# HiBob > Bob is HiBob's HR platform for employee records, time off, attendance, tasks, documents and hiring. Agents reach it through a REST API authenticated with service users, 30 webhook events and a hosted MCP server that uses OAuth. - Canonical: https://www.anchorterminal.com/tools/hibob - Markdown: https://www.anchorterminal.com/tools/hibob.md (~7,250 tokens) - Slim: https://www.anchorterminal.com/tools/hibob.min.md (~1,930 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/hibob.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade C · 57/100 · rank #429 of 629 · #4 in HR & employee operations · not agent-ready · confidence medium** ## Assessment Service users start with no permissions and gain view or edit rights per field, and the docs are served as Markdown with an OpenAPI definition on each endpoint page. There is no public price, trial or free sandbox, so an agent needs a paying customer's admin to issue credentials. No idempotency keys or official SDKs were found. ## Facts | Field | Value | | --- | --- | | Vendor | Hi Bob Ltd. (https://www.hibob.com) | | Kind | HTTP API | | Category | HR & employee operations (https://www.anchorterminal.com/categories/hr) | | Transport | HTTP | | Endpoint | `https://api.hibob.com/v1` | | Auth | OAuth or key · Access is granted by a customer's Bob admin, with no self-serve route for outsiders. Customer-built integrations use a service user, an ID and token sent as HTTP Basic, which starts with no permissions and gains them through a permission group (product areas, fields by View, View history and Edit, and which employees). OAuth 2.0 authorisation code apps are open only to approved Marketplace and technology partners through the Developer Portal, with 28 scopes, an audience the customer chooses at install, 5-minute access tokens and 30-day refresh tokens. The hosted MCP server uses OAuth as the signed-in employee and follows that person's Bob permissions. | | Pricing | Paid (Paid) · No public prices. HiBob quotes per employee by company size and chosen modules, and the pricing page asks for a demo or a custom quote. No free tier or trial was found. The API sandbox at api.sandbox.hibob.com is available only to accounts that have bought the Sandbox module, so an agent cannot start without a customer contract (https://www.hibob.com/pricing-plans, checked 2026-10-07). | | x402 | No · No x402, MPP or L402 in the developer docs, the API terms or the pricing page (checked 2026-10-07). | | Licence | Proprietary service under HiBob's customer subscription terms and API Terms of Use | | Docs | https://apidocs.hibob.com | | llms.txt | https://apidocs.hibob.com/llms.txt | | Last release | 2026-10-07 | | Surface graded | The public REST API at https://api.hibob.com/v1 with service-user credentials. The hosted MCP server is noted but its tool documentation could not be read | | API coverage | 265 reference entries across employee data, employee and custom tables, time off, attendance and projects, tasks, reports, documents, goals, skills, job catalogue, employers, workforce planning and hiring, 30 of them webhook events | | Credentials | Service user ID and token over HTTP Basic for customer integrations. OAuth 2.0 authorisation code for approved Marketplace partners, with 5-minute access tokens, 30-day refresh tokens and 28 scopes such as employee_data:read and timeoff:write | | Permissions | Service users start with none. Permission groups grant product areas, people's data by category or field (View, View history, Edit) and the set of employees covered. Sensitive fields need both View and Edit to be returned | | MCP server | Hosted, released 28 April 2026 with service users and moved to OAuth per employee from June 2026 in a gradual rollout. HiBob lists ChatGPT, Claude.ai, Claude Desktop and Cursor as clients. An admin enables it in Bob | | Rate limits | Per endpoint per minute. People search 50, read employee by ID 100, update, create and terminate employee 10 each, public profiles 40. The Docs API has none at present. More than 50 responses of 401 or 403 in 10 seconds blocks the IP for 5 minutes | | Errors | 400, 401, 403, 404, 429 and 500 documented with JSON bodies whose shape varies by module. 429 carries Retry-After, X-RateLimit-Limit and X-RateLimit-Remaining. 304 means the submitted data matched the record | | Pagination | Cursor and limit (default 50, maximum 200) on bulk table, workforce planning and job catalogue endpoints. People search and read by ID are not paginated | | Webhooks | v2 events for employees, time off, tasks, documents and workforce planning. Payloads carry identifiers and changed-field metadata only. Signed, retried with exponential backoff for up to 3 days, then the webhook is deactivated | | Time off | Submit and cancel requests, read balances, policies, who's out and request changes, and create balance adjustments. No approve or decline endpoint is listed in the reference index | | Sandbox | https://api.sandbox.hibob.com/v1, available only to accounts that have bought the Sandbox module | | Audit | Bob has an API audit log of Public API usage, linked from the developer docs. The help centre article describing it returned 403 to our reader | | Certifications | SOC 2 Type II, ISO 27001:2022 and ISO 27018:2019 per hibob.com/privacy/security. Bug bounty on Bugcrowd. Hosted on AWS in Ireland with disaster recovery in Frankfurt | | Status | status.hibob.io on Statuspage, 46 components including Public API, Sandbox, Time Off, Docs and Tasks | | Sub-processors | List updated November 2025. AWS (EU), SingleStore (EU), Cloudinary, Cloudflare and Zendesk as core, with OpenAI and Microsoft Azure OpenAI for optional AI functions | | Capabilities | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | | Tags | hosted, enterprise, sales-led, api-key, oauth, mcp, llms-txt, openapi, webhooks, sandbox, status-page, bug-bounty, soc2 | | JSON | https://www.anchorterminal.com/api/v1/tools/hibob.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 67 | 13.4 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 78 | 12.7 | | Agent ergonomics | 13% | 16.2 | 47 | 7.6 | | Security & auth | 14% | 17.5 | 68 | 11.9 | | Payments & pricing | 10% | 12.5 | 0 | 0.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 59 | 5.2 | | Transparency & trust (editorial 58, provenance 83) | 7% | 8.8 | 71 | 6.2 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **57 → C** | ### Why each score - Reliability 67: Graded on the public REST API. Statuspage at status.hibob.io with 46 components, Public API among them (20). Nine incidents between 9 July and 7 October 2026. Three were major or critical on single modules (employee work tables failing to update for 4 hours 26 minutes on 31 August, Talent for 1 hour 9 minutes on 26 August, Workforce Planning on 4 August), and the Public API component is named once, for 2 hours 6 minutes of slowness on 3 August, which we scored between minor only and one major outage (12). Per-endpoint limits are published, such as 50 a minute on people search and 10 on employee updates (15). 429 carries Retry-After and X-RateLimit headers and the docs ask for backoff on 429 and 500, but no idempotency keys were found for writes (10). No SLA found, and the subscription terms disclaim uninterrupted service (0). The API is generally available, while the OAuth MCP server is in gradual rollout (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 78: Each endpoint and webhook page embeds an OpenAPI 3.1.1 definition in its Markdown version. No single downloadable spec was found (20). llms.txt and a .md twin of every page (10). Endpoint descriptions state permissions, supported user types and a list of critical behaviours such as no pagination and silent omission, though not when to choose another endpoint (15). Inputs are typed with enums (humanReadable APPEND or REPLACE) and limits (400 fields), but field IDs are free strings resolved through metadata endpoints (10). Request examples and documented 400, 403, 429 and default responses, with error bodies that differ by module (11). A /v1 path and a dated changelog with an RSS feed, with no per-entry dates in the Markdown twins (12). - Agent ergonomics 47: The `fields` array sizes people responses, but people search returns every matching employee in one response (13). Cursor pagination with a limit up to 200 covers bulk tables, workforce planning and the job catalogue only, and people search filters accept only `root.id` and `root.email` with equals (10). Status codes and recovery advice are documented (no retry on 400, stop on 401 and 403), but fields without permission vanish from a 200 response with no warning (12). No idempotency keys. 304 signals an unchanged record, and the MCP tool annotations could not be read (6). Few required parameters on reads. No official SDK found in the reviewed documentation (6). - Security & auth 68: Service users are separate, revocable credentials with no permissions by default and rights granted per feature, per field and per employee population. They travel as HTTP Basic. OAuth with 28 scopes, 5-minute access tokens and a customer-chosen audience exists for approved partners, and the MCP server uses OAuth as the signed-in employee (25). Field-level View and Edit make read-only service users possible. No confirmation step for terminate or delete calls was found (14). The API returns text written by employees, and no injection guidance was found. The MCP documentation was unreadable (2). Bob has an API audit log linked from the docs, whose article we could not open (10). SOC 2 Type II, ISO 27001:2022, ISO 27018:2019, third-party penetration tests and a Bugcrowd bounty. security.txt could not be checked (17). - Payments & pricing 0: No x402, MPP or L402 (0). Prices are by quote only (0). No free tier or trial found, and the sandbox is a purchased module (0). Credentials come from a customer's admin in the Bob interface, with no programmatic route (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 59: The newest developer changelog entry is dated 7 October 2026 (30). Ten entries between 21 July and 7 October, including new Employee Tables endpoints on 17 August and a Skills API on 5 August (20). A dated changelog with RSS and a support desk. No public issue tracker or developer forum was found (9). No official SDKs found, and the MCP registry could not be reached to check for an entry (0). No public packages or CI to assess (0). - Transparency & trust 71: Closed service with public API Terms of Use and customer subscription terms revised January 2026 (15). The subscription terms promise deletion of personal data within 30 days of termination and let HiBob use anonymised, aggregated customer data freely. The privacy policy excludes data processed for customers, and the DPA sits behind a DocuSign link we could not read (15). Past deprecations carried dates and four to seven months' notice (2023 and 2024), but the deprecations page was last updated in May 2025 and the API terms promise notice only where commercially reasonable (10). The sub-processor list (November 2025) names providers, purposes and locations, including OpenAI and Azure OpenAI for optional functions, and hosting is stated as AWS Ireland with Frankfurt for recovery (18). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/hibob.md (JSON https://www.anchorterminal.com/fixes/hibob.json) ### What we couldn't check - unchecked: the help centre article on the MCP server (server URL, tool list, annotations, confirmation of writes), which returned 403 - unchecked: www.hibob.com/.well-known/security.txt, which returned a Cloudflare block page - unchecked: the DPA text, which sits behind a DocuSign link - unchecked: the official MCP registry, which did not answer from our shell - unchecked: the help centre article on API audit logs and on rotating service user tokens - Whether a time off request can be approved or declined through the public API. No such endpoint is in the reference index, and the MCP tool list was unreadable - Whether API access or the MCP server costs extra on top of the core subscription - Whether an SLA exists in order forms - apidocs.hibob.com served a bot check to curl after about 25 requests. Later pages were read through WebFetch ### Sources - developer docs index (llms.txt): (seen 2026-10-07) - API reference index: (seen 2026-10-07) - service users and permissions: (seen 2026-10-07) - authorisation header: (seen 2026-10-07) - rate limiting and WAF blocking: (seen 2026-10-07) - people endpoints and their limits: (seen 2026-10-07) - people search, embedded OpenAPI: (seen 2026-10-07) - pagination: (seen 2026-10-07) - error handling: (seen 2026-10-07) - OAuth 2.0 for partners: (seen 2026-10-07) - webhooks v2: (seen 2026-10-07) - MCP server note and OAuth changelog entry: (seen 2026-10-07) - MCP product page: (seen 2026-10-07) - changelog feed: (seen 2026-10-07) - API changes and deprecations: (seen 2026-10-07) - API Terms of Use: (seen 2026-10-07) - status incidents: (seen 2026-10-07) - pricing: (seen 2026-10-07) - security page: (seen 2026-10-07) - customer subscription terms: (seen 2026-10-07) - privacy policy: (seen 2026-10-07) - subsidiaries and sub-processors: (seen 2026-10-07) - domain registration (RDAP): (seen 2026-10-07) ## Who's behind it (provenance 83/100, checked 2026-10-07) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Hi Bob Ltd. | 20/20 | | Domain age | hibob.com, registered 2010-02-25 (16 years) | 15/15 | | Endpoint on the vendor's domain | api.hibob.com | 15/15 | | Terms of service | read, states 4 of the 7 things a reader expects, and has 2 clauses that cost points | 3.4/10 | | Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 | | Status page | status.hibob.io | 10/10 | | Changelog | published | 10/10 | | security.txt | could not be fetched | 0/10 | The API Terms of Use name Hi Bob Ltd. and its subsidiaries. The privacy policy (updated 16 February 2026) names Hi Bob (UK) Limited, 5 New Street Square, London EC4A 3TW, and says it does not cover people who use Bob at a customer's direction. The customer subscription terms (revised January 2026) list contracting entities by region, among them Hi Bob, Inc., Hi Bob Ltd., Hi Bob (UK) Limited and Hi Bob (NL) B.V. The API answers at https://api.hibob.com/v1 and the sandbox at https://api.sandbox.hibob.com/v1. OAuth tokens are exchanged at https://auth.app.hibob.com/oauth2/v1/apps/token. The status page is on a separate domain, status.hibob.io. www.hibob.com/.well-known/security.txt returned a Cloudflare block page (403) to both of our fetchers, so its presence is unknown. RDAP for hibob.com gives a registration date of 2010-02-25. The data processing addendum page (updated September 2026) links to a pre-signed DocuSign document and does not show the terms. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://apidocs.hibob.com/docs/api-terms-of-use), read 2026-10-08, gives no date, states 4 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "Without limiting the generality of the foregoing, you may not: (i) scrape, crawl, build a database of, or create a permanent copy of the API Licensed Material or any portion except as strictly necessary for the permitted operation of the Integrated App in accordance with these API Terms;" - To know. Says the terms or the service can change without notice (costs points). "HiBob reserves the right to modify such limits at any time without notice." - To know. Says access can be ended without notice or for any reason. "We may suspend or terminate your access to, or use of, the APIs without notice for breach or suspected breach of these API Terms." - Not found in the text. Gives the date it was last updated. - States a limit on its liability. Capped at $100. - Not found in the text. Says how changes to the terms are announced. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). HiBob's aggregate liability under the API terms is capped at 100 US dollars, except for wilful misconduct or gross negligence. "TO THE FULLEST EXTENT PERMITTED BY LAW, AND OTHER THAN IN THE EVENT OF WILLFUL MISCONDUCT OR GROSS NEGLIGENCE, HIBOB’S AGGREGATE LIABILITY UNDER THIS AGREEMENT SHALL NOT EXCEED $100 USD (“LIABILITY CAP”)." - Also in the text (2026-10-08). The API terms give read only access and no right to change API data in HiBob's platform unless expressly permitted. "For clarity's sake, you have no right to change any of the API data within HiBob’s platform unless expressly permitted in the applicable HiBob documents or without our prior written consent and shall have a “read only” access." - Also in the text (2026-10-08). Any third party that is to use the API material needs HiBob's prior written consent and must agree to the API terms. "You agree you will ensure you obtain HiBob’s prior written consent and will ensure that such third party agrees to the API Terms for any third party that you wish to have used the API Licensed Materials for the purposes herein" **Privacy policy** (https://www.hibob.com/privacy/privacy-policy), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects. - To know. Says it sells personal data or shares it for advertising. "Under some data protection laws, like the CCPA and other US state privacy laws, our disclosure of this data to third parties for targeted advertising may be considered as a “sale” or “sharing” of personal information." - Not found in the text. Gives the date it was last updated. - Gives a privacy contact. Names a data protection officer. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). The policy does not cover people who use the product at a customer's direction, such as the customer's employees and contractors. "Please note that this Privacy Policy does NOT cover our practices regarding individuals who use the Solutions at our Customer’s direction, including a Customer’s employees, staff, and contractors (“End Users”)." - Also in the text (2026-10-08). De-identified data created from personal data may be used by HiBob or its business partners for any purpose. "To create aggregated data, inferred non-personal data or anonymized or pseudonymized data (de-identified data), which we or our business partners may use to provide and improve our respective services, conduct research, or for any other purpose." ## Live (updated 2026-10-08 17:36 UTC) - Right now: up, HTTP 200, 98 ms, checked 2026-10-08 17:36 UTC (get on `https://api.hibob.com/v1`) - Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 106 ms · p95 157 ms - Vendor status page: none, All Systems Operational - security.txt: unknown - Always current: https://www.anchorterminal.com/api/v1/live/hibob.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - Service users have no permissions by default, and view, edit and history rights are granted per category or field through permission groups - llms.txt index and a Markdown twin of every docs page, with an OpenAPI 3.1.1 definition embedded in each endpoint page - Per-endpoint rate limits are published, and 429 responses carry Retry-After and X-RateLimit headers - Webhooks v2 retry with exponential backoff for up to three days, with signed requests - SOC 2 Type II, ISO 27001:2022, ISO 27018:2019 and a Bugcrowd bug bounty listed on the security page ## Weaknesses - No public price, free tier or trial. The sandbox is a purchased module - People search has no pagination and returns every matching employee in one response - Fields without permission or with invalid IDs are dropped from a 200 response with no warning - No idempotency keys and no official SDK found in the reviewed documentation - MCP setup and tool documentation sit in the help centre, which returned 403 to our reader ## Before you call it (notes for agents) 1. Send `Authorization: Basic base64(SERVICE-USER-ID:TOKEN)` to https://api.hibob.com/v1. Ask the Bob admin to put the service user in a permission group first, because it starts with none 2. Request only the fields needed in `fields` on POST /people/search (maximum 400). The call returns all matching employees at once, so batch by `root.id` in large companies 3. Compare returned fields with requested ones. Missing permission or a wrong field ID yields 200 with the field omitted 4. Stop on 401 or 403. More than 50 in 10 seconds blocks the IP for 5 minutes 5. Back off on 429 using Retry-After. Writes such as update, create and terminate employee allow 10 calls a minute, and no idempotency key exists, so check state before retrying a write ## Connect First request: ```bash curl -X POST "https://api.hibob.com/v1/people/search" \ -u "$BOB_SERVICE_USER_ID:$BOB_SERVICE_USER_TOKEN" -H "Content-Type: application/json" \ -d '{"fields":["root.id","root.email","work.department"]}' ``` Through letme (picks today, calling later): https://letme.dev/hibob. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Deel | B | 69.1 | 158 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/deel.md | | BambooHR | C | 61.7 | 319 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/bamboohr.md | | Rippling | C | 60.8 | 341 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/rippling.md | | Finch | BB | 71.6 | 99 | hr.employees, hr.org, hr.documents | no | https://www.anchorterminal.com/tools/finch.md | | Workable | C | 61.7 | 320 | hr.employees, hr.time-off, hr.org | no | https://www.anchorterminal.com/tools/workable.md | | Gusto | B | 63.3 | 283 | hr.onboarding, hr.time-off | no | https://www.anchorterminal.com/tools/gusto.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Customer integrations authenticate with a service user ID and token over HTTP Basic. OAuth 2.0 apps are for approved Marketplace and technology partners only (source: ) - The hosted MCP server moved to OAuth per employee on 30 June 2026 in a gradual rollout, and its setup and tool documentation are kept only in the Bob help centre (source: ) - POST /people/search returns all matching employees in one response with no pagination, and omits fields the service user cannot read without a warning (source: ) - Every docs page has a Markdown version at the same URL plus .md, indexed at llms.txt, and endpoint pages embed their OpenAPI 3.1.1 definition (source: ) - status.hibob.io lists nine incidents between 9 July and 7 October 2026, three of them major or critical on single modules. The Public API component is named in one, 2 hours 6 minutes of slowness on 3 August (source: ) - The API terms let HiBob change rate limits without notice and say advance notice of deprecations is given where commercially reasonable (source: ) - Pricing is by quote, based on employee count and modules, with no trial on the pricing page (source: ) ## Compare - [BambooHR vs HiBob](https://www.anchorterminal.com/compare/bamboohr-vs-hibob.md): C 61.7 vs C 57 - [Deel vs HiBob](https://www.anchorterminal.com/compare/deel-vs-hibob.md): B 69.1 vs C 57 - [HiBob vs Rippling](https://www.anchorterminal.com/compare/hibob-vs-rippling.md): C 57 vs C 60.8 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on hibob.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "hibob", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html HiBob on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![HiBob on Anchor Terminal](https://www.anchorterminal.com/badges/hibob.svg)](https://www.anchorterminal.com/tools/hibob) ``` Plain link: ```html HiBob on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say HiBob is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/hibob-dark.png - Light: https://www.anchorterminal.com/assets/share/hibob-light.png