Lever
by Employ, Inc. HTTP API in Recruiting & applicant tracking
Hosted
Employ, Inc. · lever.co since 2010 · status page · who's behind it
Applicant tracking and candidate relationship system from Employ Inc. Its Data API reads and writes opportunities, postings, interviews, feedback and requisitions, and a separate Postings API serves published jobs.
Good for An agent working inside a company that already runs Lever, for reading the pipeline, adding candidates, moving stages, writing notes and feedback and scheduling externally managed interviews.
Is this your product? Claim this listing or verify it
Assessment. The Data API covers about 100 operations with read and write OAuth scopes per resource, field selection and a 99.9 per cent uptime commitment. Access depends on a paying customer or partner approval, with no public price, no OpenAPI file and no official SDK. The status page records three critical incidents between 14 July and 21 August 2026.
Facts
- Transport
- HTTP
- Endpoint
https://api.lever.co/v1- Auth
- OAuth or key
- Pricing
- Paid · Paid
- x402
- No
- Licence
- Proprietary service under Lever's terms of service. The postings-api and integrator-resources repositories on GitHub hold documentation and example code
- llms.txt
- not found
- Last release
- Surface graded
- The Data API v1 at https://api.lever.co/v1 (the Postings API README gives https://api.eu.lever.co/v0/postings/ for EU accounts), plus the Postings API v0 for published jobs. No official MCP server found
- Access
- API key from Settings, Integrations and API, created by a Super Admin of a paying account, or a partner OAuth app issued by Lever staff. Lever's partner FAQ says older API key integrations need the customer to have the Data API feature
- Sandbox
- https://api.sandbox.lever.co/v1, given to approved partners under the Developer Sandbox Terms. Email is switched off, only test data is allowed and Lever may delete data without notice
- OAuth
- Authorisation code grant at https://auth.lever.co/authorize with a required
audience. Access tokens last 1 hour, refresh tokens 1 year or 90 days idle. At most 20 scopes per app, and a write scope includes the matching read scope - Rate limits
- 10 requests a second per API key steady, bursts to 20, no per-endpoint limits. Postings API application POSTs 2 a second
- Pagination
limit1 to 100 (default 100), opaqueoffsettoken,nextandhasNextin every list response. Deleted-record and file-action endpoints use keyset pagination with a time window of at most 30 days- Response sizing
includereturns only the named fields.expandinlines linked objects such as applications, stage, owner and followers- Errors
- 400, 401, 403, 404, 429, 500 and 503 with a JSON body of
codeandmessage, such as ResourceNotFound - Webhooks
- applicationCreated, candidateHired, candidateStageChange, candidateArchiveChange, candidateDeleted, interviewCreated, interviewUpdated, interviewDeleted, contactCreated and contactUpdated. HTTPS only, HMAC-SHA256 signature in the body, five retries, delivery history in settings
- Write limits
- Offer records are read-only. Interviews and panels can be written only when
externallyManagedis true. Confidential postings can't be modified through the API - Audit
- GET /audit_events lists user provisioning, authentication and data export events. It is a paid add-on
- SLA
- 99.9 per cent monthly uptime for all customers, credits of 10 times the fees for the downtime, exhibit last updated 14 April 2022
- Certifications
- SOC 2 Type II and ISO/IEC 27001 (certificate issued by Schellman) per lever.co/security. Reports on request to customers. No bug bounty
- Hosting
- AWS us-west-2 and eu-central-1, with separate global and EU data centres
- Sub-processors
- List effective 21 September 2025 with purpose and location, among them AWS, Google Cloud, Mailgun, Snowflake, Textkernel, Twilio Segment and Zendesk. AI Companions add Anthropic, OpenAI, AssemblyAI, IBM watsonx and Recall
Facts verified 2026-10-07 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- About 100 documented operations on https://api.lever.co/v1, with writes for opportunities, stages, notes, feedback, interviews, postings and requisitions
- OAuth 2.0 authorisation code grant with around 50 scopes split into read and write per resource, and a separate scope for confidential data
- Every list endpoint takes
limit(1 to 100), an opaqueoffsettoken,includefor field selection andexpandfor linked objects - Published SLA commits to 99.9 per cent monthly uptime with automatic service credits
- Sub-processor list dated 21 September 2025 names each vendor, purpose and location
Weaknesses
- No public price, free tier or self-serve signup. OAuth apps and sandbox accounts are issued by Lever staff after a partner application
- No OpenAPI file, llms.txt or official SDK. The reference is one HTML page and a Postman collection last changed in February 2025
- Three incidents marked critical on status.lever.co between 14 July and 21 August 2026, one with elevated API error rates for 14 minutes
- No idempotency keys, and 429 responses are documented without a Retry-After header
- The Postings API takes its key in the URL query string for application submissions
- Offer records are read-only, and interviews can be written only on panels marked
externallyManaged
Before you call it notes for agents
- Send
perform_aswith a Lever user id on creates and most updates. Opportunity, note, feedback, panel and interview writes reject requests without it - Use the Opportunities endpoints. The Candidates endpoints were deprecated in 2020 and the old candidate id works as the opportunity id
- Stay under 10 requests a second per key and back off exponentially on 429 and 503. Application POSTs are limited to 2 a second
- Create interviews on a panel with
externallyManagedtrue. Panels made in the Lever app can't be changed through the API - Pass
includeto trim fields and follownextwhilehasNextis true. Anoffsetmust come from a previous response - Send a full object on PUT to panels and interviews. Missing fields are deleted
Who's behind it provenance 87/100
- Legal entity namedEmploy, Inc.20/20
- Domain agelever.co, registered 2010-07-20 (16 years)15/15
- Endpoint on the vendor's domainapi.lever.co15/15
- Terms of serviceread, states 7 of the 7 things a reader expects, and has 1 clause that costs points8/10
- Privacy policyread, states 7 of the 8 things a reader expects9.3/10
- Status pagestatus.lever.co10/10
- Changelogpublished10/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2023-08-25, states 7 of 7, 3 to know
TL;DR Dated 2023-08-25. States all 7 things a reader expects. To know before relying on it, limits on benchmarking, arbitration or a class action waiver and no update in three years.
Restricts benchmarking or competitive usecosts points
In addition, the software and services may not be accessed for the exclusive purpose of monitoring performance, or functionality, or for any other benchmarking or competitive purposes.
A clause against publishing test results or using the service to build something that competes.
Requires arbitration or waives class actions
If the parties do not reach such solution within a period of sixty (60) days, then, upon notice by either party to the other, all disputes shall be finally settled by binding arbitration taking place in San Francisco, California.
Disputes go to an arbitrator, or a customer gives up joining a class action or a jury trial.
Has not been updated for three years or more
Last updated August 25, 2023
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2023-08-25
Last updated August 25, 2023
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
This Agreement is governed by and construed in accordance with the internal laws of the State of California without giving effect to any choice or conflict of law.
Says where a dispute would be heard and under whose law.
States a limit on its liability Capped at the fees paid in the 12 months before the claim
…liability arising out of a party's indemnity obligations, gross negligence, fraud or willful misconduct, in no event will either party or their respective directors, officers, agents, or employees, be liable to the other party for any reason, whether in contract or in tort, for any claims, suits, liability or damages…
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
Notwithstanding anything to the contrary in this Agreement, Lever may impose limitations on bandwidth usage, and/or temporarily suspend Customer's and any user authorized by Customer to access to any portion or all of the Services if Lever reasonably determines that (i) there is a threat to or attack on any of the Ser…
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
Lever reserves the right to periodically modify these Terms of Service upon written notice to Customer, and such modification will become effective in the next service term.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
Customer will not, and will not permit any third party to: reverse engineer, decompile, disassemble or otherwise attempt to discover the source code, object code or underlying structure, ideas or algorithms of the Services, Documentation or data related to the Services (provided that reverse engineering is prohibited…
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Lever will provide the Services in accordance with the service level agreement exhibit identified at www.lever.co/agreements/sla.
Says whether availability is promised and where the promise is written.
The agreement renews automatically for further one-year periods unless either party asks in writing to end it at least 30 days before the term ends.
will automatically renew for additional one year periods (together with each “Renewal Service Term,” the “Term”) subject to section 3.2 of the Agreement, unless either party requests termination in writing at least thirty (30) days prior to the end of the then-current Term.
Noted by a second reader on 2026-10-08.
Renewal fees may rise by up to the change in the US Consumer Price Index over the latest twelve months plus five per cent.
price increase to be made effective upon the effective date of the Renewal Service Term not to exceed the change in the U.S. Department of Labor's Bureau of Labor Statistics Consumer Price Index – All Urban Consumers (“CPI”) during the most recent twelve (12) month period plus five percent (5%).
Noted by a second reader on 2026-10-08.
After the term expires, customer data is no longer accessible and is deleted under Lever's data retention policy.
After the expiration of the Term, Customer Data will no longer be accessible and will be promptly deleted in accordance with Lever's data retention policy.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 5,622 words
Privacy policy dated 2023-09-25, states 7 of 8, 1 to know
TL;DR Dated 2023-09-25. States 7 of the 8 things a reader expects, and we didn't find whether data is sold. To know before relying on it, no update in three years.
Has not been updated for three years or more
Effective as of September 25, 2023
The date the document gives for itself is more than three years ago.
Gives the date it was last updated Last updated 2023-09-25
Effective as of September 25, 2023
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
Employ may combine the foregoing types of data with data Employ already has or data provided by third parties, including third parties from whom Employ has purchased Personal Data.
The basic statement a privacy policy exists to make.
Says how long data is kept
Employ may retain your Personal Data for a period of time consistent with the original purpose of collection (see the “Our Purposes for Processing Personal Data” section above).
Says when data sent to the service is deleted.
Says who else receives the data
With Employ service providers, who provide services such as IT and system administration and hosting, credit card processing, research and analytics, marketing, customer support and data enrichment for the purposes and pursuant to the legal bases described above;
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
Not found in the text.
A plain statement either way.
Says what rights people have over their data
Where Employ processes your Personal Data for direct marketing purposes or share it with third parties for their own direct marketing purposes, you can exercise your right to object at any time to such processing without having to provide any specific reason for such objection;
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@employinc.com
…has provided Employ with Personal Data without their consent, he or she should contact Employ at privacy@employinc.com ever become aware that a child under 18 has provided Employ with Personal Data, Employ will take steps to delete such information from Employ’s files.
An address or officer to send a request to.
Says where data is transferred or stored Relies on standard contractual clauses
…adequate level of protection, for instance by entering into the appropriate agreements and, if required, standard contractual clauses for the transfer of data as approved by the European Commission (Art.
The countries data goes to and the safeguard used.
Employ may use personal data collected through the services to build models and to personalise content for customers.
Employ may use Personal Data to analyze trends and usage, assess capacity requirements, identify Customer opportunities and conduct surveys, build models to allow Employ to better serve Customers and personalize content and features for Customers
Noted by a second reader on 2026-10-08.
Employ may combine the data it collects with personal data bought from third parties.
Employ may combine the foregoing types of data with data Employ already has or data provided by third parties, including third parties from whom Employ has purchased Personal Data.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 3,281 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The terms of service (last updated 25 August 2023) and the Developer Sandbox Terms (21 September 2020) name Lever, Inc. The DPA (last updated 20 May 2025) and the sub-processor list name Employ, Inc., 20 North Meridian Street, Suite 300, Indianapolis, IN 46204, and page footers read Employ Inc.
API endpoints answer at api.lever.co, with auth.lever.co for OAuth. An unauthenticated GET to https://api.lever.co/v1/opportunities returned 401 with server: lever-data-api on 7 October 2026.
www.lever.co/.well-known/security.txt and www.employinc.com/.well-known/security.txt both return 404. A vulnerability disclosure policy with security@employinc.com is in SECURITY.md in Lever's GitHub repositories and says there is no bug bounty.
RDAP at rdap.registry.co gives a registration date of 2010-07-20 for lever.co and NameCheap, Inc. as registrar.
The SLA and DPA are published on employinc.com (https://www.employinc.com/lever-sla/ and https://www.employinc.com/dpa/).
Checked 2026-10-07 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://api.lever.co/v1. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials. Last note, asks for credentials.
- Vendor status page all systems normal, All Systems Operational · 10 minutes ago
- GitHub stars 200
- security.txt none · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/lever.json
Notable
- The Data API at https://api.lever.co/v1 documents about 100 operations across opportunities, postings, interviews, panels, feedback, notes, files, requisitions, users and webhooks source
- API keys are for a customer's own workflows. Partner integrations must use OAuth, and Lever staff create each OAuth app after a registration form and a partner application source
- The Postings API returns a company's published jobs without a key, for example https://api.lever.co/v0/postings/leverdemo?mode=json, and takes applications with an API key in the query string source
- Rate limit is a token bucket of 10 requests a second per key with bursts to 20, and Lever says the defaults aren't guaranteed source
- The SLA commits to 99.9 per cent monthly uptime with service credits of 10 times the fees for the downtime source
- The terms of service prohibit access for benchmarking or competitive purposes source
- The newest entry on the API updates page is dated 30 April 2026, the fourth that month after a gap since 31 March 2025 source
- No Lever-published MCP server was found. The official MCP registry lists only third-party servers that read public job boards source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 7 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 14.6 | |
| Graded on the hosted lines for the Data API. Statuspage at status.lever.co with about 40 components, among them Integration API & Webhooks, Hire and Sandbox for the global and EU data centres (20). From 9 July to 7 October 2026 the page records six incidents, three marked critical. Offer letter sending failed platform-wide on 14 July, mitigated after about 1.5 hours and resolved after 9. A 14-minute outage on 12 August, caused by a support data query, raised API error rates per the postmortem. 500 errors on 21 August had a fix within 17 minutes. An offer document conversion outage on 7 August lasted most of a working day. None shows an hour of the API itself down, so we scored between minor-only and one major (10). 10 requests a second per key with bursts to 20, and 2 application POSTs a second (15). Exponential backoff is advised for 429 and 503, with no Retry-After header documented and no idempotency keys for writes (8). SLA of 99.9 per cent monthly uptime with service credits (10). The v1 API is generally available (10). | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 8.9 | |
| No OpenAPI file found. A Postman collection in lever/integrator-resources is the only machine-readable description and its last commit is from February 2025 (5). No llms.txt, www.lever.co/llms.txt returns 404 (0). The reference explains each resource, how candidates, contacts and opportunities relate, and marks every deprecated endpoint with the replacement to call, but gives little guidance on when not to use an endpoint (14). Attribute tables give types and mark parameters required or optional, with few enumerated values or constraints stated in a form a machine can check (10). curl examples and sample responses on nearly every endpoint, nine status codes explained and one sample error body (11). Versioned path /v1, a promise not to rename or remove fields without a version bump, and a dated updates page running from 2021 to 30 April 2026 (15). | |||
| Agent ergonomics | 13%16.2 | 10.6 | |
include trims a response to named fields, expand inlines linked objects and limit caps a page at 100 (22). Opaque offset tokens with next and hasNext on every list, and filters by stage, posting, tag, email, contact and created, updated or archived time on opportunities (20). Errors carry a code and message such as ResourceNotFound, with no per-field validation detail or list of codes documented (12). No idempotency keys. Creating an opportunity with an email address is matched to an existing contact, which limits duplicate people but still creates a second opportunity on retry (5). Reads need no parameters, but most writes require perform_as with a user id, PUT on panels deletes missing fields, and there is no official SDK (6). | |||
| Security & auth | 14%17.5 | 10.5 | |
OAuth 2.0 with around 50 scopes split by resource into read and write, one-hour access tokens and revocation by a Super Admin, plus API keys limited to chosen endpoints (30). The Postings API documents its key in the key query parameter for application POSTs (-10). Read-only scopes and a separate confidential:access:admin scope allow least privilege. Deletes of notes, files, feedback and requisitions need no confirmation (13). Resumes, notes and application answers are written by outside parties and no prompt-injection guidance was found (3). An audit events endpoint covers user provisioning, authentication and data export as a paid add-on, webhook deliveries have a history view, and perform_as attributes each write to a user (10). SOC 2 Type II, ISO/IEC 27001 and a vulnerability disclosure policy at security@employinc.com. No bug bounty and no security.txt (14). | |||
| Payments & pricing | 10%12.5 | 0.6 | |
| No x402, MPP or L402 (0). Pricing is by quote only (0). No free tier or trial found, and the sandbox goes only to approved partners (0). API keys and OAuth apps need a person, a customer contract or Lever's partner team. We gave 5 because the Postings API returns any customer's published jobs without a key or account (5). | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 1.8 | |
| The newest dated API change is 30 April 2026, 160 days before the check (10). No entries in the last 90 days. The four in April 2026 followed a gap since 31 March 2025 (0). Closed service with a dated updates page, a help centre and an integrations support address. The public postings-api repository merged a README change on 23 April 2026 (8). No official SDKs and no Lever-published MCP server in the official registry (0). No packages to assess. The example repository has CodeQL and dependency review workflows and was last changed in February 2025 (3). | |||
| Transparency & trusteditorial 63, provenance 87 | 7%8.8 | 6.6 | |
| Closed service with public terms of service (25 August 2023), an SLA and Developer Sandbox Terms. The terms bar access for benchmarking or competitive purposes (15). A DPA (updated 20 May 2025), a services privacy notice (25 September 2023) and a security page give retention and deletion periods. They disagree on one figure, with deletion starting 30 days after termination in the DPA and 90 days on the security page, both ending by day 45 (20). A deprecated section keeps the 2020 Candidates endpoints documented and working, and Lever promises no field removals without a version bump, but no notice period or removal dates are published (10). Sub-processor list effective 21 September 2025 with purposes and locations, and hosting regions named (18). | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 53.6 · D | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 17 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Lever, or have the agent fetch /fixes/lever.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Lever From Anchor Terminal's listing at https://www.anchorterminal.com/tools/lever, the October 2026 research run, assessed 7 October 2026. Grade D, 53.6 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Lever: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Payments & pricing, 5 out of 100, up to 11.9 more on the total Why it scored 5: No x402, MPP or L402 (0). Pricing is by quote only (0). No free tier or trial found, and the sandbox goes only to approved partners (0). API keys and OAuth apps need a person, a customer contract or Lever's partner team. We gave 5 because the Postings API returns any customer's published jobs without a key or account (5). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 2. Schema & documentation, 55 out of 100, up to 7.3 more on the total Why it scored 55: No OpenAPI file found. A Postman collection in lever/integrator-resources is the only machine-readable description and its last commit is from February 2025 (5). No llms.txt, www.lever.co/llms.txt returns 404 (0). The reference explains each resource, how candidates, contacts and opportunities relate, and marks every deprecated endpoint with the replacement to call, but gives little guidance on when not to use an endpoint (14). Attribute tables give types and mark parameters required or optional, with few enumerated values or constraints stated in a form a machine can check (10). curl examples and sample responses on nearly every endpoint, nine status codes explained and one sample error body (11). Versioned path /v1, a promise not to rename or remove fields without a version bump, and a dated updates page running from 2021 to 30 April 2026 (15). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 3. Security & auth, 60 out of 100, up to 7 more on the total Why it scored 60: OAuth 2.0 with around 50 scopes split by resource into read and write, one-hour access tokens and revocation by a Super Admin, plus API keys limited to chosen endpoints (30). The Postings API documents its key in the `key` query parameter for application POSTs (-10). Read-only scopes and a separate `confidential:access:admin` scope allow least privilege. Deletes of notes, files, feedback and requisitions need no confirmation (13). Resumes, notes and application answers are written by outside parties and no prompt-injection guidance was found (3). An audit events endpoint covers user provisioning, authentication and data export as a paid add-on, webhook deliveries have a history view, and `perform_as` attributes each write to a user (10). SOC 2 Type II, ISO/IEC 27001 and a vulnerability disclosure policy at security@employinc.com. No bug bounty and no security.txt (14). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 4. Maintenance & community, 21 out of 100, up to 6.9 more on the total Why it scored 21: The newest dated API change is 30 April 2026, 160 days before the check (10). No entries in the last 90 days. The four in April 2026 followed a gap since 31 March 2025 (0). Closed service with a dated updates page, a help centre and an integrations support address. The public postings-api repository merged a README change on 23 April 2026 (8). No official SDKs and no Lever-published MCP server in the official registry (0). No packages to assess. The example repository has CodeQL and dependency review workflows and was last changed in February 2025 (3). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 5. Agent ergonomics, 65 out of 100, up to 5.7 more on the total Why it scored 65: `include` trims a response to named fields, `expand` inlines linked objects and `limit` caps a page at 100 (22). Opaque offset tokens with `next` and `hasNext` on every list, and filters by stage, posting, tag, email, contact and created, updated or archived time on opportunities (20). Errors carry a `code` and `message` such as ResourceNotFound, with no per-field validation detail or list of codes documented (12). No idempotency keys. Creating an opportunity with an email address is matched to an existing contact, which limits duplicate people but still creates a second opportunity on retry (5). Reads need no parameters, but most writes require `perform_as` with a user id, PUT on panels deletes missing fields, and there is no official SDK (6). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 6. Reliability, 73 out of 100, up to 5.4 more on the total Why it scored 73: Graded on the hosted lines for the Data API. Statuspage at status.lever.co with about 40 components, among them Integration API & Webhooks, Hire and Sandbox for the global and EU data centres (20). From 9 July to 7 October 2026 the page records six incidents, three marked critical. Offer letter sending failed platform-wide on 14 July, mitigated after about 1.5 hours and resolved after 9. A 14-minute outage on 12 August, caused by a support data query, raised API error rates per the postmortem. 500 errors on 21 August had a fix within 17 minutes. An offer document conversion outage on 7 August lasted most of a working day. None shows an hour of the API itself down, so we scored between minor-only and one major (10). 10 requests a second per key with bursts to 20, and 2 application POSTs a second (15). Exponential backoff is advised for 429 and 503, with no Retry-After header documented and no idempotency keys for writes (8). SLA of 99.9 per cent monthly uptime with service credits (10). The v1 API is generally available (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 7. Transparency & trust, 75 out of 100, up to 2.2 more on the total Made of editorial 63, provenance 87. Why it scored 75: Closed service with public terms of service (25 August 2023), an SLA and Developer Sandbox Terms. The terms bar access for benchmarking or competitive purposes (15). A DPA (updated 20 May 2025), a services privacy notice (25 September 2023) and a security page give retention and deletion periods. They disagree on one figure, with deletion starting 30 days after termination in the DPA and 90 days on the security page, both ending by day 45 (20). A deprecated section keeps the 2020 Candidates endpoints documented and working, and Lever promises no field removals without a version bump, but no notice period or removal dates are published (10). Sub-processor list effective 21 September 2025 with purposes and locations, and hosting regions named (18). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Terms of service: read, states 7 of the 7 things a reader expects, and has 1 clause that costs points (8 of 10) - Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10) - security.txt: not found (0 of 10) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - unchecked: the developer FAQ and use-case tabs (https://hire.lever.co/developer/faq and /use-cases), which redirected to a login - unchecked: the help centre article on API key permissions, so the per-endpoint key limits are taken from the Data API reference and its 403 text - Whether 429 responses carry a Retry-After header. The documentation doesn't say and we made no authenticated calls - Whether the Data API feature for API keys is included in every current plan. The partner FAQ says older API key integrations need it, and no plan table is public - Which legal entity contracts today. The 2023 terms name Lever, Inc. and the 2025 DPA names Employ, Inc. - How long partner approval takes and whether Lever accepts agent builders that aren't selling a product integration - Root cause analyses for the 21 and 25 August 2026 incidents weren't on the status page when checked ## Weaknesses - No public price, free tier or self-serve signup. OAuth apps and sandbox accounts are issued by Lever staff after a partner application - No OpenAPI file, llms.txt or official SDK. The reference is one HTML page and a Postman collection last changed in February 2025 - Three incidents marked critical on status.lever.co between 14 July and 21 August 2026, one with elevated API error rates for 14 minutes - No idempotency keys, and 429 responses are documented without a Retry-After header - The Postings API takes its key in the URL query string for application submissions - Offer records are read-only, and interviews can be written only on panels marked `externallyManaged` ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Send `perform_as` with a Lever user id on creates and most updates. Opportunity, note, feedback, panel and interview writes reject requests without it - Use the Opportunities endpoints. The Candidates endpoints were deprecated in 2020 and the old candidate id works as the opportunity id - Stay under 10 requests a second per key and back off exponentially on 429 and 503. Application POSTs are limited to 2 a second - Create interviews on a panel with `externallyManaged` true. Panels made in the Lever app can't be changed through the API - Pass `include` to trim fields and follow `next` while `hasNext` is true. An `offset` must come from a previous response - Send a full object on PUT to panels and interviews. Missing fields are deleted ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: the developer FAQ and use-case tabs (https://hire.lever.co/developer/faq and /use-cases), which redirected to a login
- unchecked: the help centre article on API key permissions, so the per-endpoint key limits are taken from the Data API reference and its 403 text
- Whether 429 responses carry a Retry-After header. The documentation doesn't say and we made no authenticated calls
- Whether the Data API feature for API keys is included in every current plan. The partner FAQ says older API key integrations need it, and no plan table is public
- Which legal entity contracts today. The 2023 terms name Lever, Inc. and the 2025 DPA names Employ, Inc.
- How long partner approval takes and whether Lever accepts agent builders that aren't selling a product integration
- Root cause analyses for the 21 and 25 August 2026 incidents weren't on the status page when checked
Sources 18
- Data API reference (auth, scopes, rate limits, errors, pagination, webhooks, endpoints) hire.lever.co · seen 2026-10-07
- OAuth registration and sandbox hire.lever.co · seen 2026-10-07
- partner integration process and FAQ hire.lever.co · seen 2026-10-07
- API updates page hire.lever.co · seen 2026-10-07
- deprecated Candidates endpoints hire.lever.co · seen 2026-10-07
- Postings API README and SECURITY.md github.com · seen 2026-10-07
- Postman collection and example OAuth app github.com · seen 2026-10-07
- status incidents (JSON) status.lever.co · seen 2026-10-07
- pricing page lever.co · seen 2026-10-07
- security page lever.co · seen 2026-10-07
- terms of service lever.co · seen 2026-10-07
- SLA employinc.com · seen 2026-10-07
- DPA employinc.com · seen 2026-10-07
- sub-processor list employinc.com · seen 2026-10-07
- services privacy notice employinc.com · seen 2026-10-07
- Developer Sandbox Terms employinc.com · seen 2026-10-07
- official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-07
- RDAP for lever.co rdap.registry.co · seen 2026-10-07
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid Paid No public price. lever.co/pricing has a quote form and says pricing scales with team size and hiring needs, with no trial, free tier or self-serve signup found. Lever's partner FAQ says OAuth integrations work for all customers, while API key use needs the Data API feature, requisition endpoints need the TRM Enterprise package or Advanced HR, and the audit events endpoint is an add-on. A sandbox account is free to approved partners only, so an agent can't start without a customer contract or partner approval. Reading a company's published jobs through the Postings API needs no account (checked 2026-10-07).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/lever.xml, or this listing's score history at history.json.
Connect
First request
curl -u "$LEVER_API_KEY:" "https://api.lever.co/v1/opportunities?limit=10&include=name&include=stage"
Through letme picks today, calling later
GET https://letme.dev/lever
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Greenhouse BAshby CSmartRecruiters CWorkable CBambooHR CRippling C
Head to head Ashby vs Lever · Greenhouse vs Lever · Lever vs SmartRecruiters · Lever vs Workable
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Greenhouse Greenhouse Software, Inc. | B | 64.8 | recruiting.candidates recruiting.jobs recruiting.applications recruiting.interviews recruiting.offer-letters | no |
| Ashby Ashby, Inc. | C | 61.3 | recruiting.candidates recruiting.jobs recruiting.applications recruiting.interviews recruiting.offer-letters | no |
| SmartRecruiters SmartRecruiters, Inc. (an SAP company) | C | 60.4 | recruiting.candidates recruiting.jobs recruiting.applications recruiting.interviews recruiting.offer-letters | no |
| Workable Workable Software Limited | C | 61.7 | recruiting.candidates recruiting.jobs recruiting.applications recruiting.offer-letters | no |
| BambooHR Bamboo HR LLC | C | 61.7 | recruiting.applications recruiting.jobs | no |
| Rippling People Center, Inc. dba Rippling | C | 60.8 | recruiting.candidates | no |
Machine-readable
- JSON
/api/v1/tools/lever.json· historyhistory.json· badge/badges/lever.svg· changes feed/feeds/tools/lever.xml - Markdown
/tools/lever.md· slim/tools/lever.min.md(or sendAccept: text/markdown) - Fix list
/fixes/lever.md·/fixes/lever.json - From a terminal
anchor tool lever --md(the CLI) · over MCPget_tool {"slug": "lever"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/lever"><img src="https://www.anchorterminal.com/badges/lever.svg" alt="Lever on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/lever)<a href="https://www.anchorterminal.com/tools/lever">Lever on Anchor Terminal</a>It counts on a page on lever.co or one of its subdomains, or the README of github.com/lever/postings-api.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "lever", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
