# Humaans (slim) > Humaans is an HR system of record for employee profiles, job roles, compensation, time away, timesheets, documents and equipment. Agents reach it through a REST API with scoped access tokens, signed webhooks and a hosted MCP server that uses OAuth. - Full: https://www.anchorterminal.com/tools/humaans.md (~7,350 tokens) · this version ~2,230 tokens · JSON https://www.anchorterminal.com/tools/humaans.json · canonical https://www.anchorterminal.com/tools/humaans - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 54.4/100 · rank #529 of 722 · #7 in HR & employee operations · not agent-ready · confidence medium** Assessment: API tokens are limited by eight scopes and the creator's role, can expire and can be rotated with a seven-day overlap, and rate limits are published with Retry-After on 429. No OpenAPI file, API changelog, official SDK or idempotency keys were found, and prices are by quote, so an agent needs a paying customer's token. ## Facts - Kind: HTTP API · vendor: Humaans Software UK Ltd · category: HR & employee operations · legal entity: Humaans Software UK Ltd · provenance 81/100 - Endpoint: `https://app.humaans.io/api` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under Humaans' Terms of Service - Probe metrics: not measured yet (probes haven't run) - Surface graded: The public REST API at https://app.humaans.io/api with scoped access tokens. The hosted MCP server is recorded but its tool list could not be read without signing in - API coverage: 174 method and path pairs across 50 resources (86 GET, 30 POST, 29 PATCH, 29 DELETE). People, job roles, compensations, bank accounts, emergency contacts, working patterns, time away with policies, allocations and adjustments, timesheets, documents and identity documents, equipment, org units, job library, custom fields, data exports and webhooks - Credentials: Bearer API access token created in the app. Scopes `public:read`, `private:read`, `private:write`, `compensations:read`, `compensations:write`, `documents:read`, `documents:write` and `webhooks:manage`. Optional expiry of 1 to 365 days with email warnings, and rotation with up to seven days of overlap. `GET /api/token-info` returns scopes and expiry - Permissions: A token can do only what its creator can. Owner has full access, Admin edits all profiles, Finance reads all profiles, Tech sees limited data, Manager sees reports' data and User sees their own. Compensation defaults to Owner and Finance, personal documents to Owner - MCP server: Hosted at https://mcp.humaans.ai/mcp. OAuth 2.0 with dynamic client registration and PKCE S256 against app.humaans.io, 32 scopes including `timeAway:write`, `workflows:write` and `auditLog:read`. Launched April 2026 and opened to all Growth and Enterprise customers on 8 June 2026. The vendor's page names the tools `find_people`, `find_compensations`, `create_compensations` and `send_esign_document` - Rate limits: Per token. A bucket of 40 requests refilling at 7 a second, about 400 a minute. `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Policy` headers, and `Retry-After` on 429 - Errors: JSON error object with id, code, name, message and per-field `issues`. 400, 401, 403, 404, 405, 409, 413, 422 (ValidationError, Unprocessable, EmailTaken), 429, 500, 502 and 503 documented - Pagination: `$limit` (default 100, maximum 250) and `$skip`, with `total` in each response. Filters `$in`, `$nin`, `$gt`, `$gte`, `$lt`, `$lte` and `$or` on listed fields. Incremental sync by `updatedAt` with `$includeDeleted=true`, and deleted records kept as tombstones for 30 days - Webhooks: 28 event types across time away, people, bank accounts, job roles, compensation, emergency contacts and equipment. Signed with HMAC SHA-256 in `webhook-signature`, sent from three published IPv4 addresses and one IPv6 range, retried with exponential backoff, and disabled after 5 days of failures. Listed under the Enterprise plan - Time away: Create, update and delete entries, and approve or decline by setting `requestStatus` to approved or declined with a `reviewNote` on `PATCH /api/time-away/:id`. Types, policies, periods, allocations and adjustments have their own endpoints - Onboarding: `POST /api/people` with status `newHire` creates a pending hire that only Owner and Admin can see until it is made active. No workflow or task endpoints are in the REST reference. The MCP page says workflows such as onboarding can be started through the MCP server - Versioning: None. The docs commit to no backward-incompatible changes, say unused APIs may be removed, and say any future versioning will not break the existing API. Four performance resources are marked Preview - Sandbox: A dedicated sandbox account is listed under the Enterprise plan. Integration builders can ask for one through a form titled Request a Sandbox Account for Integration - Audit: The audit log records who acted, what changed, when and from where, with filters by actor, action, field and space. Unlimited audit logs and export are listed under Enterprise - Certifications: SOC 2 Type II and ISO 27001:2022 per humaans.io/security, with reports in the trust centre. Hosted on Google Cloud in the EU, AES-256 at rest with application-level encryption, regular penetration tests - Status: humaansstatus.io on Instatus with Website, Platform and API components, 90-day uptime bars and RSS and Atom feeds - Sub-processors: DPA Annex C, effective 6 October 2026. Google Cloud EMEA (infrastructure, Ireland), AWS (backups), Stripe, Postmark and Svix among the core set. Google, Anthropic and OpenAI for AI models, defaulting to the EEA or Switzerland. 14 days' notice of additions - Scores: Reliability 70, Performance pending, Schema & documentation 44, Agent ergonomics 60, Security & auth 70, Payments & pricing 0, Task success pending, Maintenance & community 56, Transparency & trust 73 · total over the 7 assessed categories - Why: Reliability, Graded on the public REST API, as a hosted service. · Schema & documentation, No OpenAPI or other machine-readable contract was found (0). · Agent ergonomics, `$limit` sizes pages, `$select` appears on three list endpoints only, and the `public:read` scope returns trimmed profiles (13). · Security & auth, API tokens are revocable, limited by eight scopes and by the creator's role, can expire after 1 to 365 days and can be rotated with the old… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, The newest dated product update is 10 September 2026, 28 days before the check (30). · Transparency & trust, Closed service with public Terms of Service effective 6 October 2026 and a link to the previous version (15). - Sources: 21, open questions: 8, both in the full twin - Capabilities: hr.employees, hr.time-off, hr.org, hr.documents, hr.onboarding - JSON: https://www.anchorterminal.com/api/v1/tools/humaans.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/humaans.svg` or a link to https://www.anchorterminal.com/tools/humaans from a page on humaans.io or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `Authorization: Bearer ` to https://app.humaans.io/api. Call `GET /api/token-info` first to read the token's scopes and expiry 2. Expect a role limit as well as scopes. A token made by a user with the User role reads only public company data and that person's own profile 3. Page with `$limit` (maximum 250) and `$skip`, and pass `-g` to curl because parameters use `$` and `[]` 4. On 429 wait the seconds in `Retry-After`. The bucket holds 40 requests and refills at 7 a second per token 5. Check state before retrying a POST. No idempotency key exists, and `DELETE /api/people/:id` cannot be undone ## Connect ```bash curl https://app.humaans.io/api/me \ -H 'Authorization: Bearer ' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/humaans ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Deel | B | 69.1 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/deel.min.md | | BambooHR | C | 61.7 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/bamboohr.min.md | | Rippling | C | 60.8 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/rippling.min.md | | HiBob | C | 57 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/hibob.min.md | | Zoho People | C | 55 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/zoho-people.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)