# Deel > Deel is a global HR, payroll and employer-of-record platform. Its REST API and hosted MCP server let an agent read and update people records, time off, organisation structure, onboarding, contracts and compliance documents. - Canonical: https://www.anchorterminal.com/tools/deel - Markdown: https://www.anchorterminal.com/tools/deel.md (~6,850 tokens) - Slim: https://www.anchorterminal.com/tools/deel.min.md (~1,830 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/deel.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 69.1/100 · rank #158 of 629 · #1 in HR & employee operations · not agent-ready · confidence medium** ## Assessment The API has 506 operations in public OpenAPI 3.1 specs, about 90 read and write OAuth scopes, a sandbox and a dated versioning policy with one year of deprecation notice. The limit is 5 requests a second for a whole organisation, and the legal documents load only with JavaScript, so data handling terms weren't read. ## Facts | Field | Value | | --- | --- | | Vendor | Deel, Inc. (https://www.deel.com) | | Kind | HTTP API | | Category | HR & employee operations (https://www.anchorterminal.com/categories/hr) | | Transport | HTTP, Streamable HTTP, SSE (legacy) | | Endpoint | `https://api.letsdeel.com/rest` | | Auth | OAuth or key · Self-serve for an existing Deel customer. An admin creates an organisation or personal token in the Developer Centre (More, Developer, Access Tokens), choosing scopes and what sensitive data it can read, or registers an OAuth 2 app. No partner or sales approval is documented for a company's own data. Publishing to the Deel App Store has its own submission step, and worker tokens need the Embedded partnership. The MCP server takes OAuth with PKCE and dynamic client registration, or a personal token. Scopes follow `{resource}:read` and `{resource}:write`. | | Pricing | Paid ($5 / seat-mo) · No separate API charge was found. Access comes with a Deel account, priced per person a month. Deel HR is $5 (Core), $19 (Advanced) or $29 (Elite) per employee, contractor management $49 per contractor and EOR $599 per employee. No free plan is on the pricing page, whose buttons book a demo. The quickstart says a sandbox can be created from the Developer Centre after signing up at app.deel.com. We didn't sign up, so whether that needs a card or a contract is unconfirmed (https://www.deel.com/pricing/, checked 2026-10-07). | | x402 | No · No x402, MPP or L402 in the developer docs, the OpenAPI specs or the pricing page (checked 2026-10-07). | | Licence | Proprietary service under Deel's platform terms. The Deel CLI on GitHub is MIT | | Tools exposed | 86 | | Packages | npm: `@deel-org/cli`; npm: `@deel-developers/deel` | | Source | https://github.com/letsdeel/deel-cli | | Docs | https://developer.deel.com | | llms.txt | https://developer.deel.com/llms.txt | | Last release | 2026-10-05 | | npm downloads / week | 17 | | API | REST at https://api.letsdeel.com/rest, stable version 2026-01-01 set with the `X-Version` header. 506 operations (260 GET, 154 POST, 50 PATCH, 31 DELETE, 11 PUT) and 55 webhook events in the OpenAPI 3.1 spec, with SCIM 2.0 at /scim/v2 | | HR coverage | People (list, retrieve, create, update personal information and working location), custom fields, organisation structures, positions, worker relations, time off (policies, entitlements, create, update, cancel, approve or reject), onboarding tracker, compliance and HR documents | | MCP server | Hosted at https://api.letsdeel.com/mcp over HTTP with SSE, server name deel-mcp 1.0.0, protocol 2025-03-26. 86 tools in the docs across contracts, people, time off, payments, payroll, hiring insights, benefits, IT assets, onboarding and reference data. 8 public tools are listed without a token | | Credentials | Organisation token, personal token or OAuth 2 app, all Bearer. Tokens are created in the Developer Centre with chosen scopes and a sensitive-data setting. OAuth for MCP uses PKCE (S256) and dynamic client registration | | Rate limits | 5 requests a second per organisation, shared by all tokens, rolling one-second window, 429 on excess. Same limits in the sandbox and on the MCP server | | Retries | `Idempotency-Key` header on POST and PATCH, responses cached 24 hours, replayed responses carry `x-original-request-id`. The MCP error page says 429 carries `Retry-After` | | Errors | JSON body with a `request` object (method, url, status, api_req_id, docs link) and an `errors` array of message and JSON path. `X-Request-ID` on every response | | Pagination | Mixed. `limit` with `offset` on some lists (people, limit up to 200), cursor parameters on others, and `page_size` with `next` on time-off requests | | Sandbox | https://api-staging.letsdeel.com/rest, created from the Developer Centre with its own login and tokens. Sample workers and organisations, simulated payments and signatures, resettable | | Webhooks | 55 events in the spec, among them worker created, updated and deleted, time off created, reviewed, updated and deleted, and onboarding status updated. HMAC-SHA256 signature, ten retries, 30-second timeout | | Clients | Deel CLI @deel-org/cli 0.2.0 (24 September 2026, MIT, Node 22.18+ or a signed binary). TypeScript SDK @deel-developers/deel 2.1.56, last published 13 March 2025 | | Certifications | SOC 1, SOC 2, SOC 3 and ISO 27001 per deel.com/security. AWS hosting with primary operations in Ireland and disaster recovery in France | | Status | status.deel.com on StatusPal, with a Deel Developer API component, a Demo & Sandboxes component and 60-day uptime bars | | Capabilities | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | | Tags | hosted, official, mcp, closed-source, oauth, openapi, llms-txt, webhooks, sandbox, scim, typescript, status-page, soc2, sales-led | | JSON | https://www.anchorterminal.com/api/v1/tools/deel.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 88 | 17.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 85 | 13.8 | | Agent ergonomics | 13% | 16.2 | 65 | 10.6 | | Security & auth | 14% | 17.5 | 64 | 11.2 | | Payments & pricing | 10% | 12.5 | 30 | 3.8 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 70 | 6.1 | | Transparency & trust (editorial 43, provenance 94) | 7% | 8.8 | 69 | 6.0 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **69.1 → B** | ### Why each score - Reliability 88: Graded on the hosted REST API, with the MCP server on the same host. status.deel.com on StatusPal has components for the Deel Developer API and Demo & Sandboxes, with 60-day uptime bars (20). The incident history lists nothing after scheduled maintenance on 25 December 2025, and its last incidents are from July to September 2025 (30). The limit is published as 5 requests a second per organisation (15). Backoff guidance and an `Idempotency-Key` header for POST and PATCH are documented, but the rate limits page says no rate limit headers are returned while the MCP error page says 429 carries `Retry-After` (13). No SLA found. The platform terms didn't render without JavaScript (0). Version 2026-01-01 is labelled stable (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 85: OpenAPI 3.1 specs are public under developer.deel.com/openapi/, 506 operations and 55 webhook events in the full file. The two spec links in the docs index return 404 (25). llms.txt, section indexes and a Markdown copy of each page (10). Operation descriptions average about 235 characters and name the required scopes, and some state limits such as rejection being irreversible. Few say when not to use an endpoint, and the public MCP tools have one-sentence descriptions (13). 1,988 enums, numeric bounds and formats in the spec, though several MCP tools wrap input in a single `data` object (13). 400, 401, 403, 404 and 500 are declared on nearly every operation with a shared error schema, 429 on only 28, and the spec carries few examples (9). Date-based versions and a dated changelog (15). - Agent ergonomics 65: The MCP docs list 86 tools with no toolsets. Unauthenticated clients see 8 public ones, and scopes limit what a token can call. REST lists take `limit`, and people has a `fields` filter (10). Pagination and filters exist on list endpoints but in three styles (offset, cursor, `page_size` with `next`) (16). Errors carry a message, the JSON path of the failed field, a request id and a docs link, and the MCP guide separates retryable from non-retryable errors (16). `Idempotency-Key` on POST and PATCH with a 24-hour cache, declared in the spec on one operation. The 8 MCP tools we could list all set readOnlyHint and destructiveHint (17). One TypeScript SDK, last published 13 March 2025, and a CLI at 0.2.0. No Python SDK found (6). - Security & auth 64: OAuth 2 with PKCE, dynamic client registration, single-use refresh tokens and about 90 scopes split into read and write. Organisation and personal tokens are scoped, revocable and have a sensitive-data setting (30). Read scopes allow a read-only agent and MCP tools carry annotations. No confirmation step for writes such as time-off rejection was found (13). The API returns free text written by workers and managers, and no prompt-injection guidance was found (3). An `api-logs:read` scope exists in the OAuth metadata, but no operator audit log for API or MCP calls was found in the docs (3). security.txt is valid until 21 July 2027, the CLI's security policy takes reports at security@deel.com, and deel.com/security lists SOC 1, SOC 2, SOC 3 and ISO 27001. No bug bounty found (15). - Payments & pricing 30: No x402, MPP or L402 (0). Per-person monthly prices are public, such as Deel HR from $5 per employee, with no API charge found. We scored it between plan-only and per-unit (15). The quickstart describes a sandbox created after signing up at app.deel.com, but the pricing page lists no free plan and we didn't confirm that signup needs no card or contract (10). A person signs up and creates tokens in a browser. Eight public MCP tools (hiring cost and salary data) are listed without a token, and OAuth clients can self-register (5). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 70: The API changelog's newest entry is 5 October 2026 (30). 20 dated entries between 2 September and 5 October 2026 (20). Closed service with a dated changelog and a community forum at stack.deel.com, which we didn't read for response times (8). The TypeScript SDK was last published on 13 March 2025 and its repository isn't public. The CLI's first public release was 24 September 2026. The MCP server isn't in the official MCP registry (6). The CLI repository has a pull-request workflow and tests (6). - Transparency & trust 69: Editorial half only. Closed service. The platform terms, privacy policy and DPA exist at stable URLs but returned no text without JavaScript, so we scored the terms as partly established. The CLI is MIT (10). Data handling couldn't be read for the same reason. The security page states AES-256 at rest and AWS hosting (5). The versioning policy gives at least one year stable and one year deprecated with `Sunset` headers, and the spec dates removals, such as the current people list on 30 September 2027 (20). Hosting locations are disclosed (Ireland, with disaster recovery in France). No sub-processor list was read (8). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/deel.md (JSON https://www.anchorterminal.com/fixes/deel.json) ### What we couldn't check - unchecked: the privacy policy, data processing addendum and platform terms on deel.com/legal returned no document text without JavaScript, so retention periods, sub-processors, the contracting entity and any SLA weren't read - unchecked: trust.deel.com is a JavaScript application and returned no content - unchecked: whether signing up and creating a sandbox needs a card, a contract or a sales call. We didn't create an account - unchecked: the authenticated MCP tool list. The server listed 8 public tools without a token, and the docs list 86 under different names - unchecked: whether 429 responses carry `Retry-After`. The rate limits page says no rate limit headers are returned, the MCP error page says the header is sent - unchecked: the OAuth access token lifetime, given as 1 hour on the MCP page and 30 days on the OAuth page - unchecked: response times on the stack.deel.com community forum, and GitHub stars for letsdeel/deel-cli - The legal entity Deel, Inc. is taken from the CLI's licence file, not from the terms - No operator-facing audit log for API or MCP calls was found in the developer docs, though an api-logs:read scope exists - The TypeScript SDK's repository (letsdeel/deel-api-js-sdk) isn't publicly cloneable ### Sources - docs index (llms.txt): (seen 2026-10-07) - API docs index for version 2026-01-01: (seen 2026-10-07) - OpenAPI 3.1 spec, full file: (seen 2026-10-07) - authentication and token types: (seen 2026-10-07) - OAuth 2: (seen 2026-10-07) - rate limits: (seen 2026-10-07) - idempotency: (seen 2026-10-07) - API versioning and lifecycle: (seen 2026-10-07) - sandbox: (seen 2026-10-07) - quickstart: (seen 2026-10-07) - API changelog: (seen 2026-10-07) - webhooks introduction: (seen 2026-10-07) - MCP introduction: (seen 2026-10-07) - MCP authorisation: (seen 2026-10-07) - MCP tools reference: (seen 2026-10-07) - MCP error handling: (seen 2026-10-07) - MCP server, unauthenticated initialize and tools/list: (seen 2026-10-07) - OAuth authorisation server metadata and scopes: (seen 2026-10-07) - status page: (seen 2026-10-07) - status incident history: (seen 2026-10-07) - pricing: (seen 2026-10-07) - security page: (seen 2026-10-07) - security.txt: (seen 2026-10-07) - Deel CLI repository, licence and security policy: (seen 2026-10-07) - CLI on npm: (seen 2026-10-07) - TypeScript SDK on npm: (seen 2026-10-07) - MCP registry search: (seen 2026-10-07) - RDAP for deel.com: (seen 2026-10-07) ## Who's behind it (provenance 94/100, checked 2026-10-07) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Deel, Inc. | 20/20 | | Domain age | deel.com, registered 1998-04-21 (28 years) | 15/15 | | Endpoint on the vendor's domain | api.letsdeel.com | 15/15 | | Terms of service | published, but our reader couldn't read it | 7/10 | | Privacy policy | published, but our reader couldn't read it | 7/10 | | Status page | status.deel.com | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The entity name comes from the copyright line of the MIT licence in letsdeel/deel-cli (Copyright (c) 2026 Deel, Inc.). The legal pages on deel.com returned no document text without JavaScript, so the contracting entity in the terms wasn't read. The API and MCP server answer on api.letsdeel.com and the sandbox on api-staging.letsdeel.com. letsdeel.com is Deel's second domain, registered 2018-10-16 per RDAP, and the docs on developer.deel.com name it. https://www.deel.com/.well-known/security.txt gives a Contact and Policy of https://www.deel.com/security and expires on 21 July 2027. api.letsdeel.com and app.deel.com return 404 for the same path. RDAP for deel.com gives a registration date of 1998-04-21. trust.deel.com is a JavaScript application and returned no readable content. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.deel.com/legal/platform-terms-of-service), read 2026-10-08. Our reader couldn't read it (the page has only its navigation without a browser, so the document is drawn by script or sits elsewhere). **Privacy policy** (https://www.deel.com/legal/privacy-policy/), read 2026-10-08. Our reader couldn't read it (the page has only its navigation without a browser, so the document is drawn by script or sits elsewhere). ## Live (updated 2026-10-08 19:08 UTC) - Right now: up, HTTP 404, 84 ms, checked 2026-10-08 19:08 UTC (get on `https://api.letsdeel.com/rest`) - Uptime 24h 100.0% (42 probes) · 30 days 100.0% (42 probes) · p50 103 ms · p95 224 ms - Vendor status page: unknown, no machine-readable status found - github `letsdeel/deel-cli` v0.2.0, released 2026-09-24 - npm `@deel-developers/deel` 2.1.56 - npm `@deel-org/cli` 0.2.0 - security.txt: valid, expires 2027-07-21T00:00:00.000Z - Watching changelog - Watching pricing - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/deel.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Deel HR Core | $5 | per seat per month | per employee | | Deel HR Advanced | $19 | per seat per month | per employee | | Deel HR Elite | $29 | per seat per month | per employee | | Contractor management | $49 | per seat per month | per contractor | | Employer of record | $599 | per seat per month | per EOR employee | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Public OpenAPI 3.1 specs with 506 operations and 55 webhook events, plus llms.txt and a Markdown copy of every docs page - OAuth 2 with PKCE and dynamic client registration, about 90 scopes split into read and write, and single-use refresh tokens - Date-based versions with at least one year stable, one year deprecated, and `Deprecation` and `Sunset` response headers - Changelog with 20 dated entries between 2 September and 5 October 2026 - Sandbox at api-staging.letsdeel.com with sample data, simulated payments and no emails sent to workers ## Weaknesses - 5 requests a second shared by every token in an organisation, with no rate limit headers on REST responses per the rate limits page - The OpenAPI links in the docs index return 404. The working specs sit under developer.deel.com/openapi/ - The idempotency guide covers POST and PATCH, but the spec declares the `Idempotency-Key` header on one operation - TypeScript SDK last published on 13 March 2025, and no Python SDK found - Privacy policy, DPA and platform terms render only with JavaScript, and no public sub-processor list or SLA was read ## Before you call it (notes for agents) 1. Queue calls to stay under 5 requests a second for the whole organisation. Other integrations on the same account share the limit 2. Send `X-Version: 2026-01-01` on REST calls, and watch `X-State`, `Deprecation` and `Sunset` response headers 3. Send a UUID `Idempotency-Key` on POST and PATCH. Only retry a 5xx on a write when the request carried one 4. Test against https://api-staging.letsdeel.com/rest with a sandbox token. Production and sandbox tokens aren't interchangeable 5. Request read scopes only (people:read, time-off:read) for a read-only agent. Rejecting a time-off request is irreversible ## Connect Install: ```bash npm install -g @deel-org/cli ``` First request: ```bash curl -X GET 'https://api.letsdeel.com/rest/contracts' \ -H 'Authorization: Bearer YOUR-TOKEN-HERE' \ -H 'X-Version: 2026-01-01' ``` MCP client configuration: ```json { "mcpServers": { "deel": { "url": "https://api.letsdeel.com/mcp" } } } ``` Through letme (picks today, calling later): https://letme.dev/deel (letme picks it for hr.onboarding, the top-graded tool for the job, letme picks it for hr.time-off, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | BambooHR | C | 61.7 | 319 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/bamboohr.md | | Rippling | C | 60.8 | 341 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/rippling.md | | HiBob | C | 57 | 429 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/hibob.md | | Finch | BB | 71.6 | 99 | hr.employees, hr.org, hr.documents | no | https://www.anchorterminal.com/tools/finch.md | | Workable | C | 61.7 | 320 | hr.employees, hr.time-off, hr.org | no | https://www.anchorterminal.com/tools/workable.md | | Gusto | B | 63.3 | 283 | hr.onboarding, hr.time-off | no | https://www.anchorterminal.com/tools/gusto.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The MCP server at https://api.letsdeel.com/mcp answers `initialize` and `tools/list` without a token and listed 8 public tools on 7 October 2026, each with readOnlyHint and destructiveHint annotations. The docs list 86 tools for an authorised user (source: ) - Rate limit is 5 requests a second per organisation across all tokens, on a rolling one-second window (source: ) - Every endpoint version is beta for three months, stable for at least a year and deprecated for a year before a 410. MCP clients can't call beta endpoints because they can't send `X-Beta: true` (source: ) - OAuth metadata lists about 90 scopes, among them people:read, people:write, time-off:read, time-off:write, hr-suite:read and api-logs:read (source: ) - The MCP authorisation page says access tokens last 1 hour, while the OAuth 2 page says 30 days (`expires_in` 2592000). Refresh tokens last 30 days and are single-use on both (source: ) - status.deel.com runs on StatusPal with components for the Deel Developer API and for Demo & Sandboxes. Its history lists no incident after scheduled maintenance on 25 December 2025 (source: ) - Webhooks are signed with HMAC-SHA256 in `x-deel-signature`, retried ten times over about a day, then the subscription is disabled (source: ) ## Compare - [BambooHR vs Deel](https://www.anchorterminal.com/compare/bamboohr-vs-deel.md): C 61.7 vs B 69.1 - [Deel vs HiBob](https://www.anchorterminal.com/compare/deel-vs-hibob.md): B 69.1 vs C 57 - [Deel vs Rippling](https://www.anchorterminal.com/compare/deel-vs-rippling.md): B 69.1 vs C 60.8 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on deel.com or one of its subdomains, or the README of github.com/letsdeel/deel-cli. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "deel", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Deel on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Deel on Anchor Terminal](https://www.anchorterminal.com/badges/deel.svg)](https://www.anchorterminal.com/tools/deel) ``` Plain link: ```html Deel on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Deel is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/deel-dark.png - Light: https://www.anchorterminal.com/assets/share/deel-light.png