# PayFit > PayFit is payroll and HR software for small and mid-sized employers in France, the United Kingdom and Spain. Its Partner API reads employees, contracts, payslips, absences and accounting exports, with a customer API key or partner OAuth. - Canonical: https://www.anchorterminal.com/tools/payfit - Markdown: https://www.anchorterminal.com/tools/payfit.md (~7,300 tokens) - Slim: https://www.anchorterminal.com/tools/payfit.min.md (~1,480 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/payfit.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade C · 55.5/100 · rank #656 of 950 · #5 in Payroll infrastructure · not agent-ready · confidence medium** ## Assessment A public OpenAPI 3.0 file, llms.txt and scoped keys let a paying customer's agent read payroll outputs and write absences. The API cannot run or approve a payroll, new partner integrations are not being accepted, and no idempotency keys or SDKs were found. ## Facts | Field | Value | | --- | --- | | Vendor | PayFit SAS (https://payfit.com) | | Kind | HTTP API | | Category | Payroll infrastructure (https://www.anchorterminal.com/categories/payroll) | | Transport | HTTP | | Auth | OAuth or key · Two routes. A customer's company admin creates an API key in the PayFit app at app.payfit.com/integrations/hub/api, picks its scopes, and sees it once. It is sent as a Bearer token and reaches that company only. Partners use the OAuth 2.0 authorisation code grant at oauth.payfit.com with a client ID and secret that PayFit issues after reviewing the use case, and the scopes a partner may request are fixed at approval. The partner guides say PayFit is temporarily not accepting new integration requests. | | Pricing | Paid (Paid) · No charge for API calls was found. Access comes with a PayFit subscription. In France the API is included from the Paie avancée plan, listed at 27 € a collaborator a month plus a 49 € monthly subscription for 1 to 3 collaborators, before tax. The UK site lists no prices and sends buyers to a demo, and its contract appendix includes API access in the Payroll Core plan. The French site links a free signup and a first month free until 31 October 2026. Whether signup needs a card was not established. A sandbox company is given only to accepted partners (checked 2026-10-09). | | x402 | No · No x402, MPP or L402 in the API guides, the OpenAPI file or the French pricing page (checked 2026-10-09). | | Licence | Proprietary service under PayFit's general terms of service | | Docs | https://developers.payfit.io/ | | llms.txt | https://developers.payfit.io/llms.txt | | Last release | 2026-07-23 | | API | Partner API 1.0, OpenAPI 3.0.0, 31 operations at https://partner-api.payfit.com. 22 GET, 5 POST, 2 PUT (France only), 1 DELETE and 1 billing declaration for partners | | Coverage by country | 12 operations for France, the UK and Spain, 15 for France only (French contracts, accounting exports, health insurance, meal vouchers, worked time, contract creation), 2 for the UK only (income tax and auto enrolment documents) | | Credentials | Customer API key created by a company admin with chosen scopes, sent as a Bearer token. Partners use the OAuth 2.0 authorisation code grant with a client ID and secret issued by PayFit, and one token per company per client | | Scopes | 22 in the OpenAPI file, such as `collaborators:read`, `collaborators:bank-info:read`, `contracts:payslips:read`, `accounting:read`, `time:write` and `health-insurance:write` | | Rate limits | 50 requests a second for reads and 20 for writes, per client application. 429 answers `{"message": "API rate limit exceeded"}` with `X-RateLimit-Limit-Second` and `X-RateLimit-Remaining-Second` headers | | Pagination | `nextPageToken` and `maxResults` (default 10, maximum 50) on six list operations. Filters by email, contract, status and date range | | Webhooks | Delivered through Svix for partners, on request to PayFit | | Plans with the API (France) | Paie avancée at 27 € a collaborator a month plus a 49 € monthly subscription for 1 to 3 collaborators, and RH+ at 30 € plus 49 €, both before tax. Not in the Paie plan at 20 € | | Status page | https://status.payfit.com on StatusPal, ten components including Run Payroll and Custom integrations, with incident history | | Capabilities | payroll.employees, hr.time-off, hr.employees | | Tags | hosted, payroll, hr, api-key, oauth, openapi, llms-txt, webhooks, france, uk, spain, status-page, iso-27001 | | JSON | https://www.anchorterminal.com/api/v1/tools/payfit.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-09 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 79 | 15.8 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 78 | 12.7 | | Agent ergonomics | 13% | 16.2 | 51 | 8.3 | | Security & auth | 14% | 17.5 | 51 | 8.9 | | Payments & pricing | 10% | 12.5 | 10 | 1.2 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 28 | 2.5 | | Transparency & trust (editorial 56, provenance 84) | 7% | 8.8 | 70 | 6.1 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **55.5 → C** | ### Why each score - Reliability 79: Read with the hosted lines. https://status.payfit.com is a StatusPal page with ten components, including Run Payroll and Custom integrations (data synchronisation through custom APIs), and an incident history of 115 entries (20). Between 11 July and 9 October 2026 it lists two incidents, both on the help centre component. On 16 September support functions were degraded during a Salesforce incident, and on 17 September customer callbacks failed for 15 minutes in France. Neither touched payroll or the API (27 of 30). Limits are 50 requests a second for reads and 20 for writes, per client application (15). The rate limit page gives the 429 body and `X-RateLimit` headers and suggests wait and retry. No Retry-After header and no idempotency keys were found, and the API has five POST operations (7 of 15). No SLA was found. The terms say the services may be temporarily unavailable and that PayFit endeavours to maintain outside business hours (0). The spec is version 1.0 with no beta label (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 78: A public OpenAPI 3.0.0 file, linked from the FAQ, with 31 operations and 19 named schemas (25). llms.txt indexes a Markdown twin of every guide, reference and changelog page (10). All 31 operations have a description that names the required scope and the countries served, and a few state limits, such as a created collaborator not appearing in the app until it has a contract. None say when not to use an operation (12 of 20). 74 enums, 226 required lists and patterns on month parameters. `maxResults` is typed as a string and several error fields accept any object (11 of 15). 199 examples, and every operation documents 400, 401, 403 and 404 with an example body. No 429 or 5xx response is in the file (11 of 15). The changelog has ten entries, the latest dated 23 July 2026. The path carries no version, and the October 2024 entry removed a field in the same note that announced it (9 of 15). - Agent ergonomics 51: List operations take `maxResults` (default 10, maximum 50), one operation takes a `fields` parameter, and the FAQ says responses carry ETags (14 of 25). `nextPageToken` paging on six list operations, with filters by email, contract, status and date range (16 of 20). Errors are JSON with an `error` string and `details`, such as 'Missing scope "contracts:read"'. Our one unauthenticated request answered 401 with a message and a `request_id`. No error catalogue was found (12 of 20). No idempotency keys were found for the five POST operations. This is an HTTP API with no MCP annotations to read (3 of 20). Most reads need only the company ID and a month. No official SDK was found, and the docs carry one JavaScript recipe (6 of 15). - Security & auth 51: Customer API keys are created by a company admin with chosen scopes and shown once. Partners use the OAuth 2.0 authorisation code grant with scopes fixed at approval, and the guide says a token can be revoked at any time. No token expiry or refresh token is documented (26 of 30). The webhook guide documents a call with `clientSecret` in the URL query string, which takes 10 off under the checklist (16). 22 scopes separate read from write and split out bank details, social security numbers and payslips. A contract created through the API stays unfinished until an HR admin completes it. `POST /absences` creates an absence already validated, with no approval step (13 of 20). The API returns names, job titles and other text entered by employees and admins, and no guidance on treating it as untrusted was found (3 of 15). The security page describes audit logs of authentication and data access kept for one year. No per-call log for the customer was found (5 of 15). The security page states ISO 27001 certification and a private bug bounty on HackerOne, and a contact page gives security@payfit.com with a PGP key. No security.txt, and the trust centre was unread (14 of 20). - Payments & pricing 10: Read with the hosted rubric. No x402, MPP or L402 (0). The French site publishes plan prices without a login. The API is included from Paie avancée at 27 € a collaborator a month plus a 49 € monthly subscription for 1 to 3 collaborators. The UK site lists no prices. That is public plan pricing with no per-call charge (10). The French site links a free signup and a first month free until 31 October 2026. Whether it needs a card was not established, and a sandbox company goes only to accepted partners, so the line scores as absent (0). A person signs up and an admin creates the key in the browser (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 28: Closed service. The latest dated changelog entry is 23 July 2026, 78 days before the check (20 of 30). That is the only entry since 11 July 2026, so the line for three entries in 90 days is not met. The one before is 12 June 2026 (0). A public changelog exists. The docs send API questions to the help centres, which robots.txt closes to us, and the partner guides say new integration requests are not being accepted (5 of 15). No official SDK was found (0 of 15). Guide pages carry update dates between March and June 2026 and the OpenAPI file matches the reference pages (3 of 10). - Transparency & trust 70: Closed service. The general terms of service (15 June 2026 for the UK, 8 September 2026 for France) name the contracting entity and mention the API in the third-party services clause. No separate API terms were found (15 of 30). The privacy policy gives a retention table, such as six years after the contract ends for client data, and the terms set deletion 12 months after termination. The data processing rules in the appendix give ten days to object to a new sub-processor. A separate sub-processor page, last revised 31 May 2021, lists two companies while the appendix lists more, including Amazon Web Services (20 of 30). No deprecation policy was found. The changelog marks fields and one scope as deprecated without removal dates (5 of 20). The appendix lists sub-processors by purpose and region, and the security page states storage in France across three data centres (16 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (22 items): https://www.anchorterminal.com/fixes/payfit.md (JSON https://www.anchorterminal.com/fixes/payfit.json) ### What we couldn't check - unchecked: support.payfit.com, the help centre the docs name for API support, because its robots.txt disallows every path - unchecked: the trust centre at trust.payfit.com, a script-drawn Vanta page, so the certificate, penetration testing and any further sub-processor detail are unconfirmed - unchecked: the security white paper PDF linked from the security page - unchecked: whether the French signup at welcome.payfit.com needs a card, and whether a trial account can create an API key - unchecked: the official MCP registry. No MCP server was found on the vendor's pages read - unchecked: the webhook event list, which is hosted by Svix - Whether customer API keys expire or can be rotated. The guide says only that a key is shown once - Which UK plans include the API. The appendix lists it under Payroll Core, while a blog post says Standard or Premium - Whether a customer contract carries an SLA. None is in the public terms - Whether 429 responses carry a Retry-After header. The guide names only `X-RateLimit` headers - The terms pointed to are the UK entity's English text. French and Spanish clients contract under their own versions, and the Spanish one was not read - The sitemap at payfit.com/sitemap.xml was fetched before the terms, to find the terms page ### Sources - documentation index: (seen 2026-10-09) - OpenAPI 3.0 file, read as the API description in place of the rendered reference pages: (seen 2026-10-09) - customer API key guide: (seen 2026-10-09) - partner OAuth guide: (seen 2026-10-09) - partner onboarding and the notice that new requests are closed: (seen 2026-10-09) - rate limits: (seen 2026-10-09) - webhook guide: (seen 2026-10-09) - changelog with entry dates: (seen 2026-10-09) - general terms of service, UK, 15 June 2026: (seen 2026-10-09) - general conditions, France, 8 September 2026: (seen 2026-10-09) - website terms of use, 24 April 2026: (seen 2026-10-09) - privacy policy, 15 June 2026: (seen 2026-10-09) - contract appendix with plans, data processing rules and sub-processors: (seen 2026-10-09) - sub-processor page revised 31 May 2021: (seen 2026-10-09) - security page: (seen 2026-10-09) - security contact page: (seen 2026-10-09) - French plans and prices: (seen 2026-10-09) - API announcement, France: (seen 2026-10-09) - API announcement, UK: (seen 2026-10-09) - status page: (seen 2026-10-09) - incident history: (seen 2026-10-09) - one unauthenticated request, which answered 401 with a JSON message: (seen 2026-10-09) - domain registration: (seen 2026-10-09) ## Who's behind it (provenance 84/100, checked 2026-10-09) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | PayFit SAS | 20/20 | | Domain age | payfit.com, registered 2006-11-17 (19 years) | 15/15 | | Endpoint on the vendor's domain | payfit.com | 15/15 | | Terms of service | read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points | 4.3/10 | | Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 | | Status page | status.payfit.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The French general conditions (last updated 8 September 2026) name Payfit, a société par actions simplifiée registered in Paris under number 813 487 899, at 37-39 avenue Trudaine, 75009 Paris. The linked terms and privacy policy are the English ones, both last updated 15 June 2026. They name Payfit Ltd, registered in England and Wales under number 11623900, which contracts with UK clients. French clients contract under https://payfit.com/fr/conditions-generales-de-services/. No separate API terms were found. Clause 1.4 of the terms covers third-party services connected through the Payfit API, and the appendix lists access to the API as a plan item. The API answers at partner-api.payfit.com and OAuth at oauth.payfit.com. The documentation is on developers.payfit.io, a second domain. https://payfit.com/.well-known/security.txt returned 404. The security contact page gives security@payfit.com and a PGP key whose stated expiry is 27 August 2026. RDAP for payfit.com gives a registration date of 2006-11-17 and Gandi SAS as registrar. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://payfit.com/general-terms-of-service/), read 2026-10-09, dated 2026-06-15, states 5 of the 7 things a reader expects. - To know. Restricts benchmarking or competitive use (costs points). "use or access the Services to build competing products or services;" - To know. Says the terms or the service can change without notice (costs points). "Any changes are binding on the Client without notice, from the date of their implementation and/or communication." - To know. Says access can be ended without notice or for any reason. "In the event of non-compliance with these obligations by the Client or Users, Payfit may suspend access to the Accounts and provision of the Services, and terminate the Agreement without notice or compensation." - Gives the date it was last updated. Last updated 2026-06-15. - Names the governing law or courts. The law of England and Wales. - States a limit on its liability. Capped at the fees paid in the 12 months before the claim. - Not found in the text. Lists what users may not do. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Payfit states it is not responsible for errors, omissions, damages or consequences related to the responses of Copilot, its AI assistance service. "Payfit is not responsible for errors, omissions, damages or consequences related to Copilot's responses." - Also in the text (2026-10-08). When the client gives notice of termination, the agreement ends in the third calendar month after the month of notice. "The termination month will be the third calendar month following the month during which notice is given." - Also in the text (2026-10-08). A request for the return of data must be made in writing through Client Support within 30 days of the end of the agreement. "The request for data return must be made in writing via the Client Support within no more than thirty (30) days from the end of the Agreement." **Privacy policy** (https://payfit.com/privacy-policy/), read 2026-10-09, dated 2026-06-15, states 7 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2026-06-15. - Says how long data is kept. Names a period of 3 years. - Not found in the text. Says whether personal data is sold or shared for advertising. - Gives a privacy contact. Names a data protection officer. - Says where data is transferred or stored. Relies on standard contractual clauses. - Also in the text (2026-10-08). Data from use of the application, which the policy says includes payroll and salary information, may be used to develop new services once it is at least pseudonymised. "Develop and create new services and/or functionalities in connection with the Services, provided that the data is at minimum pseudonymised prior to use." ## Live (updated 2026-10-10 00:51 UTC) - Vendor status page: unknown, no machine-readable status found - Watching changelog - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/payfit.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - Public OpenAPI 3.0 file with 31 operations, each documenting 400, 401, 403 and 404 responses with an example - llms.txt and a Markdown twin for every guide, reference and changelog page - Customer API keys and partner OAuth tokens are limited to chosen scopes from 22, with read and write separate - Rate limits are published as 50 read and 20 write requests a second, with `X-RateLimit` headers on responses - The contract appendix of 15 June 2026 lists sub-processors by purpose and region, and the security page states hosting in France ## Weaknesses - No operation runs, previews or approves a payroll. The API reads payroll status, payslips and accounting exports - The partner guides say PayFit is temporarily not accepting new integration requests, with no reopening date - The webhook guide documents a call that sends `clientSecret` and `clientId` in the URL query string - No idempotency keys, no official SDK and no MCP server were found in the reviewed documentation - Fifteen of 31 operations are France-only and two are UK-only, including contract creation and both accounting exports ## Before you call it (notes for agents) 1. Have a company admin create the key at app.payfit.com/integrations/hub/api with only the scopes the task needs. The key is shown once 2. POST the key to `https://oauth.payfit.com/introspect` to get `company_id`, then call `https://partner-api.payfit.com/companies/{companyId}/...` 3. Page lists with `nextPageToken` and `maxResults`, which defaults to 10 and stops at 50 4. Check before repeating a failed POST. There is no idempotency key, and `POST /absences` creates an absence that is already validated 5. A collaborator or contract created through the API stays incomplete until an HR admin finishes it in the PayFit app, and a new contract takes 2 to 5 minutes to appear ## Connect First request: ```bash curl --request GET --url https://partner-api.payfit.com/companies/{companyId} --header 'Authorization: Bearer YOUR-API-KEY' ``` Through letme (picks today, calling later): https://letme.dev/payfit. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Finch | BB | 71.6 | 121 | payroll.employees, hr.employees | no | https://www.anchorterminal.com/tools/finch.md | | Remote | BB | 70.7 | 147 | hr.employees, hr.time-off | no | https://www.anchorterminal.com/tools/remote.md | | Deel | B | 69.1 | 197 | hr.employees, hr.time-off | no | https://www.anchorterminal.com/tools/deel.md | | Factorial | B | 66.3 | 295 | hr.employees, hr.time-off | no | https://www.anchorterminal.com/tools/factorial.md | | Gusto | B | 63.3 | 399 | payroll.employees, hr.time-off | no | https://www.anchorterminal.com/tools/gusto.md | | BambooHR | C | 61.7 | 457 | hr.employees, hr.time-off | no | https://www.anchorterminal.com/tools/bamboohr.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The Partner API has 31 operations and none runs, previews or approves a payroll. `GET /companies/{companyId}/payroll-status` reports completed or not_completed for a month (source: ) - The partner guides carry a notice that PayFit is temporarily unable to accept new requests for integrations through the API, with no timeline (source: ) - A customer creates an API key with chosen scopes in the app and uses it against the same API (source: ) - Rate limits are 50 requests a second for reads and 20 for writes per client application (source: ) - The webhook guide documents `https://oauth.payfit.com/webhooks?clientSecret=xxx&clientId=xxx`, which puts the client secret in the URL (source: ) - The changelog entry of 12 June 2026 removed DE and IT as company country values because PayFit no longer supports those countries (source: ) - The security page states ISO 27001 certification, a private bug bounty on HackerOne and data storage in France on AWS (source: ) - #5 of 11 in Best payroll APIs and embedded payroll for AI agents: https://www.anchorterminal.com/best/payroll/index.md - All 55 payroll comparisons: https://www.anchorterminal.com/compare/payroll/index.md ## Compare - [Argyle vs PayFit](https://www.anchorterminal.com/compare/argyle-vs-payfit.md): B 63.7 vs C 55.5 - [Check vs PayFit](https://www.anchorterminal.com/compare/check-payroll-vs-payfit.md): B 67.5 vs C 55.5 - [Employment Hero Payroll vs PayFit](https://www.anchorterminal.com/compare/employment-hero-vs-payfit.md): D 50.4 vs C 55.5 - [Everee vs PayFit](https://www.anchorterminal.com/compare/everee-vs-payfit.md): C 55.1 vs C 55.5 - [Finch vs PayFit](https://www.anchorterminal.com/compare/finch-vs-payfit.md): BB 71.6 vs C 55.5 - [Gusto vs PayFit](https://www.anchorterminal.com/compare/gusto-vs-payfit.md): B 63.3 vs C 55.5 - [Paychex vs PayFit](https://www.anchorterminal.com/compare/paychex-vs-payfit.md): E 44.8 vs C 55.5 - [PayFit vs Salsa](https://www.anchorterminal.com/compare/payfit-vs-salsa.md): C 55.5 vs D 46.1 - [PayFit vs Worklio](https://www.anchorterminal.com/compare/payfit-vs-worklio.md): C 55.5 vs E 38.6 - [PayFit vs Zeal](https://www.anchorterminal.com/compare/payfit-vs-zeal.md): C 55.5 vs E 45.4 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on payfit.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "payfit", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html PayFit on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![PayFit on Anchor Terminal](https://www.anchorterminal.com/badges/payfit.svg)](https://www.anchorterminal.com/tools/payfit) ``` Plain link: ```html PayFit on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say PayFit is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/payfit-dark.png - Light: https://www.anchorterminal.com/assets/share/payfit-light.png