# HiBob (slim) > Bob is HiBob's HR platform for employee records, time off, attendance, tasks, documents and hiring. Agents reach it through a REST API authenticated with service users, 30 webhook events and a hosted MCP server that uses OAuth. - Full: https://www.anchorterminal.com/tools/hibob.md (~7,250 tokens) · this version ~1,930 tokens · JSON https://www.anchorterminal.com/tools/hibob.json · canonical https://www.anchorterminal.com/tools/hibob - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 57/100 · rank #429 of 629 · #4 in HR & employee operations · not agent-ready · confidence medium** Assessment: Service users start with no permissions and gain view or edit rights per field, and the docs are served as Markdown with an OpenAPI definition on each endpoint page. There is no public price, trial or free sandbox, so an agent needs a paying customer's admin to issue credentials. No idempotency keys or official SDKs were found. ## Facts - Kind: HTTP API · vendor: Hi Bob Ltd. · category: HR & employee operations · legal entity: Hi Bob Ltd. · provenance 83/100 - Endpoint: `https://api.hibob.com/v1` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under HiBob's customer subscription terms and API Terms of Use - Probe metrics: not measured yet (probes haven't run) - Surface graded: The public REST API at https://api.hibob.com/v1 with service-user credentials. The hosted MCP server is noted but its tool documentation could not be read - API coverage: 265 reference entries across employee data, employee and custom tables, time off, attendance and projects, tasks, reports, documents, goals, skills, job catalogue, employers, workforce planning and hiring, 30 of them webhook events - Credentials: Service user ID and token over HTTP Basic for customer integrations. OAuth 2.0 authorisation code for approved Marketplace partners, with 5-minute access tokens, 30-day refresh tokens and 28 scopes such as employee_data:read and timeoff:write - Permissions: Service users start with none. Permission groups grant product areas, people's data by category or field (View, View history, Edit) and the set of employees covered. Sensitive fields need both View and Edit to be returned - MCP server: Hosted, released 28 April 2026 with service users and moved to OAuth per employee from June 2026 in a gradual rollout. HiBob lists ChatGPT, Claude.ai, Claude Desktop and Cursor as clients. An admin enables it in Bob - Rate limits: Per endpoint per minute. People search 50, read employee by ID 100, update, create and terminate employee 10 each, public profiles 40. The Docs API has none at present. More than 50 responses of 401 or 403 in 10 seconds blocks the IP for 5 minutes - Errors: 400, 401, 403, 404, 429 and 500 documented with JSON bodies whose shape varies by module. 429 carries Retry-After, X-RateLimit-Limit and X-RateLimit-Remaining. 304 means the submitted data matched the record - Pagination: Cursor and limit (default 50, maximum 200) on bulk table, workforce planning and job catalogue endpoints. People search and read by ID are not paginated - Webhooks: v2 events for employees, time off, tasks, documents and workforce planning. Payloads carry identifiers and changed-field metadata only. Signed, retried with exponential backoff for up to 3 days, then the webhook is deactivated - Time off: Submit and cancel requests, read balances, policies, who's out and request changes, and create balance adjustments. No approve or decline endpoint is listed in the reference index - Sandbox: https://api.sandbox.hibob.com/v1, available only to accounts that have bought the Sandbox module - Audit: Bob has an API audit log of Public API usage, linked from the developer docs. The help centre article describing it returned 403 to our reader - Certifications: SOC 2 Type II, ISO 27001:2022 and ISO 27018:2019 per hibob.com/privacy/security. Bug bounty on Bugcrowd. Hosted on AWS in Ireland with disaster recovery in Frankfurt - Status: status.hibob.io on Statuspage, 46 components including Public API, Sandbox, Time Off, Docs and Tasks - Sub-processors: List updated November 2025. AWS (EU), SingleStore (EU), Cloudinary, Cloudflare and Zendesk as core, with OpenAI and Microsoft Azure OpenAI for optional AI functions - Scores: Reliability 67, Performance pending, Schema & documentation 78, Agent ergonomics 47, Security & auth 68, Payments & pricing 0, Task success pending, Maintenance & community 59, Transparency & trust 71 · total over the 7 assessed categories - Why: Reliability, Graded on the public REST API. · Schema & documentation, Each endpoint and webhook page embeds an OpenAPI 3.1.1 definition in its Markdown version. · Agent ergonomics, The `fields` array sizes people responses, but people search returns every matching employee in one response (13). · Security & auth, Service users are separate, revocable credentials with no permissions by default and rights granted per feature, per field and per employee… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The newest developer changelog entry is dated 7 October 2026 (30). · Transparency & trust, Closed service with public API Terms of Use and customer subscription terms revised January 2026 (15). - Sources: 23, open questions: 9, both in the full twin - Capabilities: hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents - JSON: https://www.anchorterminal.com/api/v1/tools/hibob.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/hibob.svg` or a link to https://www.anchorterminal.com/tools/hibob from a page on hibob.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `Authorization: Basic base64(SERVICE-USER-ID:TOKEN)` to https://api.hibob.com/v1. Ask the Bob admin to put the service user in a permission group first, because it starts with none 2. Request only the fields needed in `fields` on POST /people/search (maximum 400). The call returns all matching employees at once, so batch by `root.id` in large companies 3. Compare returned fields with requested ones. Missing permission or a wrong field ID yields 200 with the field omitted 4. Stop on 401 or 403. More than 50 in 10 seconds blocks the IP for 5 minutes 5. Back off on 429 using Retry-After. Writes such as update, create and terminate employee allow 10 calls a minute, and no idempotency key exists, so check state before retrying a write ## Connect ```bash curl -X POST "https://api.hibob.com/v1/people/search" \ -u "$BOB_SERVICE_USER_ID:$BOB_SERVICE_USER_TOKEN" -H "Content-Type: application/json" \ -d '{"fields":["root.id","root.email","work.department"]}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/hibob ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Deel | B | 69.1 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/deel.min.md | | BambooHR | C | 61.7 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/bamboohr.min.md | | Rippling | C | 60.8 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/rippling.min.md | | Finch | BB | 71.6 | hr.employees, hr.org, hr.documents | https://www.anchorterminal.com/tools/finch.min.md | | Workable | C | 61.7 | hr.employees, hr.time-off, hr.org | https://www.anchorterminal.com/tools/workable.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)