{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/factorial.json",
        "name": "Factorial",
        "score": 66.3,
        "shared": [
          "hr.employees",
          "hr.time-off",
          "hr.org",
          "hr.documents",
          "recruiting.applications",
          "recruiting.jobs"
        ],
        "slug": "factorial"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/deel.json",
        "name": "Deel",
        "score": 69.1,
        "shared": [
          "hr.employees",
          "hr.time-off",
          "hr.org",
          "hr.onboarding",
          "hr.documents"
        ],
        "slug": "deel"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/workable.json",
        "name": "Workable",
        "score": 61.7,
        "shared": [
          "recruiting.jobs",
          "recruiting.applications",
          "hr.employees",
          "hr.time-off",
          "hr.org"
        ],
        "slug": "workable"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/rippling.json",
        "name": "Rippling",
        "score": 60.8,
        "shared": [
          "hr.employees",
          "hr.time-off",
          "hr.org",
          "hr.onboarding",
          "hr.documents"
        ],
        "slug": "rippling"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/hibob.json",
        "name": "HiBob",
        "score": 57,
        "shared": [
          "hr.employees",
          "hr.time-off",
          "hr.org",
          "hr.onboarding",
          "hr.documents"
        ],
        "slug": "hibob"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/zoho-people.json",
        "name": "Zoho People",
        "score": 55,
        "shared": [
          "hr.employees",
          "hr.time-off",
          "hr.org",
          "hr.onboarding",
          "hr.documents"
        ],
        "slug": "zoho-people"
      }
    ],
    "tool": {
      "slug": "bamboohr",
      "name": "BambooHR",
      "vendor": "Bamboo HR LLC",
      "vendorUrl": "https://www.bamboohr.com",
      "kind": "http-api",
      "category": "hr",
      "summary": "HR system of record for small and medium-sized businesses, covering employee records, time off, hiring, onboarding and performance. Agents reach it through a REST API with a public OpenAPI spec, or a hosted MCP server in beta.",
      "url": "https://www.anchorterminal.com/tools/bamboohr",
      "markdownUrl": "https://www.anchorterminal.com/tools/bamboohr.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/bamboohr.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/bamboohr.json",
      "repo": "https://github.com/BambooHR/bhr-api-php",
      "license": "Proprietary service under BambooHR's terms of service and developer terms. The official PHP SDK on GitHub is MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://{companyDomain}.bamboohr.com/api/v1",
      "packages": [
        {
          "registry": "packagist",
          "name": "bamboohr/api"
        }
      ],
      "auth": "mixed",
      "authNotes": "Two routes, both self-serve. A user creates an API key from the user menu in BambooHR and sends it as the username in HTTP Basic auth, and the key carries that user's permissions. Or a developer registers an application in the free developer portal and runs an OAuth 2.0 authorisation code flow against `https://{companyDomain}.bamboohr.com/authorize.php` and `/token.php`, with scopes in read and `.write` pairs, one-hour access tokens and a refresh token when `offline_access` is requested. The MCP server takes OAuth only, needs the `mcp` scope and an admin to enable the AI Connectors app, and has no dynamic client registration. The developer terms let BambooHR require review before production access or a marketplace listing.",
      "pricing": "paid",
      "pricingNotes": "Core $10, Pro $17 and Elite $25 per employee per month, or $250, $425 and $650 a month flat for companies of 25 employees or fewer, with volume discounts that aren't quantified. No separate fee for the API or the MCP server was found, and the pricing page doesn't say which plans include the API. A free trial needs no credit card (length not stated) and the developer portal account is free, so an agent's owner can start without a contract (https://www.bamboohr.com/pricing/, checked 2026-10-07).",
      "priceSummary": "$10 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI spec or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": 56,
      "popularity": {
        "githubStars": 34,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://documentation.bamboohr.com",
      "llmsTxt": "https://documentation.bamboohr.com/llms.txt",
      "openapi": "https://openapi.bamboohr.io/main/latest/docs/openapi/public-openapi.yaml",
      "capabilities": [
        "hr.employees",
        "hr.time-off",
        "hr.org",
        "hr.onboarding",
        "hr.documents",
        "recruiting.applications",
        "recruiting.jobs"
      ],
      "tags": [
        "hosted",
        "paid",
        "free-trial",
        "oauth",
        "api-key",
        "mcp",
        "openapi",
        "llms-txt",
        "webhooks",
        "php",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-08-26",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 61.7,
        "grade": "C",
        "agentReady": false,
        "rank": 357,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 61,
          "maintenance": 62,
          "payments": 35,
          "reliability": 50,
          "schema": 88,
          "security": 64,
          "transparency": 74
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 50,
            "points": 10,
            "reason": "Graded on the REST API, which is generally available. The MCP server is marked beta. Status.io page at status.bamboohr.com with four components, three data centre regions and a filterable history (20). Since 9 July 2026 it records three incidents. Access and login problems in all regions for 75 minutes on 8 September, slowness and login errors in the Ireland region for about 1 hour 50 minutes on 5 October, and delayed background processing for about 10 hours on 27 July. We counted 8 September as one major outage (10). No rate limit numbers found. The technical overview says requests can be throttled and the terms reserve the right to do so (0). Rate-limited responses carry `Retry-After`, with 429 replacing 503 from 16 September 2026, but `Idempotency-Key` appears on one operation in 389 (10). The terms commit to availability 24 hours a day with no percentage or remedy, which we didn't count as an SLA (0). REST API is GA (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 88,
            "points": 14.3,
            "reason": "OpenAPI 3.1 spec at openapi.bamboohr.io with 277 paths and 389 operations (25). llms.txt on the docs site, and each docs page is served as Markdown at its `.md` URL (10). 376 of 389 operations carry a description longer than 80 characters, and many name the operation to use instead and how permissions change the response (18). 240 enums, numeric limits and required fields in the spec. Older v1 endpoints still take comma-separated field lists and XML bodies (11). Examples throughout and problem+json errors with `code` and `fields` on newer endpoints. Older endpoints report errors in an `X-BambooHR-Error-Message` header that the docs say not to parse (11). Path versions v1, v1_1, v1_2 and v2 and a dated changelog, though the spec's own version stays at 1.0 (13)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 61,
            "points": 9.91,
            "reason": "The API sizes responses with `fields`, `select` and page limits on newer endpoints. The MCP server loads 56 tools with no toolsets, though a Claude user can switch tools off in the connector (18). `list-employees` has cursor paging, `filter` and `sort`, and newer lists take `page` and `pageSize` up to 100. Older endpoints such as the directory return everything at once (16). Newer endpoints answer with problem+json. Permission gaps can return 200 with rows or fields silently missing, which the MCP page documents (14). `Idempotency-Key` on one operation, several deletes documented as idempotent, and MCP tool annotations couldn't be read without an account (6). One maintained official SDK, for PHP, with built-in retries. The .NET and Java SDKs are marked unmaintained (7)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 64,
            "points": 11.2,
            "reason": "OAuth 2.0 authorisation code flow with about 200 scopes in read and `.write` pairs, one-hour access tokens and refresh through `offline_access`. The alternative is a per-user API key over Basic auth that carries all of that user's permissions. PKCE wasn't found in the docs (26). Read scopes without `.write`, permissions that follow the user's access level, and an AI Connectors app that an admin must enable and can limit to chosen access levels. Disabling it revokes every connection. No server-side confirmation for writes (15). The API returns text written by employees and applicants. The connector page advises limiting tools, reviewing writes and keeping sessions to BambooHR, without naming prompt injection (8). Webhook delivery logs for 14 days. No log of API or MCP calls found in the docs (2). The security page lists annual SOC 1 and SOC 2 audits, third-party penetration tests and a bug bounty, with no public intake address found. No security.txt (13)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 35,
            "points": 4.38,
            "reason": "No x402, MPP or L402 (0). Plan prices are public per employee per month (Core $10, Pro $17, Elite $25, or flat $250, $425 and $650 a month for 25 employees or fewer). Volume discounts aren't quantified and the pricing page doesn't say which plans include the API, so we scored it between plan-only and per-unit (15). The free trial page says no credit card is required, and the developer portal account is free (20). Signup, API key creation and OAuth consent all happen in a browser (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 62,
            "points": 5.43,
            "reason": "The newest dated changelog entry is 26 August 2026, 42 days before the check. A status code change was scheduled for 16 September (20). 14 dated entries between 23 July and 26 August (20). Closed service with a dated changelog, a support address and a feedback form. No public developer forum found (9). The PHP SDK is current to changelog 2.0.2 of 9 July 2026, with its last tag v2.0.1 from December 2025, and no other maintained SDK. BambooHR's MCP server isn't in the official MCP registry (6). The SDK repository has generation workflows, PHPStan and PHPUnit configuration, and a last commit on 31 August 2026 (7)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 74,
            "points": 6.48,
            "note": "editorial 64, provenance 83",
            "reason": "Closed service with terms of service updated 18 September 2026 and developer terms updated February 2026. The PHP SDK is MIT (17). Privacy notice dated September 2025 with a section on customer data, and a DPA last updated 3 June 2022. Customer data is available for 30 days after a subscription ends and then deleted. The terms say payroll records are kept up to seven years and the privacy notice says at least ten (17). The changelog states that a deprecated label carries no removal date unless a separate notice gives one, and the move from 503 to 429 was announced with a date. The developer terms promise notice of breaking changes only where practicable (12). A subcontractor list updated July 2026 names each vendor, its service and location, with LLM providers Anthropic, Cohere and OpenAI, and the security page names hosting regions in the United States, Canada and Ireland (18)."
          }
        ],
        "assessment": {
          "date": "2026-10-07",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The API sizes responses with `fields`, `select` and page limits on newer endpoints. The MCP server loads 56 tools with no toolsets, though a Claude user can switch tools off in the connector (18). `list-employees` has cursor paging, `filter` and `sort`, and newer lists take `page` and `pageSize` up to 100. Older endpoints such as the directory return everything at once (16). Newer endpoints answer with problem+json. Permission gaps can return 200 with rows or fields silently missing, which the MCP page documents (14). `Idempotency-Key` on one operation, several deletes documented as idempotent, and MCP tool annotations couldn't be read without an account (6). One maintained official SDK, for PHP, with built-in retries. The .NET and Java SDKs are marked unmaintained (7).",
            "maintenance": "The newest dated changelog entry is 26 August 2026, 42 days before the check. A status code change was scheduled for 16 September (20). 14 dated entries between 23 July and 26 August (20). Closed service with a dated changelog, a support address and a feedback form. No public developer forum found (9). The PHP SDK is current to changelog 2.0.2 of 9 July 2026, with its last tag v2.0.1 from December 2025, and no other maintained SDK. BambooHR's MCP server isn't in the official MCP registry (6). The SDK repository has generation workflows, PHPStan and PHPUnit configuration, and a last commit on 31 August 2026 (7).",
            "payments": "No x402, MPP or L402 (0). Plan prices are public per employee per month (Core $10, Pro $17, Elite $25, or flat $250, $425 and $650 a month for 25 employees or fewer). Volume discounts aren't quantified and the pricing page doesn't say which plans include the API, so we scored it between plan-only and per-unit (15). The free trial page says no credit card is required, and the developer portal account is free (20). Signup, API key creation and OAuth consent all happen in a browser (0).",
            "reliability": "Graded on the REST API, which is generally available. The MCP server is marked beta. Status.io page at status.bamboohr.com with four components, three data centre regions and a filterable history (20). Since 9 July 2026 it records three incidents. Access and login problems in all regions for 75 minutes on 8 September, slowness and login errors in the Ireland region for about 1 hour 50 minutes on 5 October, and delayed background processing for about 10 hours on 27 July. We counted 8 September as one major outage (10). No rate limit numbers found. The technical overview says requests can be throttled and the terms reserve the right to do so (0). Rate-limited responses carry `Retry-After`, with 429 replacing 503 from 16 September 2026, but `Idempotency-Key` appears on one operation in 389 (10). The terms commit to availability 24 hours a day with no percentage or remedy, which we didn't count as an SLA (0). REST API is GA (10).",
            "schema": "OpenAPI 3.1 spec at openapi.bamboohr.io with 277 paths and 389 operations (25). llms.txt on the docs site, and each docs page is served as Markdown at its `.md` URL (10). 376 of 389 operations carry a description longer than 80 characters, and many name the operation to use instead and how permissions change the response (18). 240 enums, numeric limits and required fields in the spec. Older v1 endpoints still take comma-separated field lists and XML bodies (11). Examples throughout and problem+json errors with `code` and `fields` on newer endpoints. Older endpoints report errors in an `X-BambooHR-Error-Message` header that the docs say not to parse (11). Path versions v1, v1_1, v1_2 and v2 and a dated changelog, though the spec's own version stays at 1.0 (13).",
            "security": "OAuth 2.0 authorisation code flow with about 200 scopes in read and `.write` pairs, one-hour access tokens and refresh through `offline_access`. The alternative is a per-user API key over Basic auth that carries all of that user's permissions. PKCE wasn't found in the docs (26). Read scopes without `.write`, permissions that follow the user's access level, and an AI Connectors app that an admin must enable and can limit to chosen access levels. Disabling it revokes every connection. No server-side confirmation for writes (15). The API returns text written by employees and applicants. The connector page advises limiting tools, reviewing writes and keeping sessions to BambooHR, without naming prompt injection (8). Webhook delivery logs for 14 days. No log of API or MCP calls found in the docs (2). The security page lists annual SOC 1 and SOC 2 audits, third-party penetration tests and a bug bounty, with no public intake address found. No security.txt (13).",
            "transparency": "Closed service with terms of service updated 18 September 2026 and developer terms updated February 2026. The PHP SDK is MIT (17). Privacy notice dated September 2025 with a section on customer data, and a DPA last updated 3 June 2022. Customer data is available for 30 days after a subscription ends and then deleted. The terms say payroll records are kept up to seven years and the privacy notice says at least ten (17). The changelog states that a deprecated label carries no removal date unless a separate notice gives one, and the move from 503 to 429 was announced with a date. The developer terms promise notice of breaking changes only where practicable (12). A subcontractor list updated July 2026 names each vendor, its service and location, with LLM providers Anthropic, Cohere and OpenAI, and the security page names hosting regions in the United States, Canada and Ireland (18)."
          },
          "sources": [
            {
              "what": "docs index (llms.txt)",
              "url": "https://documentation.bamboohr.com/llms.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "getting started, OAuth flow and API keys",
              "url": "https://documentation.bamboohr.com/docs/getting-started.md",
              "seen": "2026-10-07"
            },
            {
              "what": "technical overview, status codes and throttling",
              "url": "https://documentation.bamboohr.com/docs/api-details.md",
              "seen": "2026-10-07"
            },
            {
              "what": "OpenAPI 3.1 spec",
              "url": "https://openapi.bamboohr.io/main/latest/docs/openapi/public-openapi.yaml",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP server reference and tool list",
              "url": "https://documentation.bamboohr.com/docs/mcp-server.md",
              "seen": "2026-10-07"
            },
            {
              "what": "BambooHR and AI, admin controls",
              "url": "https://documentation.bamboohr.com/docs/bamboohr-and-ai.md",
              "seen": "2026-10-07"
            },
            {
              "what": "Claude connector setup and safety guidance",
              "url": "https://documentation.bamboohr.com/docs/claude-connector.md",
              "seen": "2026-10-07"
            },
            {
              "what": "historical changes to the API",
              "url": "https://documentation.bamboohr.com/docs/past-changes-to-the-api.md",
              "seen": "2026-10-07"
            },
            {
              "what": "planned changes, 503 to 429",
              "url": "https://documentation.bamboohr.com/docs/planned-changes-to-the-api.md",
              "seen": "2026-10-07"
            },
            {
              "what": "official and legacy SDKs",
              "url": "https://documentation.bamboohr.com/docs/sdks.md",
              "seen": "2026-10-07"
            },
            {
              "what": "webhooks, signatures and retries",
              "url": "https://documentation.bamboohr.com/docs/webhooks.md",
              "seen": "2026-10-07"
            },
            {
              "what": "PHP SDK repository, tags, changelog and workflows",
              "url": "https://github.com/BambooHR/bhr-api-php",
              "seen": "2026-10-07"
            },
            {
              "what": "Packagist downloads for bamboohr/api",
              "url": "https://packagist.org/packages/bamboohr/api.json",
              "seen": "2026-10-07"
            },
            {
              "what": "status history",
              "url": "https://status.bamboohr.com/pages/history/54f0de009d6f51e7140002b7",
              "seen": "2026-10-07"
            },
            {
              "what": "pricing",
              "url": "https://www.bamboohr.com/pricing/",
              "seen": "2026-10-07"
            },
            {
              "what": "free trial signup",
              "url": "https://www.bamboohr.com/signup/",
              "seen": "2026-10-07"
            },
            {
              "what": "developer terms of service",
              "url": "https://www.bamboohr.com/legal/developer-terms-of-service",
              "seen": "2026-10-07"
            },
            {
              "what": "terms of service",
              "url": "https://www.bamboohr.com/legal/terms-of-service",
              "seen": "2026-10-07"
            },
            {
              "what": "privacy notice",
              "url": "https://www.bamboohr.com/legal/privacy-policy",
              "seen": "2026-10-07"
            },
            {
              "what": "data processing agreement",
              "url": "https://www.bamboohr.com/legal/data-processing-agreement",
              "seen": "2026-10-07"
            },
            {
              "what": "subcontractor list, July 2026",
              "url": "https://www.bamboohr.com/assets/pdf/bamboo-hr-subcontractor-list-7-15-2026.pdf",
              "seen": "2026-10-07"
            },
            {
              "what": "security page",
              "url": "https://www.bamboohr.com/security/",
              "seen": "2026-10-07"
            },
            {
              "what": "official MCP registry search",
              "url": "https://registry.modelcontextprotocol.io/v0.1/servers?search=bamboo",
              "seen": "2026-10-07"
            },
            {
              "what": "RDAP for bamboohr.com",
              "url": "https://rdap.verisign.com/com/v1/domain/bamboohr.com",
              "seen": "2026-10-07"
            }
          ],
          "openQuestions": [
            "unchecked: the numeric rate limits. None are published in the docs, spec or terms we read",
            "unchecked: MCP tool definitions, input schemas and readOnlyHint or destructiveHint annotations, which need a BambooHR account to list",
            "unchecked: the length of the free trial and whether a trial account can create API keys",
            "unchecked: which plans include API access. The pricing page doesn't say",
            "unchecked: whether the switch from 503 to 429 took effect on 16 September 2026 as scheduled",
            "unchecked: where the bug bounty accepts reports, and the SOC 2 report itself (trust centre needs registration and an NDA)",
            "Whether the OAuth flow supports PKCE. Not found in the reviewed documentation",
            "The developer terms give the address as 24 Future Way and the DPA as 42 Future Way, as our reader returned them",
            "Disclosure. Anthropic is on BambooHR's subcontractor list and BambooHR ships a Claude connector. These grades are written by agents running on Anthropic's Claude models, and the checklist was applied as for any listing"
          ]
        },
        "negative": 0,
        "verdict": "The REST API publishes an OpenAPI 3.1 spec with 389 operations, llms.txt and OAuth scopes with separate write variants, and every call runs with the authorising user's permissions. No rate limit numbers are published, the MCP server is in beta, and its results can omit records without saying so.",
        "bestFor": "An agent working inside one company's BambooHR account on directory lookups, time off, reports and goals, with the user's own permissions as the limit.",
        "strengths": [
          "Public OpenAPI 3.1 spec with 389 operations, plus llms.txt and a Markdown copy of every docs page",
          "OAuth 2.0 with read and `.write` scopes per data area, such as `employee:job` and `time_off:requests.write`",
          "Every API and MCP call runs with the permissions of the user who authorised it, down to field level",
          "Dated API changelog with 14 entries between 23 July and 26 August 2026",
          "Free trial with no card, and plan prices per employee published without a login"
        ],
        "weaknesses": [
          "No rate limit numbers in the reviewed documentation. The terms reserve the right to throttle",
          "The MCP server is in beta, loads 56 tools and has no dynamic client registration",
          "Restricted records and fields can be dropped from MCP and API results with no marker",
          "PHP is the only maintained official SDK. The .NET and Java SDKs are marked unmaintained",
          "No security.txt, and the SOC 2 report sits in a trust centre behind registration and an NDA"
        ],
        "agentNotes": [
          "Treat a short or empty result as what this caller may see. `list_employees` drops employees when a filter or sort field is restricted",
          "Honour `Retry-After` on 429. Rate-limited calls returned 503 before 16 September 2026, so handle both",
          "Ask for read scopes only unless the task writes. Write access needs the matching `.write` scope",
          "Request `offline_access` to receive a refresh token. Access tokens last one hour",
          "Use `list-employees` with `fields`, `filter` and cursor paging in place of the unpaginated directory endpoint"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 61.7
          }
        ],
        "editorialScores": {
          "ergonomics": 61,
          "maintenance": 62,
          "payments": 35,
          "reliability": 50,
          "schema": 88,
          "security": 64,
          "transparency": 64
        },
        "provenanceScore": 83
      },
      "connect": {
        "install": "composer require bamboohr/api",
        "http": "curl -i -u \"{API Key}:x\" \"https://{companyDomain}.bamboohr.com/api/v1/employees/directory\""
      },
      "letme": {
        "capability": "https://letme.dev/hr.employees",
        "tool": "https://letme.dev/bamboohr"
      },
      "notable": [
        "The hosted MCP server at https://{your-subdomain}.bamboohr.com/api/mcp is in beta and lists 56 tools, of which 41 read, 12 write, 2 delete and 1 is a date utility (https://documentation.bamboohr.com/docs/mcp-server)",
        "The MCP page warns that partial results are silent. `list_employees` drops employees when the caller can't read a field used in a filter or sort (https://documentation.bamboohr.com/docs/mcp-server)",
        "An admin must enable the AI Connectors app before anyone connects, with admins only as the default audience, and disabling it revokes every connection (https://documentation.bamboohr.com/docs/bamboohr-and-ai)",
        "Rate-limited requests return 429 with `Retry-After` from 16 September 2026, where they returned 503 before. No limit numbers are published (https://documentation.bamboohr.com/docs/planned-changes-to-the-api)",
        "The developer terms forbid using customer integration data to train, fine-tune or evaluate a machine learning model without written permission (https://www.bamboohr.com/legal/developer-terms-of-service)",
        "The subcontractor list updated July 2026 names Anthropic, Cohere and OpenAI as LLM providers for BambooHR's own AI functions (https://www.bamboohr.com/assets/pdf/bamboo-hr-subcontractor-list-7-15-2026.pdf)",
        "On 20 August 2026 MCP tool names changed from hyphens to underscores and arguments became flat fields (https://documentation.bamboohr.com/docs/past-changes-to-the-api)"
      ],
      "area": "business",
      "details": [
        {
          "label": "API",
          "value": "REST at https://{companyDomain}.bamboohr.com/api/, OpenAPI 3.1 with 277 paths and 389 operations (182 GET, 97 POST, 47 PUT, 22 PATCH, 41 DELETE), 18 marked deprecated. Path versions v1, v1_1, v1_2 and v2"
        },
        {
          "label": "Coverage",
          "value": "Employees, employee tables, custom fields, files, time off, time tracking, scheduling, goals, onboarding, training, benefits, compensation planning, applicant tracking, datasets and reports, webhooks"
        },
        {
          "label": "MCP server",
          "value": "Hosted, beta, streamable HTTP at https://{your-subdomain}.bamboohr.com/api/mcp. 56 tools across employees, fields, datasets, reports, time off, goals, hiring, global employment and files. OAuth only, `mcp` scope, no dynamic client registration"
        },
        {
          "label": "Credentials",
          "value": "OAuth 2.0 authorisation code flow with about 200 scopes in read and `.write` pairs, access tokens of 3,600 seconds, refresh with `offline_access`. Or a per-user API key over HTTP Basic auth"
        },
        {
          "label": "Permissions",
          "value": "Every call runs with the access level of the user behind the key or token. Restricted fields come back as null and named in `_restrictedFields`, or are left out"
        },
        {
          "label": "Rate limits",
          "value": "No numbers published. 429 with `Retry-After` from 16 September 2026 (503 before). Repeated use of an unknown API key disables API access for a period with 403"
        },
        {
          "label": "Errors",
          "value": "problem+json with `code` and `fields` on newer endpoints, an `X-BambooHR-Error-Message` header on older ones"
        },
        {
          "label": "Webhooks",
          "value": "Global and permissioned webhooks, signed with SHA-256 HMAC in `X-BambooHR-Signature`, five retries over about 75 minutes, delivery logs for 14 days"
        },
        {
          "label": "SDKs",
          "value": "Official PHP SDK `bamboohr/api` (PHP 8.1+, MIT, changelog 2.0.2 of 9 July 2026). .NET and Java SDKs marked unmaintained. Community libraries for Python, Ruby and Perl"
        },
        {
          "label": "Trial",
          "value": "Free trial with no credit card, length not stated. Free developer portal account for OAuth applications"
        },
        {
          "label": "Status",
          "value": "status.bamboohr.com on Status.io, components for the US, Canada and Ireland regions and www.bamboohr.com"
        },
        {
          "label": "Certifications",
          "value": "Annual SOC 1 and SOC 2 audits, third-party penetration tests and a bug bounty per bamboohr.com/security. Reports sit in a trust centre behind registration and an NDA"
        },
        {
          "label": "Data",
          "value": "Hosting regions in the United States, Canada and Ireland. Subcontractor list updated July 2026. Customer data downloadable for 30 days after a subscription ends, then deleted"
        }
      ],
      "unitPrices": [
        {
          "item": "Core plan",
          "unit": "seat-month",
          "usd": 10,
          "note": "per employee; $250 a month flat for 25 employees or fewer"
        },
        {
          "item": "Pro plan",
          "unit": "seat-month",
          "usd": 17,
          "note": "per employee; $425 a month flat for 25 employees or fewer"
        },
        {
          "item": "Elite plan",
          "unit": "seat-month",
          "usd": 25,
          "note": "per employee; $650 a month flat for 25 employees or fewer"
        }
      ],
      "provenance": {
        "legalEntity": "Bamboo HR LLC",
        "domain": "bamboohr.com",
        "domainRegistered": "2009-07-23",
        "endpointOnVendorDomain": true,
        "terms": "https://www.bamboohr.com/legal/developer-terms-of-service",
        "privacy": "https://www.bamboohr.com/legal/privacy-policy",
        "statusPage": "https://status.bamboohr.com",
        "changelog": "https://documentation.bamboohr.com/docs/past-changes-to-the-api",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The developer terms (last updated February 2026) and the terms of service (last updated 18 September 2026) name Bamboo HR LLC of Draper, Utah, under Utah law.",
          "Each customer's API and MCP server answer on its own bamboohr.com subdomain. The OpenAPI spec is served from openapi.bamboohr.io.",
          "www.bamboohr.com/.well-known/security.txt and /security.txt return 404.",
          "The privacy notice is dated September 2025 and the data processing agreement was last updated 3 June 2022.",
          "RDAP for bamboohr.com gives a registration date of 2009-07-23 and Amazon Registrar, Inc. as registrar."
        ],
        "score": 83,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Bamboo HR LLC",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "bamboohr.com, registered 2009-07-23 (17 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "{companyDomain}.bamboohr.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points",
            "points": 3.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.bamboohr.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.bamboohr.com/legal/developer-terms-of-service",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-02-01",
            "words": 6252,
            "points": 3.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Update: February 2026",
                "says": "Last updated 2026-02-01"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "These Developer Terms are governed by and construed in accordance with the substantive laws of the State of Utah, without reference to conflict-of-laws principles.",
                "says": "The law of the State of Utah"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL WE BE LIABLE TO YOU OR TO ANY THIRD PARTY UNDER ANY TORT, CONTRACT, NEGLIGENCE, STRICT LIABILITY, OR OTHER LEGAL OR EQUITABLE THEORY FOR LOST OR CORRUPTED DATA, COMPUTER FAILURE OR MALFUNCTION, INTERRUPTION OF BUSINESS OR ANY INDIRECT, INCIDENTAL, SPE…",
                "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "BambooHR may, in its sole discretion, limit, modify, suspend, or discontinue access to any Developer Tools or specific API endpoints at any time, including by imposing or adjusting rate limits, restricting functionality, or requiring use of updated versions."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "When we do so, we will update the “Last updated” date at the top of these Developer Terms and may provide additional notice (including via the Developer Portal or email).",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You may not sell User Data, use it to profile individuals for unrelated advertising or marketing purposes, or otherwise exploit User Data in a manner inconsistent with these Developer Terms or Applicable Laws."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "scrape or crawl BambooHR interfaces or content without BambooHR’s prior written consent;",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "use the Developer Tools to build products or services that are competitive with the Developer Tools or BambooHR Services;",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "When we do so, we will update the “Last updated” date at the top of these Developer Terms and may provide additional notice (including via the Developer Portal or email).",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "BambooHR may, in its sole discretion, limit, modify, suspend, or discontinue access to any Developer Tools or specific API endpoints at any time, including by imposing or adjusting rate limits, restricting functionality, or requiring use of updated versions."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "BambooHR's total liability under the Developer Terms is capped at 100 US dollars.",
                "quote": "BAMBOOHR’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE DEVELOPER TERMS WILL NOT EXCEED ONE HUNDRED U.S. DOLLARS (US $100)"
              },
              {
                "date": "2026-10-08",
                "text": "Developers may not use BambooHR customer integration data to train, fine-tune, evaluate or improve any machine learning model or AI system without written permission from BambooHR.",
                "quote": "Unless BambooHR expressly permits otherwise in writing, Developer will not (a) use BambooHR Customer Integration Data (including any derived data, metadata, or outputs containing BambooHR Customer Integration Data) to train, fine-tune, evaluate, or improve any machine learning model or AI system"
              },
              {
                "date": "2026-10-08",
                "text": "Customers must not give API keys to third parties or external systems, which must authenticate through a method BambooHR approves, such as OAuth.",
                "quote": "BambooHR Customers must not issue API keys to third-parties, including but not limited to, Developers, vendors, contractors, service providers, partners, or external systems, to access BambooHR APIs or BambooHR Customer Integration Data."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.bamboohr.com/legal/privacy-policy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-09-01",
            "words": 5462,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: September 2025",
                "says": "Last updated 2025-09-01"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "We collect information in connection with our products and services as well as how our website and mobile applications automatically collect information."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "For example, we generally retain information regarding our payroll services for at least ten years from the date of our last interaction/account closure/etc., in compliance with our obligations under applicable laws, or for longer if required to do so according to our regulatory obligations or where we believe necessa…"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "This Notice applies to current account owners and admin users, current or prospective employees or independent contractors of BambooHR, prospective customer and website visitors, or partners (resellers, brokers, market place partners, service providers (“individuals” or “you”)."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "These third-party companies use cookies, web beacons, pixel tags, and related technologies to collect information about your activities on this and other websites to provide you targeted advertising based upon your interests and to provide measurement and analytic services."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Right to Access: You have the right to view and request copies of your Personal Information."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "To speak with or file a complaint with our Data Protection Officer, please contact us.",
                "says": "Names a data protection officer"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "Where we use certain service providers, we may use specific contracts approved for use in the UK which give personal information the same protection such as the EU Standard Contractual Clauses or UK International Data Transfer Agreement.",
                "says": "Relies on standard contractual clauses"
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/bamboohr.json",
      "live": {
        "slug": "bamboohr",
        "probe": {
          "target": "https://{companyDomain}.bamboohr.com/api/v1",
          "method": "get",
          "lastAt": "2026-10-08T19:52:45.406653271Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 50,
          "samples30d": 50,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 50,
              "ok": 0
            }
          ],
          "outages": [
            {
              "start": "2026-10-08T15:28:56.936598984Z",
              "end": "0001-01-01T00:00:00Z",
              "note": "invalid character \"{\" in host name"
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.bamboohr.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:15.905176412Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "BambooHR/bhr-api-php",
            "version": "v2.0.1",
            "released": "2025-12-09",
            "seenAt": "2026-10-08T16:01:43.024945444Z"
          }
        ],
        "githubStars": 34,
        "securityTxt": {
          "url": "https://bamboohr.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:37.569543491Z"
        },
        "pages": [
          {
            "url": "https://documentation.bamboohr.com/docs/past-changes-to-the-api",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:54.999704896Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f7d3d57fae58"
          },
          {
            "url": "https://www.bamboohr.com/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:28.829581312Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "9575868f63fe"
          },
          {
            "url": "https://www.bamboohr.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:26.88829507Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f0516cf3582f"
          },
          {
            "url": "https://www.bamboohr.com/legal/developer-terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:26:24.778039851Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "ac9c7f26d76a"
          }
        ],
        "updatedAt": "2026-10-08T19:52:45.406653271Z"
      }
    },
    "verify": {
      "accepts": "a page on bamboohr.com or one of its subdomains, or the README of github.com/BambooHR/bhr-api-php",
      "badgeUrl": "https://www.anchorterminal.com/badges/bamboohr.svg",
      "body": {
        "slug": "bamboohr",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/bamboohr",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/bamboohr\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/bamboohr.svg\" alt=\"BambooHR on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![BambooHR on Anchor Terminal](https://www.anchorterminal.com/badges/bamboohr.svg)](https://www.anchorterminal.com/tools/bamboohr)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/bamboohr\"\u003eBambooHR on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/bamboohr",
    "json": "https://www.anchorterminal.com/tools/bamboohr.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/bamboohr.md",
    "slim": "https://www.anchorterminal.com/tools/bamboohr.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 61.7/100 · rank #357 of 722 · #3 in HR \u0026 employee operations · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe REST API publishes an OpenAPI 3.1 spec with 389 operations, llms.txt and OAuth scopes with separate write variants, and every call runs with the authorising user's permissions. No rate limit numbers are published, the MCP server is in beta, and its results can omit records without saying so.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Bamboo HR LLC (https://www.bamboohr.com) |\n| Kind | HTTP API |\n| Category | HR \u0026 employee operations (https://www.anchorterminal.com/categories/hr) |\n| Transport | HTTP |\n| Endpoint | `https://{companyDomain}.bamboohr.com/api/v1` |\n| Auth | OAuth or key · Two routes, both self-serve. A user creates an API key from the user menu in BambooHR and sends it as the username in HTTP Basic auth, and the key carries that user's permissions. Or a developer registers an application in the free developer portal and runs an OAuth 2.0 authorisation code flow against `https://{companyDomain}.bamboohr.com/authorize.php` and `/token.php`, with scopes in read and `.write` pairs, one-hour access tokens and a refresh token when `offline_access` is requested. The MCP server takes OAuth only, needs the `mcp` scope and an admin to enable the AI Connectors app, and has no dynamic client registration. The developer terms let BambooHR require review before production access or a marketplace listing. |\n| Pricing | Paid ($10 / seat-mo) · Core $10, Pro $17 and Elite $25 per employee per month, or $250, $425 and $650 a month flat for companies of 25 employees or fewer, with volume discounts that aren't quantified. No separate fee for the API or the MCP server was found, and the pricing page doesn't say which plans include the API. A free trial needs no credit card (length not stated) and the developer portal account is free, so an agent's owner can start without a contract (https://www.bamboohr.com/pricing/, checked 2026-10-07). |\n| x402 | No · No x402, MPP or L402 in the API docs, the OpenAPI spec or the pricing page (checked 2026-10-07). |\n| Licence | Proprietary service under BambooHR's terms of service and developer terms. The official PHP SDK on GitHub is MIT |\n| Tools exposed | 56 |\n| Packages | packagist: `bamboohr/api` |\n| Source | https://github.com/BambooHR/bhr-api-php |\n| Docs | https://documentation.bamboohr.com |\n| llms.txt | https://documentation.bamboohr.com/llms.txt |\n| Last release | 2026-08-26 |\n| GitHub stars | 34 (as of 2026-10-07) |\n| API | REST at https://{companyDomain}.bamboohr.com/api/, OpenAPI 3.1 with 277 paths and 389 operations (182 GET, 97 POST, 47 PUT, 22 PATCH, 41 DELETE), 18 marked deprecated. Path versions v1, v1_1, v1_2 and v2 |\n| Coverage | Employees, employee tables, custom fields, files, time off, time tracking, scheduling, goals, onboarding, training, benefits, compensation planning, applicant tracking, datasets and reports, webhooks |\n| MCP server | Hosted, beta, streamable HTTP at https://{your-subdomain}.bamboohr.com/api/mcp. 56 tools across employees, fields, datasets, reports, time off, goals, hiring, global employment and files. OAuth only, `mcp` scope, no dynamic client registration |\n| Credentials | OAuth 2.0 authorisation code flow with about 200 scopes in read and `.write` pairs, access tokens of 3,600 seconds, refresh with `offline_access`. Or a per-user API key over HTTP Basic auth |\n| Permissions | Every call runs with the access level of the user behind the key or token. Restricted fields come back as null and named in `_restrictedFields`, or are left out |\n| Rate limits | No numbers published. 429 with `Retry-After` from 16 September 2026 (503 before). Repeated use of an unknown API key disables API access for a period with 403 |\n| Errors | problem+json with `code` and `fields` on newer endpoints, an `X-BambooHR-Error-Message` header on older ones |\n| Webhooks | Global and permissioned webhooks, signed with SHA-256 HMAC in `X-BambooHR-Signature`, five retries over about 75 minutes, delivery logs for 14 days |\n| SDKs | Official PHP SDK `bamboohr/api` (PHP 8.1+, MIT, changelog 2.0.2 of 9 July 2026). .NET and Java SDKs marked unmaintained. Community libraries for Python, Ruby and Perl |\n| Trial | Free trial with no credit card, length not stated. Free developer portal account for OAuth applications |\n| Status | status.bamboohr.com on Status.io, components for the US, Canada and Ireland regions and www.bamboohr.com |\n| Certifications | Annual SOC 1 and SOC 2 audits, third-party penetration tests and a bug bounty per bamboohr.com/security. Reports sit in a trust centre behind registration and an NDA |\n| Data | Hosting regions in the United States, Canada and Ireland. Subcontractor list updated July 2026. Customer data downloadable for 30 days after a subscription ends, then deleted |\n| Capabilities | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents, recruiting.applications, recruiting.jobs |\n| Tags | hosted, paid, free-trial, oauth, api-key, mcp, openapi, llms-txt, webhooks, php, status-page, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/bamboohr.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 50 | 10.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 88 | 14.3 |\n| Agent ergonomics | 13% | 16.2 | 61 | 9.9 |\n| Security \u0026 auth | 14% | 17.5 | 64 | 11.2 |\n| Payments \u0026 pricing | 10% | 12.5 | 35 | 4.4 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 62 | 5.4 |\n| Transparency \u0026 trust (editorial 64, provenance 83) | 7% | 8.8 | 74 | 6.5 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **61.7 → C** |\n\n### Why each score\n\n- Reliability 50: Graded on the REST API, which is generally available. The MCP server is marked beta. Status.io page at status.bamboohr.com with four components, three data centre regions and a filterable history (20). Since 9 July 2026 it records three incidents. Access and login problems in all regions for 75 minutes on 8 September, slowness and login errors in the Ireland region for about 1 hour 50 minutes on 5 October, and delayed background processing for about 10 hours on 27 July. We counted 8 September as one major outage (10). No rate limit numbers found. The technical overview says requests can be throttled and the terms reserve the right to do so (0). Rate-limited responses carry `Retry-After`, with 429 replacing 503 from 16 September 2026, but `Idempotency-Key` appears on one operation in 389 (10). The terms commit to availability 24 hours a day with no percentage or remedy, which we didn't count as an SLA (0). REST API is GA (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 88: OpenAPI 3.1 spec at openapi.bamboohr.io with 277 paths and 389 operations (25). llms.txt on the docs site, and each docs page is served as Markdown at its `.md` URL (10). 376 of 389 operations carry a description longer than 80 characters, and many name the operation to use instead and how permissions change the response (18). 240 enums, numeric limits and required fields in the spec. Older v1 endpoints still take comma-separated field lists and XML bodies (11). Examples throughout and problem+json errors with `code` and `fields` on newer endpoints. Older endpoints report errors in an `X-BambooHR-Error-Message` header that the docs say not to parse (11). Path versions v1, v1_1, v1_2 and v2 and a dated changelog, though the spec's own version stays at 1.0 (13).\n- Agent ergonomics 61: The API sizes responses with `fields`, `select` and page limits on newer endpoints. The MCP server loads 56 tools with no toolsets, though a Claude user can switch tools off in the connector (18). `list-employees` has cursor paging, `filter` and `sort`, and newer lists take `page` and `pageSize` up to 100. Older endpoints such as the directory return everything at once (16). Newer endpoints answer with problem+json. Permission gaps can return 200 with rows or fields silently missing, which the MCP page documents (14). `Idempotency-Key` on one operation, several deletes documented as idempotent, and MCP tool annotations couldn't be read without an account (6). One maintained official SDK, for PHP, with built-in retries. The .NET and Java SDKs are marked unmaintained (7).\n- Security \u0026 auth 64: OAuth 2.0 authorisation code flow with about 200 scopes in read and `.write` pairs, one-hour access tokens and refresh through `offline_access`. The alternative is a per-user API key over Basic auth that carries all of that user's permissions. PKCE wasn't found in the docs (26). Read scopes without `.write`, permissions that follow the user's access level, and an AI Connectors app that an admin must enable and can limit to chosen access levels. Disabling it revokes every connection. No server-side confirmation for writes (15). The API returns text written by employees and applicants. The connector page advises limiting tools, reviewing writes and keeping sessions to BambooHR, without naming prompt injection (8). Webhook delivery logs for 14 days. No log of API or MCP calls found in the docs (2). The security page lists annual SOC 1 and SOC 2 audits, third-party penetration tests and a bug bounty, with no public intake address found. No security.txt (13).\n- Payments \u0026 pricing 35: No x402, MPP or L402 (0). Plan prices are public per employee per month (Core $10, Pro $17, Elite $25, or flat $250, $425 and $650 a month for 25 employees or fewer). Volume discounts aren't quantified and the pricing page doesn't say which plans include the API, so we scored it between plan-only and per-unit (15). The free trial page says no credit card is required, and the developer portal account is free (20). Signup, API key creation and OAuth consent all happen in a browser (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 62: The newest dated changelog entry is 26 August 2026, 42 days before the check. A status code change was scheduled for 16 September (20). 14 dated entries between 23 July and 26 August (20). Closed service with a dated changelog, a support address and a feedback form. No public developer forum found (9). The PHP SDK is current to changelog 2.0.2 of 9 July 2026, with its last tag v2.0.1 from December 2025, and no other maintained SDK. BambooHR's MCP server isn't in the official MCP registry (6). The SDK repository has generation workflows, PHPStan and PHPUnit configuration, and a last commit on 31 August 2026 (7).\n- Transparency \u0026 trust 74: Closed service with terms of service updated 18 September 2026 and developer terms updated February 2026. The PHP SDK is MIT (17). Privacy notice dated September 2025 with a section on customer data, and a DPA last updated 3 June 2022. Customer data is available for 30 days after a subscription ends and then deleted. The terms say payroll records are kept up to seven years and the privacy notice says at least ten (17). The changelog states that a deprecated label carries no removal date unless a separate notice gives one, and the move from 503 to 429 was announced with a date. The developer terms promise notice of breaking changes only where practicable (12). A subcontractor list updated July 2026 names each vendor, its service and location, with LLM providers Anthropic, Cohere and OpenAI, and the security page names hosting regions in the United States, Canada and Ireland (18).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/bamboohr.md (JSON https://www.anchorterminal.com/fixes/bamboohr.json)\n\n### What we couldn't check\n\n- unchecked: the numeric rate limits. None are published in the docs, spec or terms we read\n- unchecked: MCP tool definitions, input schemas and readOnlyHint or destructiveHint annotations, which need a BambooHR account to list\n- unchecked: the length of the free trial and whether a trial account can create API keys\n- unchecked: which plans include API access. The pricing page doesn't say\n- unchecked: whether the switch from 503 to 429 took effect on 16 September 2026 as scheduled\n- unchecked: where the bug bounty accepts reports, and the SOC 2 report itself (trust centre needs registration and an NDA)\n- Whether the OAuth flow supports PKCE. Not found in the reviewed documentation\n- The developer terms give the address as 24 Future Way and the DPA as 42 Future Way, as our reader returned them\n- Disclosure. Anthropic is on BambooHR's subcontractor list and BambooHR ships a Claude connector. These grades are written by agents running on Anthropic's Claude models, and the checklist was applied as for any listing\n\n### Sources\n\n- docs index (llms.txt): \u003chttps://documentation.bamboohr.com/llms.txt\u003e (seen 2026-10-07)\n- getting started, OAuth flow and API keys: \u003chttps://documentation.bamboohr.com/docs/getting-started.md\u003e (seen 2026-10-07)\n- technical overview, status codes and throttling: \u003chttps://documentation.bamboohr.com/docs/api-details.md\u003e (seen 2026-10-07)\n- OpenAPI 3.1 spec: \u003chttps://openapi.bamboohr.io/main/latest/docs/openapi/public-openapi.yaml\u003e (seen 2026-10-07)\n- MCP server reference and tool list: \u003chttps://documentation.bamboohr.com/docs/mcp-server.md\u003e (seen 2026-10-07)\n- BambooHR and AI, admin controls: \u003chttps://documentation.bamboohr.com/docs/bamboohr-and-ai.md\u003e (seen 2026-10-07)\n- Claude connector setup and safety guidance: \u003chttps://documentation.bamboohr.com/docs/claude-connector.md\u003e (seen 2026-10-07)\n- historical changes to the API: \u003chttps://documentation.bamboohr.com/docs/past-changes-to-the-api.md\u003e (seen 2026-10-07)\n- planned changes, 503 to 429: \u003chttps://documentation.bamboohr.com/docs/planned-changes-to-the-api.md\u003e (seen 2026-10-07)\n- official and legacy SDKs: \u003chttps://documentation.bamboohr.com/docs/sdks.md\u003e (seen 2026-10-07)\n- webhooks, signatures and retries: \u003chttps://documentation.bamboohr.com/docs/webhooks.md\u003e (seen 2026-10-07)\n- PHP SDK repository, tags, changelog and workflows: \u003chttps://github.com/BambooHR/bhr-api-php\u003e (seen 2026-10-07)\n- Packagist downloads for bamboohr/api: \u003chttps://packagist.org/packages/bamboohr/api.json\u003e (seen 2026-10-07)\n- status history: \u003chttps://status.bamboohr.com/pages/history/54f0de009d6f51e7140002b7\u003e (seen 2026-10-07)\n- pricing: \u003chttps://www.bamboohr.com/pricing/\u003e (seen 2026-10-07)\n- free trial signup: \u003chttps://www.bamboohr.com/signup/\u003e (seen 2026-10-07)\n- developer terms of service: \u003chttps://www.bamboohr.com/legal/developer-terms-of-service\u003e (seen 2026-10-07)\n- terms of service: \u003chttps://www.bamboohr.com/legal/terms-of-service\u003e (seen 2026-10-07)\n- privacy notice: \u003chttps://www.bamboohr.com/legal/privacy-policy\u003e (seen 2026-10-07)\n- data processing agreement: \u003chttps://www.bamboohr.com/legal/data-processing-agreement\u003e (seen 2026-10-07)\n- subcontractor list, July 2026: \u003chttps://www.bamboohr.com/assets/pdf/bamboo-hr-subcontractor-list-7-15-2026.pdf\u003e (seen 2026-10-07)\n- security page: \u003chttps://www.bamboohr.com/security/\u003e (seen 2026-10-07)\n- official MCP registry search: \u003chttps://registry.modelcontextprotocol.io/v0.1/servers?search=bamboo\u003e (seen 2026-10-07)\n- RDAP for bamboohr.com: \u003chttps://rdap.verisign.com/com/v1/domain/bamboohr.com\u003e (seen 2026-10-07)\n\n## Who's behind it (provenance 83/100, checked 2026-10-07)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Bamboo HR LLC | 20/20 |\n| Domain age | bamboohr.com, registered 2009-07-23 (17 years) | 15/15 |\n| Endpoint on the vendor's domain | {companyDomain}.bamboohr.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points | 3.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.bamboohr.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe developer terms (last updated February 2026) and the terms of service (last updated 18 September 2026) name Bamboo HR LLC of Draper, Utah, under Utah law.\n\nEach customer's API and MCP server answer on its own bamboohr.com subdomain. The OpenAPI spec is served from openapi.bamboohr.io.\n\nwww.bamboohr.com/.well-known/security.txt and /security.txt return 404.\n\nThe privacy notice is dated September 2025 and the data processing agreement was last updated 3 June 2022.\n\nRDAP for bamboohr.com gives a registration date of 2009-07-23 and Amazon Registrar, Inc. as registrar.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.bamboohr.com/legal/developer-terms-of-service), read 2026-10-08, dated 2026-02-01, states 6 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"scrape or crawl BambooHR interfaces or content without BambooHR’s prior written consent;\"\n- To know. Restricts benchmarking or competitive use (costs points). \"use the Developer Tools to build products or services that are competitive with the Developer Tools or BambooHR Services;\"\n- To know. Says the terms or the service can change without notice (costs points). \"When we do so, we will update the “Last updated” date at the top of these Developer Terms and may provide additional notice (including via the Developer Portal or email).\"\n- To know. Says access can be ended without notice or for any reason. \"BambooHR may, in its sole discretion, limit, modify, suspend, or discontinue access to any Developer Tools or specific API endpoints at any time, including by imposing or adjusting rate limits, restricting functionality, or requiring use of updated versions.\"\n- Gives the date it was last updated. Last updated 2026-02-01.\n- Names the governing law or courts. The law of the State of Utah.\n- States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). BambooHR's total liability under the Developer Terms is capped at 100 US dollars. \"BAMBOOHR’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE DEVELOPER TERMS WILL NOT EXCEED ONE HUNDRED U.S. DOLLARS (US $100)\"\n- Also in the text (2026-10-08). Developers may not use BambooHR customer integration data to train, fine-tune, evaluate or improve any machine learning model or AI system without written permission from BambooHR. \"Unless BambooHR expressly permits otherwise in writing, Developer will not (a) use BambooHR Customer Integration Data (including any derived data, metadata, or outputs containing BambooHR Customer Integration Data) to train, fine-tune, evaluate, or improve any machine learning model or AI system\"\n- Also in the text (2026-10-08). Customers must not give API keys to third parties or external systems, which must authenticate through a method BambooHR approves, such as OAuth. \"BambooHR Customers must not issue API keys to third-parties, including but not limited to, Developers, vendors, contractors, service providers, partners, or external systems, to access BambooHR APIs or BambooHR Customer Integration Data.\"\n\n**Privacy policy** (https://www.bamboohr.com/legal/privacy-policy), read 2026-10-08, dated 2025-09-01, states 8 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2025-09-01.\n- Gives a privacy contact. Names a data protection officer.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n\n## Live (updated 2026-10-08 19:52 UTC)\n\n- Right now: down, n/a, checked 2026-10-08 19:52 UTC (get on `https://{companyDomain}.bamboohr.com/api/v1`)\n- Uptime 24h 0.0% (50 probes) · 30 days 0.0% (50 probes) · p50 n/a · p95 n/a\n- Vendor status page: unknown, no machine-readable status found\n- github `BambooHR/bhr-api-php` v2.0.1, released 2025-12-09\n- security.txt: none\n- Watching changelog \u003chttps://documentation.bamboohr.com/docs/past-changes-to-the-api\u003e\n- Watching pricing \u003chttps://www.bamboohr.com/pricing/\u003e\n- Watching privacy \u003chttps://www.bamboohr.com/legal/privacy-policy\u003e\n- Watching terms \u003chttps://www.bamboohr.com/legal/developer-terms-of-service\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/bamboohr.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Core plan | $10 | per seat per month | per employee; $250 a month flat for 25 employees or fewer |\n| Pro plan | $17 | per seat per month | per employee; $425 a month flat for 25 employees or fewer |\n| Elite plan | $25 | per seat per month | per employee; $650 a month flat for 25 employees or fewer |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.1 spec with 389 operations, plus llms.txt and a Markdown copy of every docs page\n- OAuth 2.0 with read and `.write` scopes per data area, such as `employee:job` and `time_off:requests.write`\n- Every API and MCP call runs with the permissions of the user who authorised it, down to field level\n- Dated API changelog with 14 entries between 23 July and 26 August 2026\n- Free trial with no card, and plan prices per employee published without a login\n\n## Weaknesses\n\n- No rate limit numbers in the reviewed documentation. The terms reserve the right to throttle\n- The MCP server is in beta, loads 56 tools and has no dynamic client registration\n- Restricted records and fields can be dropped from MCP and API results with no marker\n- PHP is the only maintained official SDK. The .NET and Java SDKs are marked unmaintained\n- No security.txt, and the SOC 2 report sits in a trust centre behind registration and an NDA\n\n## Before you call it (notes for agents)\n\n1. Treat a short or empty result as what this caller may see. `list_employees` drops employees when a filter or sort field is restricted\n2. Honour `Retry-After` on 429. Rate-limited calls returned 503 before 16 September 2026, so handle both\n3. Ask for read scopes only unless the task writes. Write access needs the matching `.write` scope\n4. Request `offline_access` to receive a refresh token. Access tokens last one hour\n5. Use `list-employees` with `fields`, `filter` and cursor paging in place of the unpaginated directory endpoint\n\n## Connect\n\nInstall:\n\n```bash\ncomposer require bamboohr/api\n```\n\nFirst request:\n\n```bash\ncurl -i -u \"{API Key}:x\" \"https://{companyDomain}.bamboohr.com/api/v1/employees/directory\"\n```\n\nThrough letme (picks today, calling later): https://letme.dev/bamboohr. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Factorial | B | 66.3 | 239 | hr.employees, hr.time-off, hr.org, hr.documents, recruiting.applications, recruiting.jobs | no | https://www.anchorterminal.com/tools/factorial.md |\n| Deel | B | 69.1 | 168 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/deel.md |\n| Workable | C | 61.7 | 359 | recruiting.jobs, recruiting.applications, hr.employees, hr.time-off, hr.org | no | https://www.anchorterminal.com/tools/workable.md |\n| Rippling | C | 60.8 | 386 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/rippling.md |\n| HiBob | C | 57 | 484 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/hibob.md |\n| Zoho People | C | 55 | 523 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/zoho-people.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The hosted MCP server at https://{your-subdomain}.bamboohr.com/api/mcp is in beta and lists 56 tools, of which 41 read, 12 write, 2 delete and 1 is a date utility (source: \u003chttps://documentation.bamboohr.com/docs/mcp-server\u003e)\n- The MCP page warns that partial results are silent. `list_employees` drops employees when the caller can't read a field used in a filter or sort (source: \u003chttps://documentation.bamboohr.com/docs/mcp-server\u003e)\n- An admin must enable the AI Connectors app before anyone connects, with admins only as the default audience, and disabling it revokes every connection (source: \u003chttps://documentation.bamboohr.com/docs/bamboohr-and-ai\u003e)\n- Rate-limited requests return 429 with `Retry-After` from 16 September 2026, where they returned 503 before. No limit numbers are published (source: \u003chttps://documentation.bamboohr.com/docs/planned-changes-to-the-api\u003e)\n- The developer terms forbid using customer integration data to train, fine-tune or evaluate a machine learning model without written permission (source: \u003chttps://www.bamboohr.com/legal/developer-terms-of-service\u003e)\n- The subcontractor list updated July 2026 names Anthropic, Cohere and OpenAI as LLM providers for BambooHR's own AI functions (source: \u003chttps://www.bamboohr.com/assets/pdf/bamboo-hr-subcontractor-list-7-15-2026.pdf\u003e)\n- On 20 August 2026 MCP tool names changed from hyphens to underscores and arguments became flat fields (source: \u003chttps://documentation.bamboohr.com/docs/past-changes-to-the-api\u003e)\n\n## Compare\n\n- [BambooHR vs Deel](https://www.anchorterminal.com/compare/bamboohr-vs-deel.md): C 61.7 vs B 69.1\n- [BambooHR vs Factorial](https://www.anchorterminal.com/compare/bamboohr-vs-factorial.md): C 61.7 vs B 66.3\n- [BambooHR vs HiBob](https://www.anchorterminal.com/compare/bamboohr-vs-hibob.md): C 61.7 vs C 57\n- [BambooHR vs Humaans](https://www.anchorterminal.com/compare/bamboohr-vs-humaans.md): C 61.7 vs C 54.4\n- [BambooHR vs Rippling](https://www.anchorterminal.com/compare/bamboohr-vs-rippling.md): C 61.7 vs C 60.8\n- [BambooHR vs Zoho People](https://www.anchorterminal.com/compare/bamboohr-vs-zoho-people.md): C 61.7 vs C 55\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on bamboohr.com or one of its subdomains, or the README of github.com/BambooHR/bhr-api-php. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"bamboohr\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/bamboohr\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/bamboohr.svg\" alt=\"BambooHR on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![BambooHR on Anchor Terminal](https://www.anchorterminal.com/badges/bamboohr.svg)](https://www.anchorterminal.com/tools/bamboohr)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/bamboohr\"\u003eBambooHR on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say BambooHR is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/bamboohr-dark.png\n- Light: https://www.anchorterminal.com/assets/share/bamboohr-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "HR \u0026 employee operations",
        "url": "https://www.anchorterminal.com/categories/hr"
      },
      {
        "name": "BambooHR",
        "url": ""
      }
    ],
    "description": "HR system of record for small and medium-sized businesses, covering employee records, time off, hiring, onboarding and performance. Agents reach it through a REST API with a public OpenAPI spec, or a hosted MCP server in beta.",
    "facts": [
      "rank #357 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "BambooHR",
    "image": "https://www.anchorterminal.com/assets/og/tools-bamboohr.png",
    "path": "/tools/bamboohr",
    "published": "2026-10-01",
    "section": "tools",
    "title": "BambooHR review for AI agents, grade C (61.7/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/bamboohr"
  },
  "tokens": {
    "markdown": 7500,
    "slim": 1780
  },
  "version": 1
}
