# Paychex (slim) > Paychex's REST API reads and updates company, worker and pay data in Paychex Flex, a US payroll and HR service. Clients create an app inside their Flex account. Software partners apply to Paychex for a sandbox and production credentials. - Full: https://www.anchorterminal.com/tools/paychex.md (~8,750 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/paychex.json · canonical https://www.anchorterminal.com/tools/paychex - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **E · 44.8/100 · rank #666 of 722 · #9 in Payroll infrastructure · not agent-ready · confidence medium** Assessment: A public OpenAPI 3.0.3 definition covers 110 operations, and payroll entries stay unprocessed until a person submits the payroll in Flex. Partner credentials and the sandbox follow approval by Paychex, no price is published, and no status page, SLA or SDK was found in the reviewed pages. ## Facts - Kind: HTTP API · vendor: Paychex, Inc. · category: Payroll infrastructure · legal entity: Paychex, Inc. · provenance 69/100 - Local only (HTTP) - Auth: OAuth · pricing: Paid · x402: no · licence: Proprietary service. Public use is under the Paychex User Terms of Use. Partner terms aren't published - Probe metrics: not measured yet (probes haven't run) - Surface graded: Paychex API for Paychex Flex (REST, JSON) at https://api.paychex.com. 110 operations in the public OpenAPI 3.0.3 file, 60 GET, 19 POST, 15 PATCH and 16 DELETE - Coverage: Companies, jobs, locations, organisations, labour assignments, pay components, pay periods and pay frequencies. Workers with communications, contacts, pay rates, direct deposits, federal and state tax, custom fields, documents, profile image, I-9 status and time off balances. Checks and check components. Webhooks and client access - Payroll: Create, read and delete unprocessed checks and their pay components for an open pay period, and read processed checks. Submission stays with the client or a Paychex service provider in Flex - Other Paychex APIs: Time and attendance punches and timecards are on a separate Stratustime API with its own documentation, per the FAQ. Not graded here - Credentials: OAuth 2.0 client credentials. Key and secret in the form body of POST `/auth/oauth/v2/token`, Bearer token for 60 minutes, no refresh token. The sample token carries scopes such as `read:company_people` and `read:workers` - Access steps: Clients create an app in Flex and choose access levels. Partners pass a questionnaire, a review, a sandbox build and a demo before production credentials. Each client approves the partner app in Flex - Rate limits: 10,000 requests a minute per partner key and a burst of 2,000 a second, announced for 25 September. `X-RateLimit-Limit`, `X-RateLimit-Remaining` and `X-RateLimit-Reset` on responses, `Retry-After` on 429 - Paging: `offset` and `limit` on GET `/companies`, company checks for a processed pay period, and company workers. An `ETag` holds the snapshot between pages. Metadata gives `itemCount` - Errors: JSON `errors` array with `code` (such as `API-10`, `API-40`, `API-103`), `description` and `resolution`. 423 when the client is locked, 207 on a partly successful batch of workers - Versioning: Vendor media types in the `Accept` header, such as `application/vnd.paychex.workers.v1+json`. A breaking change gets a new major media type. Each resource has a default - Webhooks: POST `/management/hooks` with a public URL and domains. Receiver authentication by `BASIC_AUTH`, `API_KEY`, `OAUTH2`, `OAUTH2_BASIC` or `NO_AUTH`. Retries every five minutes. Duplicates are possible and carry a notification ID - SDKs: None found. Links labelled SDK on the developer centre lead to documentation pages - Certifications: SOC 1 Type 2 and SOC 2 Type 2 reports on request through a Paychex contact, ISO 27001 certificate IS 801702, per paychex.com/corporate/security - Status: No status page found. status.paychex.com didn't resolve on 8 October 2026 - Scores: Reliability 41, Performance pending, Schema & documentation 66, Agent ergonomics 54, Security & auth 58, Payments & pricing 0, Task success pending, Maintenance & community 26, Transparency & trust 54 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the Paychex API at https://api.paychex.com. · Schema & documentation, One public OpenAPI 3.0.3 file with 68 paths, 110 operations and 147 schemas, drawn by Redoc on the documentation page (25). · Agent ergonomics, Scored as an HTTP API. · Security & auth, OAuth 2.0 client credentials with the key and secret in the request body, 60-minute Bearer tokens and no refresh token. · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The OpenAPI file was last modified on 20 August 2026, 49 days before this check. · Transparency & trust, Closed service. - Sources: 35, open questions: 13, both in the full twin - Capabilities: payroll.employees, hr.employees, hr.onboarding, hr.documents, hr.org - JSON: https://www.anchorterminal.com/api/v1/tools/paychex.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/paychex.svg` or a link to https://www.anchorterminal.com/tools/paychex from a page on paychex.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. POST `grant_type=client_credentials` with the key and secret in the form body to `/auth/oauth/v2/token`. Tokens last 60 minutes and there is no refresh token, so request a new one 2. Call GET `/companies` first. Worker and payroll paths need a `companyId` or `workerId` the app has been granted 3. Send `offset` and `limit` on GET `/companies/{companyId}/workers`, 50 at most, and resend the `ETag` between pages. The unpaged form is withdrawn on 24 February 2027 4. Creating a check doesn't pay anyone. A person must review and submit the payroll in Paychex Flex 5. Send a unique `X-payx-client-correlationId` per request and keep the `x-payx-txid` from the response. Support asks for it 6. On 423 the client is locked by another user or process. Wait and retry ## Connect ```bash curl --location 'https://api.paychex.com/auth/oauth/v2/token' \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data-urlencode 'grant_type=client_credentials' \ --data-urlencode 'client_id=CLIENT_ID' \ --data-urlencode 'client_secret=CLIENT_SECRET' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/paychex ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Finch | BB | 71.6 | payroll.employees, hr.employees, hr.org, hr.documents | https://www.anchorterminal.com/tools/finch.min.md | | Deel | B | 69.1 | hr.employees, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/deel.min.md | | BambooHR | C | 61.7 | hr.employees, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/bamboohr.min.md | | Rippling | C | 60.8 | hr.employees, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/rippling.min.md | | HiBob | C | 57 | hr.employees, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/hibob.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)