# BambooHR (slim) > HR system of record for small and medium-sized businesses, covering employee records, time off, hiring, onboarding and performance. Agents reach it through a REST API with a public OpenAPI spec, or a hosted MCP server in beta. - Full: https://www.anchorterminal.com/tools/bamboohr.md (~7,350 tokens) · this version ~1,780 tokens · JSON https://www.anchorterminal.com/tools/bamboohr.json · canonical https://www.anchorterminal.com/tools/bamboohr - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 61.7/100 · rank #319 of 629 · #2 in HR & employee operations · not agent-ready · confidence medium** Assessment: The REST API publishes an OpenAPI 3.1 spec with 389 operations, llms.txt and OAuth scopes with separate write variants, and every call runs with the authorising user's permissions. No rate limit numbers are published, the MCP server is in beta, and its results can omit records without saying so. ## Facts - Kind: HTTP API · vendor: Bamboo HR LLC · category: HR & employee operations · legal entity: Bamboo HR LLC · provenance 83/100 - Endpoint: `https://{companyDomain}.bamboohr.com/api/v1` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under BambooHR's terms of service and developer terms. The official PHP SDK on GitHub is MIT - Probe metrics: not measured yet (probes haven't run) - API: REST at https://{companyDomain}.bamboohr.com/api/, OpenAPI 3.1 with 277 paths and 389 operations (182 GET, 97 POST, 47 PUT, 22 PATCH, 41 DELETE), 18 marked deprecated. Path versions v1, v1_1, v1_2 and v2 - Coverage: Employees, employee tables, custom fields, files, time off, time tracking, scheduling, goals, onboarding, training, benefits, compensation planning, applicant tracking, datasets and reports, webhooks - MCP server: Hosted, beta, streamable HTTP at https://{your-subdomain}.bamboohr.com/api/mcp. 56 tools across employees, fields, datasets, reports, time off, goals, hiring, global employment and files. OAuth only, `mcp` scope, no dynamic client registration - Credentials: OAuth 2.0 authorisation code flow with about 200 scopes in read and `.write` pairs, access tokens of 3,600 seconds, refresh with `offline_access`. Or a per-user API key over HTTP Basic auth - Permissions: Every call runs with the access level of the user behind the key or token. Restricted fields come back as null and named in `_restrictedFields`, or are left out - Rate limits: No numbers published. 429 with `Retry-After` from 16 September 2026 (503 before). Repeated use of an unknown API key disables API access for a period with 403 - Errors: problem+json with `code` and `fields` on newer endpoints, an `X-BambooHR-Error-Message` header on older ones - Webhooks: Global and permissioned webhooks, signed with SHA-256 HMAC in `X-BambooHR-Signature`, five retries over about 75 minutes, delivery logs for 14 days - SDKs: Official PHP SDK `bamboohr/api` (PHP 8.1+, MIT, changelog 2.0.2 of 9 July 2026). .NET and Java SDKs marked unmaintained. Community libraries for Python, Ruby and Perl - Trial: Free trial with no credit card, length not stated. Free developer portal account for OAuth applications - Status: status.bamboohr.com on Status.io, components for the US, Canada and Ireland regions and www.bamboohr.com - Certifications: Annual SOC 1 and SOC 2 audits, third-party penetration tests and a bug bounty per bamboohr.com/security. Reports sit in a trust centre behind registration and an NDA - Data: Hosting regions in the United States, Canada and Ireland. Subcontractor list updated July 2026. Customer data downloadable for 30 days after a subscription ends, then deleted - Prices: Core plan $10 per seat per month; Pro plan $17 per seat per month; Elite plan $25 per seat per month - Scores: Reliability 50, Performance pending, Schema & documentation 88, Agent ergonomics 61, Security & auth 64, Payments & pricing 35, Task success pending, Maintenance & community 62, Transparency & trust 74 · total over the 7 assessed categories - Why: Reliability, Graded on the REST API, which is generally available. · Schema & documentation, OpenAPI 3.1 spec at openapi.bamboohr.io with 277 paths and 389 operations (25). · Agent ergonomics, The API sizes responses with `fields`, `select` and page limits on newer endpoints. · Security & auth, OAuth 2.0 authorisation code flow with about 200 scopes in read and `.write` pairs, one-hour access tokens and refresh through… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The newest dated changelog entry is 26 August 2026, 42 days before the check. · Transparency & trust, Closed service with terms of service updated 18 September 2026 and developer terms updated February 2026. The PHP SDK is MIT (17). - Sources: 24, open questions: 9, both in the full twin - Capabilities: hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents, recruiting.applications, recruiting.jobs - JSON: https://www.anchorterminal.com/api/v1/tools/bamboohr.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/bamboohr.svg` or a link to https://www.anchorterminal.com/tools/bamboohr from a page on bamboohr.com or one of its subdomains, or the README of github.com/BambooHR/bhr-api-php, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Treat a short or empty result as what this caller may see. `list_employees` drops employees when a filter or sort field is restricted 2. Honour `Retry-After` on 429. Rate-limited calls returned 503 before 16 September 2026, so handle both 3. Ask for read scopes only unless the task writes. Write access needs the matching `.write` scope 4. Request `offline_access` to receive a refresh token. Access tokens last one hour 5. Use `list-employees` with `fields`, `filter` and cursor paging in place of the unpaginated directory endpoint ## Connect ```bash composer require bamboohr/api ``` ```bash curl -i -u "{API Key}:x" "https://{companyDomain}.bamboohr.com/api/v1/employees/directory" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/bamboohr ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Deel | B | 69.1 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/deel.min.md | | Workable | C | 61.7 | recruiting.jobs, recruiting.applications, hr.employees, hr.time-off, hr.org | https://www.anchorterminal.com/tools/workable.min.md | | Rippling | C | 60.8 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/rippling.min.md | | HiBob | C | 57 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/hibob.min.md | | Finch | BB | 71.6 | hr.employees, hr.org, hr.documents | https://www.anchorterminal.com/tools/finch.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)