# Rippling (slim) > Rippling is a workforce platform for HR, payroll, IT and spend. Its REST Platform API v2 reads and writes worker, time off and organisation data with scoped Bearer tokens. A first-party MCP server runs as the signed-in employee. - Full: https://www.anchorterminal.com/tools/rippling.md (~7,050 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/rippling.json · canonical https://www.anchorterminal.com/tools/rippling - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **C · 60.8/100 · rank #341 of 629 · #3 in HR & employee operations · not agent-ready · confidence medium** Assessment: API tokens carry any of 162 scopes and can never see more than their owner, and hires and worker changes land as drafts for a person to review. There is no public price, trial or self-serve signup, and status.rippling.com shows five incidents marked critical between 16 July and 29 September 2026. ## Facts - Kind: HTTP API · vendor: People Center, Inc. dba Rippling · category: HR & employee operations · legal entity: People Center, Inc. dba Rippling · provenance 69/100 - Endpoint: `https://rest.ripplingapis.com` (HTTP) - Auth: OAuth or key · pricing: Paid · x402: no · licence: Proprietary service under Rippling's customer terms and Developer Terms of Use. The JavaScript SDK on npm is Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - APIs: REST Platform API v2 at https://rest.ripplingapis.com (reference version 2024-08-01, about 350 operations). V1 Base, Employee, Company, Payroll, Reports, Time and Attendance and Recruiting APIs at api.rippling.com are legacy - HR coverage: Read workers, users, compensations, departments, teams, titles, levels, work locations, legal entities, leave types, balances and requests. Write leave requests, departments, teams, work locations, employee documents, custom objects, draft hires, hires and draft transitions (proposed worker changes) - Credentials: API tokens with 162 listed scopes for a customer's own use, limited to the owner's permission profile and revoked after 30 days unused. OAuth 2.0 authorisation code for App Shop partners. Employee sign-in for the Rippling MCP - MCP server: First-party and remote, enabled per company and governed in MCP Gateway. One code tool over 31 functions, 10 of them writes. The server URL is copied from IT > My IT > MCP connectors. Needs a Rippling AI trial or subscription - Rate limits: REST API 300 requests per IP per sliding 10 seconds, then every request is rejected for 10 seconds. MCP 50 calls per function per 60 seconds per user, 5 ask_ai starts a minute and 10 concurrent runs - Pagination and queries: Cursor pagination through `next_link`, 50 records by default and 100 at most. `filter` with eq, ne, gt, gte, lt, lte, in, and, or (64 nodes at most), `expand` to two levels and ten fields, `order_by` - Errors: Status table with a retry column for 400, 401, 403, 404, 409, 422, 429, 500 and 504. Responses carry `x-rippling-request-id`. Fields the token can't see are null and named in `__meta.redacted_fields` - Idempotency: `Idempotency-Key` is required on POST /hires/ and shown on POST /draft-transitions/ and time entries. Not found as a general rule for writes - SDK: @rippling/rippling-sdk 0.2.0-alpha.106 (7 October 2026), TypeScript, Apache-2.0, no runtime dependencies, two retries by default. The source repository is private - Webhooks: App Shop partner webhooks only, with about five minutes' lag and an optional Bearer token. In-product webhooks trigger Rippling workflows - Audit: Activity log endpoint with 90 days of events, filterable by time, event type, worker and source app. An email goes to the owner and admins when a token is created. MCP Gateway keeps audit logs - Certifications: SOC 1 Type II, SOC 2 Type II, SOC 3, ISO 27001, ISO 27018, ISO 42001 and CSA STAR Level 2 per rippling.com/security. Vulnerability reporting programme with bounties at Rippling's discretion - Status: status.rippling.com on Atlassian Statuspage, with components among them Rippling App, Platform API, Third-party integrations and Rippling AI - Scores: Reliability 62, Performance pending, Schema & documentation 73, Agent ergonomics 75, Security & auth 90, Payments & pricing 5, Task success pending, Maintenance & community 74, Transparency & trust 51 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Read with the hosted lines and scored on the REST Platform API v2, the surface an outside agent calls with a token. · Schema & documentation, The reference is generated from an OpenAPI document and shows a JSON Schema tab per operation, but we found no downloadable spec, and the ty… · Agent ergonomics, Related objects come back null until asked for with `expand`, and `limit` sizes a page. · Security & auth, API tokens with 162 listed scopes, most split into read and read-write, limited to the owner's permission profile, shown once, revocable, an… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The changelog's latest entry is 28 September 2026 and the SDK's latest version 7 October 2026 (30). · Transparency & trust, Closed service. - Sources: 22, open questions: 8, both in the full twin - Capabilities: hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents, recruiting.candidates - JSON: https://www.anchorterminal.com/api/v1/tools/rippling.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/rippling.svg` or a link to https://www.anchorterminal.com/tools/rippling from a page on rippling.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call https://rest.ripplingapis.com with a Bearer token and pin `Rippling-Api-Version`. Use V1 at api.rippling.com only for resources that exist nowhere else 2. Treat a null field as possibly hidden. Check `__meta.redacted_fields`, the token's scopes and whether `expand` was sent 3. Follow `next_link` until it is null. The default page is 50 records and a `limit` above 100 returns 400 4. Stay under 300 requests per IP in any 10 seconds. Going over rejects every request for the next 10 seconds 5. Send an `Idempotency-Key` on POST /hires/ and POST /draft-transitions/, then poll the request until it reaches a final status ## Connect ```bash npm install @rippling/rippling-sdk ``` ```bash curl -X GET 'https://rest.ripplingapis.com/companies/' \ -H 'Accept: application/json' \ -H 'Authorization: Bearer YOUR_API_TOKEN' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/rippling ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Deel | B | 69.1 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/deel.min.md | | BambooHR | C | 61.7 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/bamboohr.min.md | | HiBob | C | 57 | hr.employees, hr.time-off, hr.org, hr.onboarding, hr.documents | https://www.anchorterminal.com/tools/hibob.min.md | | Workable | C | 61.7 | recruiting.candidates, hr.employees, hr.time-off, hr.org | https://www.anchorterminal.com/tools/workable.min.md | | Finch | BB | 71.6 | hr.employees, hr.org, hr.documents | https://www.anchorterminal.com/tools/finch.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)