# Bullhorn (slim) > Applicant tracking and CRM software for staffing and recruitment agencies from Bullhorn, Inc. in Boston. Its REST API reads and writes candidates, job orders, submissions, placements and notes with OAuth 2.0, under credentials Bullhorn issues to customers and contracted partners. - Full: https://www.anchorterminal.com/tools/bullhorn.md (~8,250 tokens) · this version ~2,080 tokens · JSON https://www.anchorterminal.com/tools/bullhorn.json · canonical https://www.anchorterminal.com/tools/bullhorn - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **D · 46.7/100 · rank #644 of 722 · #10 in Recruiting & applicant tracking · not agent-ready · confidence medium** Assessment: The REST API covers 91 documented entities with required field selection, Lucene and JPQL queries and an event queue. Access is by support ticket or a paid partner contract, and the API Fair Use Policy bars connecting third-party AI or LLM tools or MCP without Bullhorn's written permission. No OpenAPI file or numeric rate limit was found. ## Facts - Kind: HTTP API · vendor: Bullhorn, Inc. · category: Recruiting & applicant tracking · legal entity: Bullhorn, Inc. · provenance 82/100 - Endpoint: `https://rest.bullhornstaffing.com/rest-services` (HTTP) - Auth: OAuth · pricing: Paid · x402: no · licence: Proprietary service under a Bullhorn customer or partner agreement that is not published, with a public API Fair Use Policy. The `sdk-rest` Java library and the `@bullhorn/taurus` and `@bullhorn/bullhorn-types` packages are MIT per npm and the repositories - Probe metrics: not measured yet (probes haven't run) - Surface graded: Bullhorn REST API version 2.0 for Bullhorn ATS and CRM, generally available. No official MCP server was found - AI and MCP use: The API Fair Use Policy (17 December 2025) requires Bullhorn's explicit written permission before the API is connected to third-party AI or LLM tools, or used with MCP to move or change data - API: 69 documented operations (27 GET, 20 POST, 12 PUT, 10 DELETE) across `/entity`, `/search`, `/query`, `/find`, `/meta`, `/file`, `/resume`, `/massUpdate`, `/savedSearch`, `/services`, `/settings` and `/event/subscription`. JSON, with optional JSONP - Entities: 91 entity reference pages, among them Candidate, ClientContact, ClientCorporation, JobOrder, JobSubmission, Sendout, Appointment, Placement, Note, Lead, Opportunity and Tearsheet, plus Pay and Bill entities - Credentials: OAuth 2.0 authorisation code grant with a client ID and secret issued by Bullhorn. Access token valid 10 minutes, rotating refresh token where enabled, then a `BhRestToken` session from `/login` with an optional `ttl`. No scopes found - Access: Customers request keys by support ticket. Integrators sign the API Access Agreement, pay an annual platform fee and pass a security assessment. Each partner application gets its own API key - Rate limits: No number in the reference. 429 means wait 1 second and retry. Partner allowance of 200,000 calls a month with overage charges. Login rates are strictly limited, with no figure - Pagination: `start` and `count`, default 20, maximum 500 (300 on some calls). To-many associations return 5 by default. `orderBy` and `showTotalMatched` on searches - Field selection: `fields` or `layout` is required on reads, with nested sub-fields, per-association counts and sub-where filters. `fields=*` is blocked outside `/meta` - Errors: Status codes 400, 401, 403, 404, 405, 406, 410, 429, 500 and 503 with one-line meanings. 412 when `BhRestToken` is missing. No error bodies documented - Events: Polling event queue. `PUT /event/subscription` creates a subscription, `GET` reads up to `maxEvents`, and `lastRequestId` re-reads the last batch. No outbound webhooks documented in the reference - SDKs: Java `sdk-rest` 3.0.0 (29 September 2026, Java 17), TypeScript `@bullhorn/taurus` 3.9.8 (22 April 2026) and `@bullhorn/bullhorn-types` 1.142.0 (28 September 2026) - Audit: `EntityEditHistory` and `EntityEditHistoryFieldChange` entities record changes, and events carry `PERSON_ID` and `TRANSACTION_ID`. No per-call API log found - Certifications: Annual SOC 1 Type 2 and SOC 2 Type 2 audits per the GDPR commitment statement, which says many services hold SOC 2 Type 2 or ISO 27001 without naming them - Status: status.bullhorn.com on Statuspage, 96 components by product and cluster (CLS numbers for ATS/CRM), no REST API component - Sub-processors: List version 25 August 2026 with purpose, location and covered services. Bullhorn ATS is hosted on Amazon Web Services and Bullhorn's own data centres in Australia, Canada, Germany, Ireland, the Netherlands, the United Kingdom and the United States - Prices: Bullhorn Starter, per user $99 per seat per month; Bullhorn Core, per user $165 per seat per month - Scores: Reliability 53, Performance pending, Schema & documentation 55, Agent ergonomics 64, Security & auth 31, Payments & pricing 5, Task success pending, Maintenance & community 56, Transparency & trust 67 · total over the 7 assessed categories - Why: Reliability, Read with the hosted rubric, for the REST API. · Schema & documentation, No OpenAPI or other downloadable contract was found. · Agent ergonomics, Every read must name its `fields`, with nested sub-fields and a count per to-many association, and `fields=*` is blocked outside `/meta` (22… · Security & auth, OAuth 2.0 authorisation code grant with a client ID and secret issued by Bullhorn, ten-minute access tokens and rotating refresh tokens, exc… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The REST API change log's newest entry is the June 2026 release (2026.6), over 90 days old. · Transparency & trust, Closed service. - Sources: 23, open questions: 8, both in the full twin - Capabilities: recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews - JSON: https://www.anchorterminal.com/api/v1/tools/bullhorn.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/bullhorn.svg` or a link to https://www.anchorterminal.com/tools/bullhorn from a page on bullhorn.com or one of its subdomains, or the README of github.com/bullhorn/rest-api-docs, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Confirm the customer holds Bullhorn's written permission for AI or LLM access before any call. The API Fair Use Policy forbids it otherwise 2. Call `/rest-services/loginInfo?username=` first to learn the data centre, then use the returned OAuth and REST URLs and follow any 307 redirect 3. Log in once and reuse `BhRestToken` until a call returns 401, then use the refresh token. Bullhorn limits login rates and may block frequent logins 4. Send `BhRestToken` as a header, never in the URL, and always pass `fields`. `fields=*` is blocked outside `/meta` 5. On 429 wait one second and retry. Writes have no idempotency key, so read the record back before repeating a PUT ## Connect ```bash curl "https://rest.bullhornstaffing.com/rest-services/loginInfo?username={API_Username}" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/bullhorn ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Greenhouse | B | 64.8 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews | https://www.anchorterminal.com/tools/greenhouse.min.md | | Ashby | C | 61.3 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews | https://www.anchorterminal.com/tools/ashby.min.md | | SmartRecruiters | C | 60.4 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews | https://www.anchorterminal.com/tools/smartrecruiters.min.md | | Zoho Recruit | C | 59.8 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews | https://www.anchorterminal.com/tools/zoho-recruit.min.md | | Lever | D | 53.6 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews | https://www.anchorterminal.com/tools/lever.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)