labels 14 changes breaking since October 2025 while the reference still shows one version, 2024-08-01",
          "No downloadable OpenAPI file found, and the documentation site renders only with JavaScript",
          "One official SDK, JavaScript at 0.2.0-alpha.106, and the documented @rippling/rippling-sdk-mcp package returned 404 on npm"
        ],
        "agentNotes": [
          "Call https://rest.ripplingapis.com with a Bearer token and pin `Rippling-Api-Version`. Use V1 at api.rippling.com only for resources that exist nowhere else",
          "Treat a null field as possibly hidden. Check `__meta.redacted_fields`, the token's scopes and whether `expand` was sent",
          "Follow `next_link` until it is null. The default page is 50 records and a `limit` above 100 returns 400",
          "Stay under 300 requests per IP in any 10 seconds. Going over rejects every request for the next 10 seconds",
          "Send an `Idempotency-Key` on POST /hires/ and POST /draft-transitions/, then poll the request until it reaches a final status"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.8
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 74,
          "payments": 5,
          "reliability": 62,
          "schema": 73,
          "security": 90,
          "transparency": 33
        },
        "provenanceScore": 69
      },
      "connect": {
        "install": "npm install @rippling/rippling-sdk",
        "http": "curl -X GET 'https://rest.ripplingapis.com/companies/' \\\n  -H 'Accept: application/json' \\\n  -H 'Authorization: Bearer YOUR_API_TOKEN'"
      },
      "letme": {
        "capability": "https://letme.dev/hr.employees",
        "tool": "https://letme.dev/rippling"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "People Center, Inc. dba Rippling",
        "domain": "rippling.com",
        "domainRegistered": "2002-02-25",
        "endpointOnVendorDomain": false,
        "terms": "https://app.rippling.com/legal",
        "privacy": "https://app.rippling.com/legal/privacy",
        "statusPage": "https://status.rippling.com",
        "changelog": "https://developer.rippling.com/documentation/rest-api/essentials/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The Vulnerability Reporting Terms and Conditions, last updated 21 August 2024, name People Center, Inc. dba Rippling and its affiliates.",
          "The v2 API answers at rest.ripplingapis.com, a separate domain from rippling.com that the vendor's llms.txt and quickstart name. V1 and the OAuth token exchange use api.rippling.com and app.rippling.com.",
          "www.rippling.com/.well-known/security.txt returns 404. Reports go through the form at rippling.com/vulnerability-reporting or to security@rippling.com.",
          "The terms, privacy notice, DPA and Developer Terms of Use sit on app.rippling.com, which returned only a JavaScript application to our reader, so their text is unread.",
          "RDAP for rippling.com gives a registration date of 2002-02-25."
        ],
        "score": 69
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/rippling.json",
      "live": {
        "slug": "rippling",
        "probe": {
          "target": "https://rest.ripplingapis.com",
          "method": "get",
          "lastAt": "2026-10-08T18:20:39.176388921Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 260,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 301,
          "p95ms24h": 2545,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.rippling.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T18:22:18.3293084Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "@rippling/rippling-sdk",
            "version": "0.2.0-alpha.106",
            "seenAt": "2026-10-08T16:27:45.404049579Z"
          }
        ],
        "npmWeekly": 3633,
        "securityTxt": {
          "url": "https://rippling.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:49.166690021Z"
        },
        "pages": [
          {
            "url": "https://developer.rippling.com/documentation/rest-api/essentials/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:17.596835563Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e3b0c44298fc"
          },
          {
            "url": "https://app.rippling.com/legal/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:21.558708711Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8a3694d85aaa"
          },
          {
            "url": "https://app.rippling.com/legal",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:15:19.356857643Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "8a3694d85aaa"
          }
        ],
        "updatedAt": "2026-10-08T18:22:18.3293084Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Hi Bob Ltd.",
        "b": "People Center, Inc. dba Rippling",
        "name": "Vendor"
      },
      {
        "a": "https://api.hibob.com/v1",
        "b": "https://rest.ripplingapis.com",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under HiBob's customer subscription terms and API Terms of Use",
        "b": "Proprietary service under Rippling's customer terms and Developer Terms of Use. The JavaScript SDK on npm is Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-07",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "no date given",
        "b": "couldn't be read",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "couldn't be read",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "couldn't be read",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "none",
        "b": "3.6k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Rippling scores 60.8 (C) on agent readiness against HiBob's 57 (C), and leads in 4 of 7 scored categories. HiBob leads on reliability, schema \u0026 documentation and transparency \u0026 trust.",
        "question": "Which is better for AI agents, HiBob or Rippling?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do HiBob and Rippling need an API key?"
      },
      {
        "answer": "Yes. HiBob has a hosted endpoint at https://api.hibob.com/v1 and Rippling at https://rest.ripplingapis.com.",
        "question": "Can an agent call HiBob and Rippling without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 67 against 62",
          "Schema \u0026 documentation, 78 against 73",
          "Transparency \u0026 trust, 71 against 51"
        ],
        "also": [
          "No incidents deducted, where Rippling loses 3 points for them"
        ],
        "goodFor": "An agent working inside a company that already runs Bob and needs field-level control over employee data, time off requests, documents and tasks.",
        "slug": "hibob",
        "watchFor": "No public price, free tier or trial. The sandbox is a purchased module"
      },
      {
        "aheadOn": [
          "Agent ergonomics, 75 against 47",
          "Security \u0026 auth, 90 against 68",
          "Payments \u0026 pricing, 5 against 0",
          "Maintenance \u0026 community, 74 against 59"
        ],
        "also": null,
        "goodFor": "An agent working for a company already on Rippling that needs scoped reads of people, organisation and time off data, and writes that wait for human review.",
        "slug": "rippling",
        "watchFor": "No public price, free tier or trial. rippling.com/pricing is a quote form, and endpoints name a paid package such as API Tier 1"
      }
    ],
    "job": {
      "capability": "hr.employees",
      "name": "Hr employees"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/bamboohr-vs-hibob.json",
        "title": "BambooHR vs HiBob",
        "url": "https://www.anchorterminal.com/compare/bamboohr-vs-hibob"
      },
      {
        "json": "https://www.anchorterminal.com/compare/bamboohr-vs-rippling.json",
        "title": "BambooHR vs Rippling",
        "url": "https://www.anchorterminal.com/compare/bamboohr-vs-rippling"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deel-vs-hibob.json",
        "title": "Deel vs HiBob",
        "url": "https://www.anchorterminal.com/compare/deel-vs-hibob"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deel-vs-rippling.json",
        "title": "Deel vs Rippling",
        "url": "https://www.anchorterminal.com/compare/deel-vs-rippling"
      }
    ],
    "scores": [
      {
        "by": 5,
        "edge": "hibob",
        "hibob": 67,
        "key": "reliability",
        "name": "Reliability",
        "rippling": 62,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "edge": "hibob",
        "hibob": 78,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "rippling": 73,
        "weight": 13
      },
      {
        "by": 28,
        "edge": "rippling",
        "hibob": 47,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "rippling": 75,
        "weight": 13
      },
      {
        "by": 22,
        "edge": "rippling",
        "hibob": 68,
        "key": "security",
        "name": "Security \u0026 auth",
        "rippling": 90,
        "weight": 14
      },
      {
        "by": 5,
        "edge": "rippling",
        "hibob": 0,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "rippling": 5,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 15,
        "edge": "rippling",
        "hibob": 59,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "rippling": 74,
        "weight": 7
      },
      {
        "by": 20,
        "edge": "hibob",
        "hibob": 71,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "rippling": 51,
        "weight": 7
      }
    ],
    "summary": "Rippling scores 60.8 (C) on agent readiness against HiBob's 57 (C), and leads in 4 of 7 scored categories. HiBob leads on reliability, schema \u0026 documentation and transparency \u0026 trust. Both do hr employees.",
    "verdicts": {
      "hibob": "Service users start with no permissions and gain view or edit rights per field, and the docs are served as Markdown with an OpenAPI definition on each endpoint page. There is no public price, trial or free sandbox, so an agent needs a paying customer's admin to issue credentials. No idempotency keys or official SDKs were found.",
      "rippling": "API tokens carry any of 162 scopes and can never see more than their owner, and hires and worker changes land as drafts for a person to review. There is no public price, trial or self-serve signup, and status.rippling.com shows five incidents marked critical between 16 July and 29 September 2026."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/hibob-vs-rippling",
    "json": "https://www.anchorterminal.com/compare/hibob-vs-rippling.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/hibob-vs-rippling.md",
    "slim": "https://www.anchorterminal.com/compare/hibob-vs-rippling.min.md"
  },
  "markdown": "Rippling scores 60.8 (C) on agent readiness against HiBob's 57 (C), and leads in 4 of 7 scored categories. HiBob leads on reliability, schema \u0026 documentation and transparency \u0026 trust. Both do hr employees.\n\n- HiBob: grade C, 57/100, rank #429 of 629. Markdown https://www.anchorterminal.com/tools/hibob.md · JSON https://www.anchorterminal.com/api/v1/tools/hibob.json\n- Rippling: grade C, 60.8/100, rank #341 of 629. Markdown https://www.anchorterminal.com/tools/rippling.md · JSON https://www.anchorterminal.com/api/v1/tools/rippling.json\n\n## Which one, for what\n\n### HiBob (C)\n\nGood for: An agent working inside a company that already runs Bob and needs field-level control over employee data, time off requests, documents and tasks.\n\nAhead on:\n- Reliability, 67 against 62\n- Schema \u0026 documentation, 78 against 73\n- Transparency \u0026 trust, 71 against 51\n\nAlso in its favour:\n- No incidents deducted, where Rippling loses 3 points for them\n\nWatch for: No public price, free tier or trial. The sandbox is a purchased module\n\n### Rippling (C)\n\nGood for: An agent working for a company already on Rippling that needs scoped reads of people, organisation and time off data, and writes that wait for human review.\n\nAhead on:\n- Agent ergonomics, 75 against 47\n- Security \u0026 auth, 90 against 68\n- Payments \u0026 pricing, 5 against 0\n- Maintenance \u0026 community, 74 against 59\n\nWatch for: No public price, free tier or trial. rippling.com/pricing is a quote form, and endpoints name a paid package such as API Tier 1\n\n\n## Score by category\n\n| Category | Weight | HiBob | Rippling | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 67 | 62 | HiBob +5 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 78 | 73 | HiBob +5 |\n| Agent ergonomics | 13% (16.2 this run) | 47 | 75 | Rippling +28 |\n| Security \u0026 auth | 14% (17.5 this run) | 68 | 90 | Rippling +22 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 0 | 5 | Rippling +5 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 59 | 74 | Rippling +15 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 71 | 51 | HiBob +20 |\n| Negative events | ≤15 | 0 | -3 | |\n| **Total** | | **57 · C** | **60.8 · C** | |\n\n## Facts side by side\n\n| Fact | HiBob | Rippling |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Hi Bob Ltd. | People Center, Inc. dba Rippling |\n| Hosted endpoint | `https://api.hibob.com/v1` | `https://rest.ripplingapis.com` |\n| Transports | HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Paid |\n| x402 | no | no |\n| Licence | Proprietary service under HiBob's customer subscription terms and API Terms of Use | Proprietary service under Rippling's customer terms and Developer Terms of Use. The JavaScript SDK on npm is Apache-2.0 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-10-07 | 2026-10-07 |\n| Terms last updated | no date given | couldn't be read |\n| Privacy policy last updated | no date given | couldn't be read |\n| Customer content may train models | not found in the text | couldn't be read |\n| Terms restrict automated access | yes | couldn't be read |\n| Terms restrict benchmarking | not found in the text | couldn't be read |\n| Terms or service can change without notice | yes | couldn't be read |\n| Arbitration or class-action waiver | not found in the text | couldn't be read |\n| Popularity | none | 3.6k npm/wk |\n\n## Verdicts\n\n**HiBob.** Service users start with no permissions and gain view or edit rights per field, and the docs are served as Markdown with an OpenAPI definition on each endpoint page. There is no public price, trial or free sandbox, so an agent needs a paying customer's admin to issue credentials. No idempotency keys or official SDKs were found.\n\n**Rippling.** API tokens carry any of 162 scopes and can never see more than their owner, and hires and worker changes land as drafts for a person to review. There is no public price, trial or self-serve signup, and status.rippling.com shows five incidents marked critical between 16 July and 29 September 2026.\n\n## Before you call either\n\n### HiBob\n\n1. Send `Authorization: Basic base64(SERVICE-USER-ID:TOKEN)` to https://api.hibob.com/v1. Ask the Bob admin to put the service user in a permission group first, because it starts with none\n2. Request only the fields needed in `fields` on POST /people/search (maximum 400). The call returns all matching employees at once, so batch by `root.id` in large companies\n3. Compare returned fields with requested ones. Missing permission or a wrong field ID yields 200 with the field omitted\n4. Stop on 401 or 403. More than 50 in 10 seconds blocks the IP for 5 minutes\n5. Back off on 429 using Retry-After. Writes such as update, create and terminate employee allow 10 calls a minute, and no idempotency key exists, so check state before retrying a write\n\n### Rippling\n\n1. Call https://rest.ripplingapis.com with a Bearer token and pin `Rippling-Api-Version`. Use V1 at api.rippling.com only for resources that exist nowhere else\n2. Treat a null field as possibly hidden. Check `__meta.redacted_fields`, the token's scopes and whether `expand` was sent\n3. Follow `next_link` until it is null. The default page is 50 records and a `limit` above 100 returns 400\n4. Stay under 300 requests per IP in any 10 seconds. Going over rejects every request for the next 10 seconds\n5. Send an `Idempotency-Key` on POST /hires/ and POST /draft-transitions/, then poll the request until it reaches a final status\n\n## Questions\n\n### Which is better for AI agents, HiBob or Rippling?\n\nRippling scores 60.8 (C) on agent readiness against HiBob's 57 (C), and leads in 4 of 7 scored categories. HiBob leads on reliability, schema \u0026 documentation and transparency \u0026 trust.\n\n### Do HiBob and Rippling need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call HiBob and Rippling without installing anything?\n\nYes. HiBob has a hosted endpoint at https://api.hibob.com/v1 and Rippling at https://rest.ripplingapis.com.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/hibob-vs-rippling.json, and with the fewest tokens: https://www.anchorterminal.com/compare/hibob-vs-rippling.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"hibob\", \"b\": \"rippling\"}`. From a terminal: `anchor compare hibob rippling`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/hibob.json and https://www.anchorterminal.com/api/v1/tools/rippling.json\n\n## Other comparisons with HiBob or Rippling\n\n- [BambooHR vs HiBob](https://www.anchorterminal.com/compare/bamboohr-vs-hibob.md)\n- [BambooHR vs Rippling](https://www.anchorterminal.com/compare/bamboohr-vs-rippling.md)\n- [Deel vs HiBob](https://www.anchorterminal.com/compare/deel-vs-hibob.md)\n- [Deel vs Rippling](https://www.anchorterminal.com/compare/deel-vs-rippling.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "HiBob vs Rippling",
        "url": ""
      }
    ],
    "description": "Rippling scores 60.8 (C) on agent readiness against HiBob's 57 (C), and leads in 4 of 7 scored categories. HiBob leads on reliability, schema \u0026 documentation and transparency \u0026 trust. Both do hr employees. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "HiBob C 57",
      "Rippling C 60.8",
      "scores"
    ],
    "h1": "HiBob vs Rippling",
    "image": "https://www.anchorterminal.com/assets/og/compare-hibob-vs-rippling.png",
    "path": "/compare/hibob-vs-rippling",
    "published": "2026-10-01",
    "section": "tools",
    "title": "HiBob vs Rippling for AI agents, C 57 vs C 60.8 | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/hibob-vs-rippling"
  },
  "tokens": {
    "markdown": 1950,
    "slim": 730
  },
  "version": 1
}
