Employment Hero Payroll
by Employment Hero Pty Ltd HTTP API in Payroll infrastructure
Employment Hero Pty Ltd · employmenthero.com since 2012 · status page · who's behind it
Employment Hero Payroll (formerly KeyPay) is cloud payroll for Australia, New Zealand, the United Kingdom, Singapore and Malaysia. Its REST API covers businesses, employees, timesheets, leave, pay runs and reports, with an API key or OAuth 2.0.
Good for An agent acting for an employer or bureau already on Employment Hero Payroll in Australia, New Zealand, the United Kingdom, Singapore or Malaysia, and white label partners who create businesses through the brand endpoints.
Is this your product? Claim this listing or verify it
Assessment. Five public Swagger 2.0 files describe 660 to 821 operations per region, and any payroll user can generate an API key without a partner review. The key carries its user's whole access, no idempotency keys or API changelog were found, and the only official client is for .NET.
Facts
- Transport
- HTTP
- Auth
- OAuth or key
- Pricing
- Paid · Paid
- x402
- No
- Licence
- Proprietary service under Employment Hero's General Terms. The `KeyPayV2` .NET client is MIT
- Packages
nugetKeyPayV2- llms.txt
- not found
- Last release
- GitHub stars
- 6
- Surface graded
- Employment Hero Payroll API (REST, JSON), formerly KeyPay. Base https://api.yourpayroll.com.au/api/v2. The separate HR API at developer.employmenthero.com is not graded here
- Regions
- Australia (728 operations), New Zealand (660), United Kingdom (821), Singapore (695), Malaysia (679), one Swagger 2.0 file each
- Payroll coverage
- Businesses, employees, contractors, bank accounts, super funds, pay schedules, pay runs (66 operations in the Australian spec), timesheets, rosters, leave requests, expenses, awards, reports (41), webhooks (7) and employee self-service (111)
- Pay run steps
- Create, recalculate, read warnings and totals, start the approval process, finalise, unlock. Finalise options include
lodgePayRun,lodgePayRunInTestMode,publishPaySlipsandexportJournals - Credentials
- API key from My Account, sent as the Basic auth username with a blank password. OAuth 2.0 authorisation code grant at
/oauth/authoriseand/oauth/token, 24-hour access tokens, 28-day refresh tokens, andPOST /oauth/token/revoke. The spec namesreadandwritescopes - Access steps
- API key is self-serve for any user with a payroll login. OAuth client ID and secret come from a support request
- Rate limits
- 5 requests a second per API key per IP address. Our unauthenticated test saw
x-rate-limit-limit,x-rate-limit-remainingandx-rate-limit-resetheaders, and a 429 withretry-after: 1. The docs don't describe these headers - Pagination and filtering
- OData v3
$skip,$top(100 by default and at most),$orderbyand$filteron most GET operations.$selecton the Employee API only.$expandnot supported - Errors
- Some operations document 400, 404 and 409 with a
ProblemDetailsbody (type,title,status,detail,instance). 401 and 429 answered our test as plain text - Webhooks
- Seven operations under
/api/v2/business/{businessId}/webhookregistrations, with a test call - SDK
KeyPayV2on NuGet for .NET Standard 2.0, MIT, 574 versions, latest 3.0.0.969 on 2 September 2026. Source in Thinkei/keypay-dotnet-v2, generated from the API, last build commit 3.0.0.1025 on 8 October 2026- Status
- https://status.employmenthero.com with Login, Create Pay Run, Finalise Pay Run and Create Employee components for each of five payroll regions. No component names the Payroll API
- Data locations
- Per the DPA of 15 June 2026, APAC data in Australia, United Kingdom payroll data primarily in Ireland, Canadian payroll data primarily in Canada
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Public Swagger 2.0 file for each of five regions, 728 operations for Australia and 821 for the United Kingdom, downloadable without a login
- A payroll user generates an API key under My Account with no partner review, and Change API Key invalidates the old one
- OData
$filter,$orderby,$topand$skipon most GET operations, with$topcapped at 100 - Pay run endpoints cover create, recalculate, warnings, approval start, finalise and unlock, so a run can be checked before it is finalised
- The .NET client is regenerated from the API, with commits on 52 separate days between 10 July and 8 October 2026
Weaknesses
- An API key carries the whole access of the user who generated it. No per-key scopes were found
- No idempotency keys in the spec or guides, and 5 requests a second per key and IP address is the only documented limit
- No changelog, versioning policy or deprecation policy was found for the Payroll API
- Only 13 of 460 schema definitions in the Australian spec list required fields, and 711 of 728 operations document a 200 response and little else
- The developer forum's recent topics include spam, and several API questions from 2024 and 2025 show no replies
Before you call it notes for agents
- Send the API key as the Basic auth username with a blank password, for example
curl -u {api_key}: https://api.yourpayroll.com.au/api/v2/user - Pick the Swagger file for the business's region (
swagger-au.json,swagger-nz.json,swagger-uk.json,swagger-sg.json,swagger-my.json). Paths and models differ by region - Stay under 5 requests a second per key and IP address. A 429 answered our test with
retry-after: 1 - Page lists with
$skipand$top(100 at most). Filter property names are capitalised, unlike the camelCase JSON - Read
GET /api/v2/business/{businessId}/payrun/{payRunId}/warningsbeforePOST .../finalise. Finalise can lodge with the tax office and publish pay slips in the same call
Who's behind it provenance 71/100
- Legal entity namedEmployment Hero Pty Ltd20/20
- Domain ageemploymenthero.com, registered 2012-05-02 (14 years)15/15
- Endpoint on the vendor's domain is not on employmenthero.com0/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 1 clause that costs points7.1/10
- Privacy policyread, states 7 of the 8 things a reader expects9.3/10
- Status pagestatus.employmenthero.com10/10
- Changelognot found0/10
- security.txtvalid10/10
Terms and privacy, as read
Terms of service gives no date, states 6 of 7, 1 to know
TL;DR Gives no date. States 6 of the 7 things a reader expects. To know before relying on it, limits on automated access.
Restricts automated accesscosts points
develop, support or use software, scripts, robots or any other means or processes to scrape or otherwise copy information from the EH Platform in a way that breaches another EH Platform Rule or our EH Platform Terms;
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of New South Wales, with disputes in the courts of New South Wales, Australia
6.1 If you are based in Australia, or any region not mentioned below – the EH Platform Terms will be governed by the laws of New South Wales, Australia, and the parties will be subject to the exclusive jurisdiction of the courts of New South Wales, Australia
Says where a dispute would be heard and under whose law.
States a limit on its liability
Our liability for breach of any such non-excludable warranty, guarantee or other right is limited to (at our option) either replacing or paying the cost of replacing the relevant service (unless the law requires otherwise).
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
If the change to the EH Platform or the EH Platform Terms is unacceptable to you, you may stop using the EH Platform, cancel your Subscription or terminate your account in accordance with the EH Platform Terms.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Gives 30 days of notice before a change
For any upgrade or downgrade in your plan or Subscription level (which must be made with at least 30 days notice), you will be invoiced for the new rate on your next billing cycle.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
If you don’t agree with these General Terms, then you must not use the EH Platform.
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
AI Services are not subject to any service level commitments that apply to other EH Platform services.
Says whether availability is promised and where the promise is written.
The customer is solely responsible for the outcome of any action the vendor's AI functions suggest or carry out once the customer approves it or lets it run.
You are solely responsible for the outcomes of any AI Action that you (as an Organisation or as a User) approve, confirm, initiate, or allow to execute.
Noted by a second reader on 2026-10-08.
Users must not share login credentials with anyone else or let more than one individual use a single user account.
share your login credentials with any other person or allow multiple individuals to access the EH Platform using a single User Account;
Noted by a second reader on 2026-10-08.
The liability limit does not apply to liabilities arising from the customer's indemnities or from the customer's breach of the platform rules.
The exclusion of liability under clause 28 does not apply to liabilities arising out of your indemnification obligations in these General Terms or your breach of the EH Platform Rules.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 12,675 words
Privacy policy gives no date, states 7 of 8, 1 to know
TL;DR Gives no date. States 7 of the 8 things a reader expects. To know before relying on it, selling or sharing data for advertising.
Says it sells personal data or shares it for advertising
We may share certain data such as device identifiers and usage data with advertising and analytics partners in ways that may constitute ‘sharing’ under the CCPA for cross-context behavioural advertising.
Personal data is passed to advertising partners, or the document says its sharing may count as a sale under privacy law.
Gives the date it was last updated
Not found in the text.
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
This Privacy Policy explains how we collect, use, and share your Personal Data, and the data protection rights that apply to you.
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
We retain data for as long as necessary to provide our Services and in accordance with our internal Data Retention Policy.
Says when data sent to the service is deleted.
Says who else receives the data
Location information including specific location information you provide us via your device using GPS, wireless, or Bluetooth technology, including IP addresses and information about your internet service provider, computer and device information like device, application, or browser type and version, and location info…
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
We may share certain data such as device identifiers and usage data with advertising and analytics partners in ways that may constitute ‘sharing’ under the CCPA for cross-context behavioural advertising.
A plain statement either way.
Says what rights people have over their data
You have a right to opt out of direct marketing at any time.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@employmenthero.com
If you are a parent or guardian and believe your child has provided us with Personal Data, or if you become aware that a minor has accessed our Services, please contact us at privacy@employmenthero.com.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
…section 5 above) for the purposes described in section 7 above to another country by relying on the EU Standard Contractual Clauses for the transfers from the EU, or the International Data Transfer Agreement or International Data Transfer Addendum to the EU Standard Contractual Clauses for the transfers from the UK, o…
The countries data goes to and the safeguard used.
The document · read 2026-10-08 · 9,336 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The General Terms (effective 15 June 2026) name Employment Hero Pty Ltd and its affiliates, and define the EH Platform to include products reached through its APIs. They are the platform terms, and no separate API terms were found.
The privacy policy is effective 3 June 2026 and points to a Data Processing Addendum effective 15 June 2026 at https://employmenthero.com/legals/privacy-policy/data-processing/.
The API answers at api.yourpayroll.com.au and the documentation at api.keypay.com.au, both off employmenthero.com. RDAP for yourpayroll.com.au names the registrar only, so we could not confirm the registrant.
https://employmenthero.com/.well-known/security.txt gives vuln@employmenthero.com, a policy link and an expiry of 31 December 2026.
RDAP for employmenthero.com gives a registration date of 2012-05-02 and GoDaddy.com, LLC as registrar.
No changelog for the Payroll API was found on the documentation site.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 21:06 UTC
- Vendor status page all systems normal, All Systems Operational · 6 minutes ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/employment-hero.json
Notable
- The docs site lists a Swagger 2.0 file per region, and each downloads without a login. Operations per file, 728 Australia, 660 New Zealand, 821 United Kingdom, 695 Singapore, 679 Malaysia source
- All operations are prefixed by https://api.yourpayroll.com.au/api/v2, and a white label uses its own host such as https://keypay.yourpayroll.com.au source
- OAuth 2.0 client credentials are issued after a support request with the application's name, callback URL and logo. Access tokens last 24 hours and refresh tokens 28 days source
- The usage guide limits the API to 5 requests per second per API key per IP address source
POST /api/v2/business/{businessId}/payrun/{payRunId}/finalisetakes options to lodge the pay run, publish pay slips and export journals, each Manual, Immediate or Scheduled source- Brand, reseller and white label endpoints create businesses and users, and three single sign-on endpoints return a one-use URL valid for 5 minutes for embedding the payroll screens source
- Employment Hero's HR platform has a separate API with its own documentation, OAuth flow and rate limits, which this listing does not grade source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 13.0 | |
Read with the hosted lines. https://status.employmenthero.com is a Statuspage with Login, Create Pay Run, Finalise Pay Run and Create Employee components for each of five payroll regions and incident history. No component names the Payroll API (20). Between 10 July and 8 October 2026 it lists two payroll incidents. On 21 July pay runs did not load employee data for businesses with a deleted leave category still referenced in a pay run, marked major and resolved in 2 hours 3 minutes. On 2 September employees could not be removed from a pay run, marked no impact, with a fix posted 5 minutes after the notice. One major that touched a subset of businesses sits between the minor and one-major lines (15 of 30). Four further incidents in the window are on HR Software, a separate product. 5 requests a second per API key per IP address (15). The usage guide says only to space calls out. Our unauthenticated test saw a 429 with retry-after: 1 and x-rate-limit headers, which the docs don't describe, and no idempotency keys were found (5 of 15). No SLA found in the General Terms or the docs (0). The API is at v2 with no beta label (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 8.3 | |
A Swagger 2.0 file for each of five regions, public and without a login, 728 operations and 460 definitions for Australia (25). No llms.txt or Markdown twin on the documentation site. employmenthero.com/llms.txt indexes marketing pages only (0). 713 of 728 Australian operations have a description, most of one sentence, such as noting OData support or that a pay run can't be finalised while calculations run. None say when not to use an operation (8 of 20). Every request body references a named model and 269 of 4,461 properties carry enums, but only 13 of 460 definitions list required fields and dates are plain date-time strings (9 of 15). The guides have curl and HTTP examples for both auth routes and OData. 711 of 728 operations document a 200 response, 131 a 400 and 136 a 404, with a ProblemDetails model, and no example bodies (5 of 15). The path carries v2. No API changelog was found, and the .NET client documents one set of breaking changes (4 of 15). | |||
| Agent ergonomics | 13%16.2 | 8.6 | |
$top caps lists at 100 and $select trims fields on the Employee API only. Summary endpoints exist for pay runs (15 of 25). OData $skip, $top, $orderby and $filter on most GET operations (20). Some operations return ProblemDetails. 401 and 429 answered our test as plain text, and the docs have no error catalogue (8 of 20). No idempotency keys. Employees and several other resources can be looked up by externalId, which lets a caller check before repeating a create. This is an HTTP API with no MCP annotations to read (4 of 20). One official client, for .NET. Creating a pay run needs a pay schedule, a period end and a paid date (6 of 15). | |||
| Security & auth | 14%17.5 | 8.1 | |
An API key generated under My Account, sent as the Basic auth username, and replaced with Change API Key. It carries its user's access. OAuth 2.0 authorisation code grant with 24-hour access tokens, 28-day refresh tokens and a revoke endpoint. The spec names read and write scopes, while the guide's sample token shows an empty scope (22 of 30). Business access can be Restricted to employee groups and locations, a user can be created as apiOnly, and pay runs have an approval start endpoint. Nothing holds a finalise call for confirmation (10 of 20). The API returns notes and other text written by employees and managers, with no guidance on treating it as untrusted (3 of 15). Employee audit and pay run audit reports are in the spec, and responses carry x-correlation-id. No per-call log for the operator was found (5 of 15). security.txt is valid until 31 December 2026 and links a Vulnerability Disclosure Policy v1.2. The trust centre is script-drawn and unread, so certifications and any bounty are unconfirmed (6 of 20). | |||
| Payments & pricing | 10%12.5 | 1.2 | |
| Read with the hosted rubric. No x402, MPP or L402 (0). The Australian pricing page lists the Payroll plan at $10 with conditions and a minimum of 10 users, and says prices are AUD ex. GST in its plan disclaimers. That is public plan pricing with no per-call charge (10). No free tier or trial for Payroll was found on the pages read. The two-week free trial in the partner guide is for an HR organisation (0). A person signs up and generates the key in the browser (0). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 6.0 | |
| The .NET client repository, generated from the API, has a build commit on 8 October 2026, and the swagger files were last modified on 28 August 2026 (30). The repository has commits on 52 separate days since 10 July, and NuGet shows 62 package versions published in the same period (20). Closed service with no API changelog. The developer forum's front page shows spam topics and API questions from 2024 and 2025 with no replies (4 of 15). One current official client. NuGet stops at 3.0.0.969 from 2 September while the repository is at build 3.0.0.1025 (10 of 15). The client repository has no CI workflow, and its test folder holds a sample application (4 of 10). | |||
| Transparency & trusteditorial 49, provenance 71 | 7%8.8 | 5.2 | |
| Closed service. General Terms effective 15 June 2026 name Employment Hero Pty Ltd and cover access through its APIs. The .NET client is MIT (15 of 30). The privacy policy (3 June 2026) and the DPA (15 June 2026) agree on processor and controller roles, say personal data is not used to train AI models, and name storage in Australia, Ireland and Canada. Retention is 'as long as necessary' under an internal policy, with no periods (20 of 30). No deprecation policy or dated notices were found for the Payroll API (2 of 20). The DPA gives data centre locations by region and 30 days to object to a new sub-processor. The sub-processor list sits on a trust centre our reader could not read (12 of 20). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 50.4 · D | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 23 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Employment Hero Payroll, or have the agent fetch /fixes/employment-hero.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Employment Hero Payroll
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/employment-hero, the October 2026 research run, assessed 8 October 2026. Grade D, 50.4 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on Employment Hero Payroll: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Payments & pricing, 10 out of 100, up to 11.3 more on the total
Why it scored 10: Read with the hosted rubric. No x402, MPP or L402 (0). The Australian pricing page lists the Payroll plan at $10 with conditions and a minimum of 10 users, and says prices are AUD ex. GST in its plan disclaimers. That is public plan pricing with no per-call charge (10). No free tier or trial for Payroll was found on the pages read. The two-week free trial in the partner guide is for an HR organisation (0). A person signs up and generates the key in the browser (0).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## 2. Security & auth, 46 out of 100, up to 9.5 more on the total
Why it scored 46: An API key generated under My Account, sent as the Basic auth username, and replaced with Change API Key. It carries its user's access. OAuth 2.0 authorisation code grant with 24-hour access tokens, 28-day refresh tokens and a revoke endpoint. The spec names `read` and `write` scopes, while the guide's sample token shows an empty scope (22 of 30). Business access can be Restricted to employee groups and locations, a user can be created as `apiOnly`, and pay runs have an approval start endpoint. Nothing holds a finalise call for confirmation (10 of 20). The API returns notes and other text written by employees and managers, with no guidance on treating it as untrusted (3 of 15). Employee audit and pay run audit reports are in the spec, and responses carry `x-correlation-id`. No per-call log for the operator was found (5 of 15). security.txt is valid until 31 December 2026 and links a Vulnerability Disclosure Policy v1.2. The trust centre is script-drawn and unread, so certifications and any bounty are unconfirmed (6 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 3. Schema & documentation, 51 out of 100, up to 8 more on the total
Why it scored 51: A Swagger 2.0 file for each of five regions, public and without a login, 728 operations and 460 definitions for Australia (25). No llms.txt or Markdown twin on the documentation site. employmenthero.com/llms.txt indexes marketing pages only (0). 713 of 728 Australian operations have a description, most of one sentence, such as noting OData support or that a pay run can't be finalised while calculations run. None say when not to use an operation (8 of 20). Every request body references a named model and 269 of 4,461 properties carry enums, but only 13 of 460 definitions list required fields and dates are plain date-time strings (9 of 15). The guides have curl and HTTP examples for both auth routes and OData. 711 of 728 operations document a 200 response, 131 a 400 and 136 a 404, with a `ProblemDetails` model, and no example bodies (5 of 15). The path carries v2. No API changelog was found, and the .NET client documents one set of breaking changes (4 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## 4. Agent ergonomics, 53 out of 100, up to 7.6 more on the total
Why it scored 53: `$top` caps lists at 100 and `$select` trims fields on the Employee API only. Summary endpoints exist for pay runs (15 of 25). OData `$skip`, `$top`, `$orderby` and `$filter` on most GET operations (20). Some operations return `ProblemDetails`. 401 and 429 answered our test as plain text, and the docs have no error catalogue (8 of 20). No idempotency keys. Employees and several other resources can be looked up by `externalId`, which lets a caller check before repeating a create. This is an HTTP API with no MCP annotations to read (4 of 20). One official client, for .NET. Creating a pay run needs a pay schedule, a period end and a paid date (6 of 15).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 5. Reliability, 65 out of 100, up to 7 more on the total
Why it scored 65: Read with the hosted lines. https://status.employmenthero.com is a Statuspage with Login, Create Pay Run, Finalise Pay Run and Create Employee components for each of five payroll regions and incident history. No component names the Payroll API (20). Between 10 July and 8 October 2026 it lists two payroll incidents. On 21 July pay runs did not load employee data for businesses with a deleted leave category still referenced in a pay run, marked major and resolved in 2 hours 3 minutes. On 2 September employees could not be removed from a pay run, marked no impact, with a fix posted 5 minutes after the notice. One major that touched a subset of businesses sits between the minor and one-major lines (15 of 30). Four further incidents in the window are on HR Software, a separate product. 5 requests a second per API key per IP address (15). The usage guide says only to space calls out. Our unauthenticated test saw a 429 with `retry-after: 1` and `x-rate-limit` headers, which the docs don't describe, and no idempotency keys were found (5 of 15). No SLA found in the General Terms or the docs (0). The API is at v2 with no beta label (10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 6. Transparency & trust, 60 out of 100, up to 3.5 more on the total
Made of editorial 49, provenance 71.
Why it scored 60: Closed service. General Terms effective 15 June 2026 name Employment Hero Pty Ltd and cover access through its APIs. The .NET client is MIT (15 of 30). The privacy policy (3 June 2026) and the DPA (15 June 2026) agree on processor and controller roles, say personal data is not used to train AI models, and name storage in Australia, Ireland and Canada. Retention is 'as long as necessary' under an internal policy, with no periods (20 of 30). No deprecation policy or dated notices were found for the Payroll API (2 of 20). The DPA gives data centre locations by region and 30 days to object to a new sub-processor. The sub-processor list sits on a trust centre our reader could not read (12 of 20).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Endpoint on the vendor's domain: is not on employmenthero.com (0 of 15)
- Terms of service: read, states 6 of the 7 things a reader expects, and has 1 clause that costs points (7.1 of 10)
- Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10)
- Changelog: not found (0 of 10)
## 7. Maintenance & community, 68 out of 100, up to 2.8 more on the total
Why it scored 68: The .NET client repository, generated from the API, has a build commit on 8 October 2026, and the swagger files were last modified on 28 August 2026 (30). The repository has commits on 52 separate days since 10 July, and NuGet shows 62 package versions published in the same period (20). Closed service with no API changelog. The developer forum's front page shows spam topics and API questions from 2024 and 2025 with no replies (4 of 15). One current official client. NuGet stops at 3.0.0.969 from 2 September while the repository is at build 3.0.0.1025 (10 of 15). The client repository has no CI workflow, and its test folder holds a sample application (4 of 10).
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- unchecked: the trust centre at trust.employmenthero.com and its sub-processor page are script-drawn and showed our reader a title only, so certifications, penetration testing, any bounty and the sub-processor list are unconfirmed
- unchecked: the body of the Vulnerability Disclosure Policy v1.2 linked from security.txt, a Google document that showed our reader its title only
- unchecked: the official MCP registry search answered 500, so presence of any Employment Hero server there is unconfirmed. No MCP server was found on the vendor's pages read
- unchecked: open issues and replies on Thinkei/keypay-dotnet-v2, which aren't in a git clone. The GitHub API reports one open issue
- Whether Employment Hero Payroll has a free trial or sandbox of its own. None was found on the pricing page or the API docs, and the free trial in the partner guide is for an HR organisation
- The unit behind the Payroll plan's $10. The page shows the figure with a 10-user minimum and billing by user count, and states AUD ex. GST in plan disclaimers, but the per-user wording sits in script-drawn tooltips we did not read in full
- Whether OAuth tokens can be limited to `read`. The spec names `read` and `write` scopes under an implicit flow, while the guide describes the authorisation code grant and shows an empty scope
- Which API host serves each region. The docs name api.yourpayroll.com.au, the client README uses a United Kingdom host, and api.yourpayroll.co.uk, api.yourpayroll.io and api.nzpayroll.co.nz each answered 401 to our test
- Whether a customer agreement includes an SLA. None is in the public General Terms
- The 429 `retry-after` header and `x-rate-limit` headers were seen on unauthenticated calls and aren't in the docs, so their behaviour for authenticated calls is unconfirmed
- The registrant of yourpayroll.com.au and keypay.com.au. RDAP names only the registrar
- The star count is for Thinkei/keypay-dotnet-v2. The API has no public repository of its own
## Weaknesses
- An API key carries the whole access of the user who generated it. No per-key scopes were found
- No idempotency keys in the spec or guides, and 5 requests a second per key and IP address is the only documented limit
- No changelog, versioning policy or deprecation policy was found for the Payroll API
- Only 13 of 460 schema definitions in the Australian spec list required fields, and 711 of 728 operations document a 200 response and little else
- The developer forum's recent topics include spam, and several API questions from 2024 and 2025 show no replies
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Send the API key as the Basic auth username with a blank password, for example `curl -u {api_key}: https://api.yourpayroll.com.au/api/v2/user`
- Pick the Swagger file for the business's region (`swagger-au.json`, `swagger-nz.json`, `swagger-uk.json`, `swagger-sg.json`, `swagger-my.json`). Paths and models differ by region
- Stay under 5 requests a second per key and IP address. A 429 answered our test with `retry-after: 1`
- Page lists with `$skip` and `$top` (100 at most). Filter property names are capitalised, unlike the camelCase JSON
- Read `GET /api/v2/business/{businessId}/payrun/{payRunId}/warnings` before `POST .../finalise`. Finalise can lodge with the tax office and publish pay slips in the same call
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the trust centre at trust.employmenthero.com and its sub-processor page are script-drawn and showed our reader a title only, so certifications, penetration testing, any bounty and the sub-processor list are unconfirmed
- unchecked: the body of the Vulnerability Disclosure Policy v1.2 linked from security.txt, a Google document that showed our reader its title only
- unchecked: the official MCP registry search answered 500, so presence of any Employment Hero server there is unconfirmed. No MCP server was found on the vendor's pages read
- unchecked: open issues and replies on Thinkei/keypay-dotnet-v2, which aren't in a git clone. The GitHub API reports one open issue
- Whether Employment Hero Payroll has a free trial or sandbox of its own. None was found on the pricing page or the API docs, and the free trial in the partner guide is for an HR organisation
- The unit behind the Payroll plan's $10. The page shows the figure with a 10-user minimum and billing by user count, and states AUD ex. GST in plan disclaimers, but the per-user wording sits in script-drawn tooltips we did not read in full
- Whether OAuth tokens can be limited to
read. The spec namesreadandwritescopes under an implicit flow, while the guide describes the authorisation code grant and shows an empty scope - Which API host serves each region. The docs name api.yourpayroll.com.au, the client README uses a United Kingdom host, and api.yourpayroll.co.uk, api.yourpayroll.io and api.nzpayroll.co.nz each answered 401 to our test
- Whether a customer agreement includes an SLA. None is in the public General Terms
- The 429
retry-afterheader andx-rate-limitheaders were seen on unauthenticated calls and aren't in the docs, so their behaviour for authenticated calls is unconfirmed - The registrant of yourpayroll.com.au and keypay.com.au. RDAP names only the registrar
- The star count is for Thinkei/keypay-dotnet-v2. The API has no public repository of its own
Sources 29
- documentation index and regional spec list api.keypay.com.au · seen 2026-10-08
- API home guide, base URL and forum link api.keypay.com.au · seen 2026-10-08
- API key authentication api.keypay.com.au · seen 2026-10-08
- OAuth 2.0 guide, token lifetimes and credential request api.keypay.com.au · seen 2026-10-08
- usage limits api.keypay.com.au · seen 2026-10-08
- OData filtering and paging api.keypay.com.au · seen 2026-10-08
- single sign-on guide api.keypay.com.au · seen 2026-10-08
- Swagger 2.0 file, Australia api.keypay.com.au · seen 2026-10-08
- Swagger 2.0 file, United Kingdom api.keypay.com.au · seen 2026-10-08
- Swagger 2.0 file, New Zealand api.keypay.com.au · seen 2026-10-08
- Swagger 2.0 file, Singapore api.keypay.com.au · seen 2026-10-08
- Swagger 2.0 file, Malaysia api.keypay.com.au · seen 2026-10-08
- finalise pay run reference api.keypay.com.au · seen 2026-10-08
- create pay run reference api.keypay.com.au · seen 2026-10-08
- unauthenticated call to the API (401, 429 and headers) api.yourpayroll.com.au · seen 2026-10-08
- status incidents status.employmenthero.com · seen 2026-10-08
- status components status.employmenthero.com · seen 2026-10-08
- pricing page, Australian edition employmenthero.com · seen 2026-10-08
- General Terms, effective 15 June 2026 employmenthero.com · seen 2026-10-08
- privacy policy, effective 3 June 2026 employmenthero.com · seen 2026-10-08
- Data Processing Addendum, effective 15 June 2026 employmenthero.com · seen 2026-10-08
- security.txt employmenthero.com · seen 2026-10-08
- trust centre (title only, script-drawn) trust.employmenthero.com · seen 2026-10-08
- .NET client versions on NuGet api.nuget.org · seen 2026-10-08
- .NET client repository, commits and README github.com · seen 2026-10-08
- developer forum front page developers.yourpayroll.com.au · seen 2026-10-08
- HR API partner guides, trial and separate API developer.employmenthero.com · seen 2026-10-08
- HR API reference, separate rate limits developer.employmenthero.com · seen 2026-10-08
- RDAP for employmenthero.com rdap.org · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid Paid No charge for API calls was found. Access comes with an Employment Hero Payroll subscription. The Australian pricing page lists the Payroll plan at $10 with conditions, a minimum of 10 users and billing by user count, with prices stated as AUD ex. GST in the page's disclaimers. Employment Unlimited, which includes Payroll, is priced through sales. No free tier, trial or sandbox for Payroll was found on the pages read, so an agent starts only where a paying account exists (checked 2026-10-08).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/employment-hero.xml, or this listing's score history at history.json.
Connect
Install
Install-Package KeyPayV2
First request
curl -u {api_key}: https://api.yourpayroll.com.au/api/v2/user
Through letme picks today, calling later
GET https://letme.dev/employment-hero
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Gusto BCheck BEveree CSalsa DZeal EFinch BB
Head to head Argyle vs Employment Hero Payroll · Employment Hero Payroll vs Finch · Employment Hero Payroll vs Paychex · Check vs Employment Hero Payroll · Employment Hero Payroll vs Everee · Employment Hero Payroll vs Gusto · Employment Hero Payroll vs Salsa · Employment Hero Payroll vs Zeal
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Gusto Gusto, Inc. | B | 63.3 | payroll.run payroll.employees payroll.embedded payroll.tax-filing payroll.contractors hr.time-off | no |
| Check Check Technologies, Inc. | B | 67.5 | payroll.run payroll.employees payroll.embedded payroll.tax-filing payroll.contractors | no |
| Everee Everee, Inc. | C | 55.1 | payroll.run payroll.embedded payroll.employees payroll.contractors payroll.tax-filing | no |
| Salsa Salsa Software Inc. | D | 46.1 | payroll.run payroll.embedded payroll.employees payroll.tax-filing payroll.contractors | no |
| Zeal Puzzl Group Inc. | E | 45.4 | payroll.run payroll.embedded payroll.employees payroll.contractors payroll.tax-filing | no |
| Finch Profound Platform Inc. (dba Finch) | BB | 71.6 | payroll.employees payroll.contractors | no |
Machine-readable
- JSON
/api/v1/tools/employment-hero.json· historyhistory.json· badge/badges/employment-hero.svg· changes feed/feeds/tools/employment-hero.xml - Markdown
/tools/employment-hero.md· slim/tools/employment-hero.min.md(or sendAccept: text/markdown) - Fix list
/fixes/employment-hero.md·/fixes/employment-hero.json - From a terminal
anchor tool employment-hero --md(the CLI) · over MCPget_tool {"slug": "employment-hero"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/employment-hero"><img src="https://www.anchorterminal.com/badges/employment-hero.svg" alt="Employment Hero Payroll on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/employment-hero)<a href="https://www.anchorterminal.com/tools/employment-hero">Employment Hero Payroll on Anchor Terminal</a>It counts on a page on employmenthero.com or one of its subdomains, or the README of github.com/Thinkei/keypay-dotnet-v2.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "employment-hero", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.


