# Greenhouse (slim) > Applicant tracking system from Greenhouse Software in New York. The Harvest v3 REST API reads and writes jobs, candidates, applications, interviews, scorecards and offer records, and a hosted MCP server in open beta exposes a subset of it. - Full: https://www.anchorterminal.com/tools/greenhouse.md (~7,700 tokens) · this version ~2,030 tokens · JSON https://www.anchorterminal.com/tools/greenhouse.json · canonical https://www.anchorterminal.com/tools/greenhouse - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 64.8/100 · rank #248 of 629 · #1 in Recruiting & applicant tracking · not agent-ready · confidence medium** Assessment: Harvest v3 pairs per-endpoint OAuth scopes with Markdown docs that embed an OpenAPI 3.1 definition for each call, and the beta MCP server blocks every DELETE. Access needs a paying customer account, with no public price, trial or self-serve sandbox, and no numeric rate limit or idempotency key was found in the reviewed documentation. ## Facts - Kind: HTTP API · vendor: Greenhouse Software, Inc. · category: Recruiting & applicant tracking · legal entity: Greenhouse Software, Inc. · provenance 90/100 - Endpoint: `https://harvest.greenhouse.io/v3` (HTTP) - Auth: OAuth · pricing: Paid · x402: no · licence: Proprietary service under Greenhouse's Master Subscription Agreement. The docs repository for the older APIs on GitHub is Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Surface graded: Harvest v3 REST API at https://harvest.greenhouse.io/v3, generally available. The Greenhouse MCP server is described from its help centre articles and is in open beta - API: 179 reference pages (74 GET, 54 POST, 26 PATCH, 23 DELETE, 2 PUT) covering applications, candidates, jobs, job posts, interviews, scorecards, offer records, approvals, users and custom fields. OpenAPI 3.1 per endpoint, info version v3 - Credentials: OAuth 2.0 client credentials for a customer's own integration, created under API Credentials in Greenhouse with chosen scopes. OAuth 2.0 authorisation code grant for partners (access token 1 hour, refresh token 14 days). Scopes per endpoint, such as `harvest:candidates:list` - Rate limits: Fixed 30-second window, with the limit returned in `X-RateLimit-Limit` (the docs' example shows 75). Token requests use a separate 60-second window. 429 carries `Retry-After`. Audit Log API 50 requests per 10 seconds and 3 paginated requests per 30 seconds - Pagination: Cursor in the `Link` header (`rel="next"` only), `per_page` default 100, maximum 500, ordered by id descending - Errors: 401, 403, 422 and 429 with a JSON body of `message` and an `errors` array, shown in the guides. Reference pages list status codes without bodies - MCP server: https://mcp.greenhouse.io/mcp (the Claude Code and ChatGPT steps use https://mcp.us.greenhouse.io/mcp), hosted in the US. A subset of Harvest v3 as tools. OAuth 2.0 with PKCE and dynamic client registration, redirect URLs checked against an allowlist. Named tools are Claude, ChatGPT, Google Antigravity, Glean, Copilot Studio, Amazon Q and Grok - MCP controls: Site Admins set the scope ceiling under Dev Centre > MCP Access. Seven read-only scopes by default. DELETE blocked. Five actions need human confirmation. Access tokens last one hour, refresh tokens until 14 days of inactivity - Audit: Audit Log API (a paid add-on) keeps thirty days of events, with types `harvest_access`, `mcp_access` and `mcp_tool_call`, the OAuth client, the authorising user and redacted arguments - Webhooks: Recruiting webhooks signed with HMAC SHA-256 in a `Signature` header, up to 7 attempts over about 15 hours - Sandbox: A sandbox environment is a Pro-tier feature per the help centre. No self-serve developer account found - Certifications: SOC 1 Type II, SOC 2 Type II, ISO 27001:2022, ISO 27701:2019 and ISO 42001:2023 per greenhouse.com/security and trust.greenhouse.com. Bug bounty on HackerOne, annual third-party penetration tests - Status: status.greenhouse.io on Statuspage, with a Greenhouse Harvest API component and per-silo components - Sub-processors: Public list with purposes and locations at greenhouse.com/subprocessors-in-use. AWS hosting in the United States, Germany and Australia - Scores: Reliability 71, Performance pending, Schema & documentation 79, Agent ergonomics 63, Security & auth 85, Payments & pricing 0, Task success pending, Maintenance & community 65, Transparency & trust 79 · total over the 7 assessed categories - Why: Reliability, Read with the hosted rubric, for the Harvest v3 API. · Schema & documentation, Every v3 reference page has a Markdown twin with an OpenAPI 3.1 definition for that endpoint. · Agent ergonomics, `per_page` runs from 1 to 500 and v3 no longer embeds child records in parents, but no field selection was found (15). · Security & auth, OAuth 2.0 with a scope per endpoint, client credentials or the authorisation code grant, one-hour partner access tokens and secret rotation… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The Harvest v3 changelog showed an entry about four hours old when read on 7 October 2026 (30). · Transparency & trust, Closed service with a public Master Subscription Agreement last updated 1 February 2026, and an Apache-2.0 docs repository (15). - Sources: 22, open questions: 7, both in the full twin - Capabilities: recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters - JSON: https://www.anchorterminal.com/api/v1/tools/greenhouse.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/greenhouse.svg` or a link to https://www.anchorterminal.com/tools/greenhouse from a page on greenhouse.com or one of its subdomains, or the README of github.com/grnhse/greenhouse-api-docs, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Request a token from https://auth.greenhouse.io/token with client credentials, then send it as a Bearer token to https://harvest.greenhouse.io/v3. Tokens expire, so repeat on 401 2. Put filters and `per_page` on the first list request only. A `cursor` must be the only query parameter, or the call returns 422 3. Send the current stage as `from_stage_id` when moving an application. It guards against stale moves. Other writes have no idempotency key, so check before retrying 4. Read `X-RateLimit-Remaining` on every response and wait for `Retry-After` on 429. The window is 30 seconds 5. Expect empty list results or 403 unless the token's user is a Site Admin with the needed permissions ## Connect ```bash curl --location 'https://harvest.greenhouse.io/v3/job_posts' \ --header 'Authorization: Bearer <>' ``` ```bash claude mcp add greenhouse --transport http https://mcp.us.greenhouse.io/mcp ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/greenhouse ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Ashby | C | 61.3 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters | https://www.anchorterminal.com/tools/ashby.min.md | | SmartRecruiters | C | 60.4 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters | https://www.anchorterminal.com/tools/smartrecruiters.min.md | | Lever | D | 53.6 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters | https://www.anchorterminal.com/tools/lever.min.md | | Workable | C | 61.7 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.offer-letters | https://www.anchorterminal.com/tools/workable.min.md | | BambooHR | C | 61.7 | recruiting.applications, recruiting.jobs | https://www.anchorterminal.com/tools/bamboohr.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)