# Paychex > Paychex's REST API reads and updates company, worker and pay data in Paychex Flex, a US payroll and HR service. Clients create an app inside their Flex account. Software partners apply to Paychex for a sandbox and production credentials. - Canonical: https://www.anchorterminal.com/tools/paychex - Markdown: https://www.anchorterminal.com/tools/paychex.md (~8,750 tokens) - Slim: https://www.anchorterminal.com/tools/paychex.min.md (~1,830 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/paychex.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade E · 44.8/100 · rank #666 of 722 · #9 in Payroll infrastructure · not agent-ready · confidence medium** ## Assessment A public OpenAPI 3.0.3 definition covers 110 operations, and payroll entries stay unprocessed until a person submits the payroll in Flex. Partner credentials and the sandbox follow approval by Paychex, no price is published, and no status page, SLA or SDK was found in the reviewed pages. ## Facts | Field | Value | | --- | --- | | Vendor | Paychex, Inc. (https://www.paychex.com) | | Kind | HTTP API | | Category | Payroll infrastructure (https://www.anchorterminal.com/categories/payroll) | | Transport | HTTP | | Auth | OAuth · Graded on the Paychex API for Paychex Flex. Access is by OAuth 2.0 client credentials. A key and secret go in the form body of POST `/auth/oauth/v2/token` and return a Bearer token that lasts 60 minutes, with no refresh token. A Paychex client with a Super Admin or Security Admin role creates an app inside Flex and chooses its access levels. A software partner fills in a questionnaire, is reviewed by the Corporate Partnerships Team, builds in a sandbox Paychex issues, demos the integration and then receives a production key and secret limited to the verbs and endpoints requested. Each client approves a partner app in Flex before its data is reachable. | | Pricing | Paid (Paid) · No price is published for the API or for Paychex payroll. The Request Pricing button on paychex.com/payroll leads to the sales contact form, and the developer centre states no fee. The API reaches only companies with a paid Paychex Flex account, and the Payroll API needs online payroll added by a Paychex representative. The partner sandbox is issued after Paychex approves the partnership, so there is no way to start without Paychex's agreement (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the developer centre pages or the OpenAPI definition (checked 2026-10-08). | | Licence | Proprietary service. Public use is under the Paychex User Terms of Use. Partner terms aren't published | | Docs | https://developer.paychex.com/documentation | | llms.txt | not found | | Last release | 2026-08-20 | | Surface graded | Paychex API for Paychex Flex (REST, JSON) at https://api.paychex.com. 110 operations in the public OpenAPI 3.0.3 file, 60 GET, 19 POST, 15 PATCH and 16 DELETE | | Coverage | Companies, jobs, locations, organisations, labour assignments, pay components, pay periods and pay frequencies. Workers with communications, contacts, pay rates, direct deposits, federal and state tax, custom fields, documents, profile image, I-9 status and time off balances. Checks and check components. Webhooks and client access | | Payroll | Create, read and delete unprocessed checks and their pay components for an open pay period, and read processed checks. Submission stays with the client or a Paychex service provider in Flex | | Other Paychex APIs | Time and attendance punches and timecards are on a separate Stratustime API with its own documentation, per the FAQ. Not graded here | | Credentials | OAuth 2.0 client credentials. Key and secret in the form body of POST `/auth/oauth/v2/token`, Bearer token for 60 minutes, no refresh token. The sample token carries scopes such as `read:company_people` and `read:workers` | | Access steps | Clients create an app in Flex and choose access levels. Partners pass a questionnaire, a review, a sandbox build and a demo before production credentials. Each client approves the partner app in Flex | | Rate limits | 10,000 requests a minute per partner key and a burst of 2,000 a second, announced for 25 September. `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset` on responses, `Retry-After` on 429 | | Paging | `offset` and `limit` on GET `/companies`, company checks for a processed pay period, and company workers. An `ETag` holds the snapshot between pages. Metadata gives `itemCount` | | Errors | JSON `errors` array with `code` (such as `API-10`, `API-40`, `API-103`), `description` and `resolution`. 423 when the client is locked, 207 on a partly successful batch of workers | | Versioning | Vendor media types in the `Accept` header, such as `application/vnd.paychex.workers.v1+json`. A breaking change gets a new major media type. Each resource has a default | | Webhooks | POST `/management/hooks` with a public URL and domains. Receiver authentication by `BASIC_AUTH`, `API_KEY`, `OAUTH2`, `OAUTH2_BASIC` or `NO_AUTH`. Retries every five minutes. Duplicates are possible and carry a notification ID | | SDKs | None found. Links labelled SDK on the developer centre lead to documentation pages | | Certifications | SOC 1 Type 2 and SOC 2 Type 2 reports on request through a Paychex contact, ISO 27001 certificate IS 801702, per paychex.com/corporate/security | | Status | No status page found. status.paychex.com didn't resolve on 8 October 2026 | | Capabilities | payroll.employees, hr.employees, hr.onboarding, hr.documents, hr.org | | Tags | hosted, payroll, hr, oauth, openapi, partner-approval, sandbox, webhooks, sales-led, soc2, iso27001 | | JSON | https://www.anchorterminal.com/api/v1/tools/paychex.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 41 | 8.2 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 66 | 10.7 | | Agent ergonomics | 13% | 16.2 | 54 | 8.8 | | Security & auth | 14% | 17.5 | 58 | 10.2 | | Payments & pricing | 10% | 12.5 | 0 | 0.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 26 | 2.3 | | Transparency & trust (editorial 39, provenance 69) | 7% | 8.8 | 54 | 4.7 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **44.8 → E** | ### Why each score - Reliability 41: Read with the hosted lines and scored on the Paychex API at https://api.paychex.com. No status page was found on the developer centre or the security page, and status.paychex.com didn't resolve (0). With no page there is no readable incident history (5). The rate limiting page gives 10,000 requests a minute per partner key and a burst of 2,000 a second. It is headed coming soon for 25 September with no year, and we couldn't confirm the limit is live (15). 429 responses carry `Retry-After` and three `X-RateLimit` headers, and 423 tells a caller the client is locked and to retry later. The `X-payx-client-correlationId` header is said to be usable for idempotency, with no rules for how a repeated ID is treated (11 of 15). No SLA was found, and the User Terms of Use say Paychex doesn't guarantee availability (0). The API is version 1.0 with no beta or preview label (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 66: One public OpenAPI 3.0.3 file with 68 paths, 110 operations and 147 schemas, drawn by Redoc on the documentation page (25). developer.paychex.com/llms.txt returns 404 and the guides are HTML only. The llms.txt on www.paychex.com lists marketing pages (0). Operation descriptions have a median length of 63 characters. A few, such as adding in-progress workers, explain statuses and limits, and most restate the summary without saying when not to use the call (11 of 20). 48 enums, 244 required lists and 162 formats, with no patterns or length limits, and the file declares no security scheme or scopes (10 of 15). About 250 named request and response examples, and each operation lists error responses with codes such as `API-40` and `API-10` (13 of 15). Versioning by vendor media type is documented. The News page holds two notices and there is no dated changelog (7 of 15). - Agent ergonomics 54: Scored as an HTTP API. Lists are sized with `offset` and `limit` on three endpoints, and vendor media type profiles select a response shape, among them non-PII worker profiles. No field selection (13 of 25). Paging exists on companies, company checks and company workers only. Workers can be filtered by name, employee ID, location, status and creation dates, but the reference says paging and filters can't be combined (11 of 20). Errors carry `code`, `description` and `resolution` and are listed per operation (16 of 20). A correlation ID header, `workerCorrelationId` on batches, 207 for partial success and 423 on a locked client help retries. No idempotency key with stated behaviour was found, and there are no MCP annotations to read (8 of 20). Each resource has a default media type and most calls need only a path ID. No SDK was found in any language (6 of 15). - Security & auth 58: OAuth 2.0 client credentials with the key and secret in the request body, 60-minute Bearer tokens and no refresh token. A client chooses an app's access levels in Flex, a partner app is limited to the verbs and endpoints Paychex grants, and the sample token carries scopes such as `read:company_people`. No way to rotate a secret was found in the reviewed pages (24 of 30). We took 5 off, not the checklist's 10, because the webhook option `OAUTH2` sends the receiver's own client ID and secret as query parameters and the API's credential never travels in a URL (19). A client admin approves each partner app in Flex and access can be removed. Checks are created unprocessed and a person submits the payroll. Direct deposit and tax changes apply without a second step (16 of 20). Responses include free text such as memos, custom fields and documents, and no guidance on untrusted content was found (3 of 15). Every response has an `x-payx-txid`. No per-call log for the operator was found (5 of 15). A responsible disclosure policy with a form run with Bugcrowd and no monetary award, SOC 1 Type 2 and SOC 2 Type 2 reports on request, ISO 27001 certificate IS 801702. No security.txt (15 of 20). - Payments & pricing 0: Read with the hosted rubric. No x402, MPP or L402 (0). No price is published for the API or for payroll. The Request Pricing button leads to the sales contact form (0). No free tier or trial was found. The sandbox is issued only after Paychex approves a partnership, and a client needs a Paychex Flex account (0). A person fills in a questionnaire or creates the app inside Flex, and Paychex issues the credentials (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 26: The OpenAPI file was last modified on 20 August 2026, 49 days before this check. The two News notices give no year for their own dates (20 of 30). Three dated changes in the last 90 days couldn't be established (0). Closed service with a support form split into five request types, an FAQ and a chat widget on the developer centre. No public forum or issue tracker was found (6 of 15). No official SDK was found (0). No packages or public CI to assess (0). - Transparency & trust 54: Closed service. The Paychex User Terms of Use, effective 1 June 2026, are public and cover Paychex's sites, applications and services. The partner agreement and the Third-Party Terms of Use a client accepts in Flex weren't found in public (12 of 30). The privacy policy, last updated 1 June 2026, covers data Paychex holds as a service provider for clients and says personal information isn't sold for third-party marketing. Retention is stated as long as necessary with no periods, the terms let Paychex use submitted information to improve its services and AI tools, and no public DPA was found (12 of 30). Deprecations are announced with dates. The unpaged worker list ends on 24 February 2027 and the versioning page promises never to drop fields within a version. No notice period is stated, and the reference still warns that POST federal tax will be deprecated on 30 January 2026 (12 of 20). No sub-processor list or data locations were found. The webhooks page names three production sites as WDC, HDC and ODC (3 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (24 items): https://www.anchorterminal.com/fixes/paychex.md (JSON https://www.anchorterminal.com/fixes/paychex.json) ### What we couldn't check - unchecked: whether rate limiting is live. The page is headed coming soon for 25 September with no year, and the unauthenticated 401 we received carried no `X-RateLimit` headers - unchecked: the partner agreement and the Third-Party Terms of Use a client accepts in Flex. Neither was found in public, so the terms link is the User Terms of Use - unchecked: any fee Paychex charges partners or clients for API access. No figure is published - unchecked: the 2026 overview PDF of Paychex's security programme linked from the security page, which we didn't read - unchecked: Paychex's GitHub organisation. github.com/paychex exists, and the GitHub API refused us for its rate limit, so whether any repository is an API client is unconfirmed. The developer centre names none - unchecked: the Paychex Marketplace page, which is drawn by script - Whether a status page exists under another address. None is linked from the developer centre, the security page or the support form - Whether `X-payx-client-correlationId` makes a repeated POST safe. The headers page says it can be used for idempotency and gives no rules - The security page lists bug bounty programmes among its assessments, while the responsible disclosure page says the programme pays no award - The User Terms of Use bar robots and other automatic means of access unless Paychex approves, and bar using the sites to develop or train AI. How this applies to an approved API app isn't stated. Recorded as a fact with no deduction - www.paychex.com/llms.txt carries usage guidelines addressed to AI models. We read it as data and didn't act on it - The listing omits `payroll.run` because the API enters checks but can't submit a payroll - The OpenAPI file's name includes develop.210 and its examples list pre-processing and AI option resources that have no public path ### Sources - developer centre home: (seen 2026-10-08) - client process: (seen 2026-10-08) - partner process: (seen 2026-10-08) - partner questionnaire: (seen 2026-10-08) - API reference page (Redoc): (seen 2026-10-08) - OpenAPI 3.0.3 definition, operations, schemas, errors and Last-Modified header: (seen 2026-10-08) - getting started overview: (seen 2026-10-08) - authentication guide and sample token: (seen 2026-10-08) - sandbox issued after approval: (seen 2026-10-08) - linking a client and approval in Flex: (seen 2026-10-08) - webhook domains, registration and errors: (seen 2026-10-08) - authentication, token life and no refresh: (seen 2026-10-08) - request and response headers: (seen 2026-10-08) - versioning policy: (seen 2026-10-08) - vendor media types: (seen 2026-10-08) - paging: (seen 2026-10-08) - rate limiting: (seen 2026-10-08) - webhooks, retries, receiver authentication and IP addresses: (seen 2026-10-08) - worker onboarding rules: (seen 2026-10-08) - FAQ, sandbox, payroll access and Stratustime: (seen 2026-10-08) - payroll use case and who submits payroll: (seen 2026-10-08) - News notices: (seen 2026-10-08) - support form: (seen 2026-10-08) - developer centre llms.txt, 404: (seen 2026-10-08) - unauthenticated call, 401 with API-103: (seen 2026-10-08) - Paychex User Terms of Use, effective 1 June 2026: (seen 2026-10-08) - privacy policy, last updated 1 June 2026: (seen 2026-10-08) - security page, SOC reports and ISO 27001: (seen 2026-10-08) - responsible disclosure policy: (seen 2026-10-08) - payroll page and Request Pricing link: (seen 2026-10-08) - llms.txt on the main site: (seen 2026-10-08) - security.txt, 404: (seen 2026-10-08) - licences and legal entities: (seen 2026-10-08) - RDAP record for paychex.com: (seen 2026-10-08) - official MCP registry search, no entries: (seen 2026-10-08) ## Who's behind it (provenance 69/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Paychex, Inc. | 20/20 | | Domain age | paychex.com, registered 1991-06-10 (35 years) | 15/15 | | Endpoint on the vendor's domain | paychex.com | 15/15 | | Terms of service | read, states 5 of the 7 things a reader expects, and has 3 clauses that cost points | 2.3/10 | | Privacy policy | read, states 6 of the 8 things a reader expects, and has 1 clause that costs points | 6.5/10 | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The privacy policy (last updated 1 June 2026) names Paychex, Inc., 911 Panorama Trail South, Rochester, NY 14625. The terms link is the Paychex User Terms of Use, effective 1 June 2026, which govern Paychex's websites, software applications, mobile applications and services. No API-specific terms are published. The partner agreement and the Third-Party Terms of Use a client accepts in Flex weren't found in public. API calls go to https://api.paychex.com. An unauthenticated GET `/companies` answered 401 with error code API-103. www.paychex.com/.well-known/security.txt, www.paychex.com/security.txt and developer.paychex.com/.well-known/security.txt return 404. Vulnerability reports go through a form at paychex.com/corporate/security/responsible-disclosure run with Bugcrowd. No status page was found on the developer centre or the security page, and status.paychex.com didn't resolve. The changelog link is the developer centre's News page, which holds two notices and no dated list of changes. RDAP for paychex.com gives a registration date of 1991-06-10. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.paychex.com/corporate/terms), read 2026-10-08, gives no date, states 5 of the 7 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "Paychex may use information you provide to develop, improve, upgrade, or enhance the performance, accuracy, reliability, and usefulness of our services, business operations, and AI Powered Features, or as otherwise permitted by these Terms." - To know. Restricts automated access (costs points). "Use any robot, spider, or other automatic device, process, or means to access the Sites for any purpose, including, but not limited to, scraping, crawling, harvesting, monitoring or copying any of the material on the Sites, except as otherwise expressly approved by Paychex." - To know. Says the terms or the service can change without notice (costs points). "Paychex and its licensors reserve the right to change, suspend, remove, or disable access to any Services at any time without notice." - To know. Says access can be ended without notice or for any reason. "Paychex reserves the right to limit, suspend, or terminate your use of the Sites and/or Third-Party Services, without notice, should Paychex have reason to believe that the security or confidentiality of the Site has been compromised." - To know. Requires arbitration or waives class actions. "…with, the Sites, without regard to the theory of liability asserted, shall be determined only by binding arbitration in Rochester, New York, administered by the American Arbitration Association (“AAA”) in accordance with its Commercial Arbitration Rules." - Not found in the text. Gives the date it was last updated. - Names the governing law or courts. The law of the State of New York. - States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence. - Says how changes to the terms are announced. Says it gives notice of a change. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). The terms prohibit using the sites to develop, train or improve artificial intelligence, tools or products. "To develop, train, or improve artificial intelligence, tools, or products." - Also in the text (2026-10-08). AI tools on the sites must not be used for automated decision making unless a human oversees the final decision. "You shall not utilize AI Powered Features for automated decision making without ensuring any final decision is made with human oversight." - Also in the text (2026-10-08). Users must not rely on AI output for legal, financial, health or employment decisions and are solely responsible for any use of it. "You shall not rely on any output for legal, financial, health, or employment decisions and are solely responsible for the use of, or reliance on, the information provided by AI Powered Features and any action taken thereof" **Privacy policy** (https://www.paychex.com/corporate/security/privacy), read 2026-10-08, dated 2026-06-01, states 6 of the 8 things a reader expects. - To know. Says it may use customer content to train or improve models, and no opt-out was found (costs points). "other information provided by You (or on Your behalf), may be collected, processed, and used to perform or offer Services, offer additional services, support functionality, maintain security, improve the overall performance, reliability, and usefulness of AI Powered Features" - Gives the date it was last updated. Last updated 2026-06-01. - Says how long data is kept. For as long as needed, with no period named. - Not found in the text. Gives a privacy contact. - Not found in the text. Says where data is transferred or stored. - Also in the text (2026-10-08). Paychex treats every interaction and transaction as authorised by the account holder, even when another person started or completed it. "We will treat all interactions and transactions as though You authorized them, and as though they are authorized interactions and transactions, even if another person initiated or completed them." - Also in the text (2026-10-08). For logged-in accounts Paychex may record mouse movement, clicks, page visits and screen information. "If You use an account to access our Site, Paychex may also use certain technologies to record Your mouse movement, clicks, page visits, and screen information to enhance Your experience, for our own security purposes, and to improve our Site." ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - One public OpenAPI 3.0.3 file describes 110 operations and 147 schemas, with named request and response examples for most of them - Checks are created as unprocessed entries. The docs say the client or a Paychex service provider must review and submit the payroll - A client admin approves each partner app inside Paychex Flex before any company data is reachable, and a delete endpoint removes the link - Errors return a `code`, `description` and `resolution`, and every response carries an `x-payx-txid` for support - Published limit of 10,000 requests a minute per partner, with `X-RateLimit-*` headers and `Retry-After` on 429 ## Weaknesses - Partner access needs a questionnaire, review by the Corporate Partnerships Team, a demo and final approval. The sandbox is issued only after approval - No price is published for the API or for Paychex payroll. The pricing button leads to a sales contact form - No status page, incident history or SLA was found, and the User Terms of Use give no availability guarantee - Paging works on three endpoints only, and on the worker list it can't be combined with filters - No SDK, llms.txt or dated changelog was found. The News page holds two notices - The User Terms of Use bar automated access to Paychex sites and applications unless Paychex approves it, and allow suspension without notice ## Before you call it (notes for agents) 1. POST `grant_type=client_credentials` with the key and secret in the form body to `/auth/oauth/v2/token`. Tokens last 60 minutes and there is no refresh token, so request a new one 2. Call GET `/companies` first. Worker and payroll paths need a `companyId` or `workerId` the app has been granted 3. Send `offset` and `limit` on GET `/companies/{companyId}/workers`, 50 at most, and resend the `ETag` between pages. The unpaged form is withdrawn on 24 February 2027 4. Creating a check doesn't pay anyone. A person must review and submit the payroll in Paychex Flex 5. Send a unique `X-payx-client-correlationId` per request and keep the `x-payx-txid` from the response. Support asks for it 6. On 423 the client is locked by another user or process. Wait and retry ## Connect First request: ```bash curl --location 'https://api.paychex.com/auth/oauth/v2/token' \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data-urlencode 'grant_type=client_credentials' \ --data-urlencode 'client_id=CLIENT_ID' \ --data-urlencode 'client_secret=CLIENT_SECRET' ``` Through letme (picks today, calling later): https://letme.dev/paychex. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Finch | BB | 71.6 | 104 | payroll.employees, hr.employees, hr.org, hr.documents | no | https://www.anchorterminal.com/tools/finch.md | | Deel | B | 69.1 | 168 | hr.employees, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/deel.md | | BambooHR | C | 61.7 | 357 | hr.employees, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/bamboohr.md | | Rippling | C | 60.8 | 386 | hr.employees, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/rippling.md | | HiBob | C | 57 | 484 | hr.employees, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/hibob.md | | Zoho People | C | 55 | 523 | hr.employees, hr.org, hr.onboarding, hr.documents | no | https://www.anchorterminal.com/tools/zoho-people.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The API reference is one OpenAPI 3.0.3 file drawn by Redoc, with 68 paths and 110 operations under six tags (Authentication, Company, Payroll, Worker, Webhooks, Management). The server is https://api.paychex.com and the file was last modified on 20 August 2026 (source: ) - Partners fill in a questionnaire, the Corporate Partnerships Team reviews it, Paychex creates the partner application and a sandbox, and the partner demos the integration before Paychex issues a production key and secret (source: ) - Clients with a Super Admin or Security Admin role create an app in Paychex Flex under Company Settings and choose its access levels. Payroll API access needs online payroll added to the account by a Paychex representative (source: ) - The payroll use case states that an API integration can send payroll data but the client or a Paychex service provider must still review and complete the submission (source: ) - POST `/management/requestclientaccess` with a client's 8-digit `displayId` returns an approval link, and the client's Flex admin approves or denies the app and accepts the Third-Party Terms of Use (source: ) - Rate limiting is announced for 25 September at 10,000 requests a minute per partner with a burst of 2,000 a second. The page still carries a coming soon heading and states no year (source: ) - GET `/companies/{companyId}/workers` will return at most 50 workers a call, and the unpaged form is to be decommissioned by 24 February 2027 (source: ) - Webhooks cover 13 partner domains such as `WRKR_ADD`, `CLT_ACCESS` and `CLT_PYRN`. Failed deliveries are retried every five minutes until a 2XX answer, and notifications say that a field changed without giving the new value (source: ) - www.paychex.com/llms.txt lists marketing pages and carries AI usage guidelines addressed to AI models. It doesn't mention the API, and developer.paychex.com/llms.txt returns 404. Recorded as a fact (source: ) - The security page lists SOC 1 Type 2 and SOC 2 Type 2 reports and ISO 27001 certificate IS 801702. Vulnerability reports go through a form run with Bugcrowd, with no monetary award (source: ) ## Compare - [Argyle vs Paychex](https://www.anchorterminal.com/compare/argyle-vs-paychex.md): B 63.7 vs E 44.8 - [Check vs Paychex](https://www.anchorterminal.com/compare/check-payroll-vs-paychex.md): B 67.5 vs E 44.8 - [Employment Hero Payroll vs Paychex](https://www.anchorterminal.com/compare/employment-hero-vs-paychex.md): D 50.4 vs E 44.8 - [Everee vs Paychex](https://www.anchorterminal.com/compare/everee-vs-paychex.md): C 55.1 vs E 44.8 - [Finch vs Paychex](https://www.anchorterminal.com/compare/finch-vs-paychex.md): BB 71.6 vs E 44.8 - [Gusto vs Paychex](https://www.anchorterminal.com/compare/gusto-vs-paychex.md): B 63.3 vs E 44.8 - [Paychex vs Salsa](https://www.anchorterminal.com/compare/paychex-vs-salsa.md): E 44.8 vs D 46.1 - [Paychex vs Zeal](https://www.anchorterminal.com/compare/paychex-vs-zeal.md): E 44.8 vs E 45.4 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on paychex.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "paychex", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Paychex on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Paychex on Anchor Terminal](https://www.anchorterminal.com/badges/paychex.svg)](https://www.anchorterminal.com/tools/paychex) ``` Plain link: ```html Paychex on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Paychex is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/paychex-dark.png - Light: https://www.anchorterminal.com/assets/share/paychex-light.png