# Salsa > Embedded payroll from Salsa Software Inc. for software platforms. A partner's backend onboards employers and workers, sends pay data, previews and confirms payroll runs and reads pay statements through a REST API, while Salsa files taxes and moves money. - Canonical: https://www.anchorterminal.com/tools/salsa - Markdown: https://www.anchorterminal.com/tools/salsa.md (~7,000 tokens) - Slim: https://www.anchorterminal.com/tools/salsa.min.md (~1,780 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/salsa.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade D · 46.1/100 · rank #565 of 629 · #4 in Payroll infrastructure · not agent-ready · confidence medium** ## Assessment Salsa is reached as an embedded-payroll partner, not through an employer's existing payroll account. The REST API has a public OpenAPI 3.1 spec with 123 operations, a payroll preview, a separate confirm step and short-lived user tokens limited by role. Access starts with a sales conversation, and no public price, self-serve sandbox, status page or API changelog was found. ## Facts | Field | Value | | --- | --- | | Vendor | Salsa Software Inc. (https://www.salsa.dev) | | Kind | HTTP API | | Category | Payroll infrastructure (https://www.anchorterminal.com/categories/payroll) | | Transport | HTTP | | Endpoint | `https://api.salsa.dev/api/rest/v1` | | Auth | API key · A partner receives two bearer API tokens from Salsa after a sales contact, one for the sandbox and one for production. The docs say these tokens grant many privileges. From them a backend mints user tokens (JWT) at POST /api/rest/v1/auth/token, each with one of 12 roles in three tiers (basic, admin, super-admin, with onboarding variants), a list of up to 125 employers and a lifetime of 60 minutes by default, or up to 30 days for onboarding roles. Role limits are enforced at the API. No self-serve key page or key rotation procedure was found in the docs. This is embedded-payroll partner access. Salsa has no route into an employer's existing payroll account at another provider. | | Pricing | Paid (Paid) · No public prices. salsa.dev has no pricing page (www.salsa.dev/pricing returns 404) and access starts with a contact form. The sandbox is issued by Salsa on request, so an agent can't start without a person contacting sales, and no free tier or trial was found. A Usage API reports confirmed payroll runs, worker payments, workers paid and tax filings per employer so a partner can bill its own customers, with no unit price published (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the docs index, the OpenAPI spec or the website (checked 2026-10-08). | | Licence | Proprietary service. The website Terms of Use are public and the partner agreement isn't. The browser library @salsa-payroll/salsa-js on npm is MIT | | Packages | npm: `@salsa-payroll/salsa-js` | | Docs | https://docs.salsa.dev | | llms.txt | https://docs.salsa.dev/llms.txt | | Last release | 2026-10-07 | | npm downloads / week | 435 | | Access graded | Embedded-payroll partner access. A software platform signs with Salsa and runs payroll for its own customers. Salsa has no connector into an employer's existing payroll account at another provider | | API | REST v1 under /api/rest/v1, OpenAPI 3.1 at docs.salsa.dev/openapi/salsadev.yaml with 123 operations (63 GET, 32 POST, 11 DELETE, 10 PUT, 7 PATCH) and 78 webhook events. A GraphQL API is mentioned in the docs, and its reference isn't in the public index | | Environments | Sandbox at https://api.sandbox.salsa.dev and production at https://api.salsa.dev, each with its own API token | | Payroll run | POST /payroll-runs/preview returns totals without creating anything. POST /payroll-runs creates a PENDING run, POST /payroll-runs/{id}/confirm confirms it, and DELETE removes a pending run | | Data in | Paystream endpoints take employers, workers, pay, time worked, time off, benefits and deductions, asynchronously by default or inline with synchronous=true | | Credentials | Partner API token per environment, plus user tokens with 12 roles, up to 125 employers each and 60 minutes by default (30 days at most for onboarding roles) | | Rate limits | 3,000 requests every 5 minutes per IP address and per API token. 429 when exceeded. No Retry-After header documented | | Paging and filters | page, size (default 500) and sort on four list endpoints (payroll runs, workers, a worker's payment records, usage). filter[field] syntax with date operators such as onOrAfter(date) | | Errors | Every operation documents 400, 404, 422 and 500 with one envelope (message, target, details). No machine-readable error codes | | Webhooks | 78 event types, signed with HMAC SHA-256 in a Webhook-Signature header, retried with exponential backoff. Rotating the signing secret means contacting support | | SDKs | Salsa.js for the browser (script at https://js.salsa.dev/v0, npm @salsa-payroll/salsa-js 0.3.0, MIT, 11 December 2025). No server SDK, and the docs point to OpenAPI Generator | | Sandbox | Issued by Salsa on request. mock-onboard endpoints complete employer and worker onboarding with sample data | | Audit | `auditEntries` GraphQL query, paged, with entity, action, timestamp and actor (user, API client or system) | | Certifications | A SOC 2 Type 2 badge image on the home page. No security page, report request page or trust centre was found | | Capabilities | payroll.run, payroll.embedded, payroll.employees, payroll.tax-filing, payroll.contractors | | Tags | hosted, closed-source, api-key, openapi, llms-txt, webhooks, sandbox, sales-led, partner-access, soc2 | | JSON | https://www.anchorterminal.com/api/v1/tools/salsa.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 36 | 7.2 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 73 | 11.9 | | Agent ergonomics | 13% | 16.2 | 48 | 7.8 | | Security & auth | 14% | 17.5 | 56 | 9.8 | | Payments & pricing | 10% | 12.5 | 5 | 0.6 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 50 | 4.4 | | Transparency & trust (editorial 31, provenance 70) | 7% | 8.8 | 51 | 4.5 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **46.1 → D** | ### Why each score - Reliability 36: Read with the hosted rubric, for embedded-payroll partner access. No status page is linked from salsa.dev or docs.salsa.dev, and status.salsa.dev didn't connect. salsa.statuspage.io exists with two components marked "(example)" and a last update of 4 November 2022, which we didn't count (0). No readable incident history (5). Limits are published as 3,000 requests every 5 minutes per IP address and per API token (15). The docs name the 429 response without a Retry-After header or backoff guidance. There are no idempotency keys, though a create that repeats an externalId fails with a uniqueness error (6 of 15). No SLA found (0). REST v1 with a production host, not marked beta (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 73: Public OpenAPI 3.1 spec with 123 operations and 78 webhook events (25). llms.txt with 292 lines, and every docs page has a Markdown copy (10). 111 of 123 operations carry a description and the spec holds about 3,200 description fields. They state purpose and seldom say when not to use an endpoint (13 of 20). Inputs use enums, required fields, formats and discriminated unions, with no free-form JSON bodies found (12 of 15). 364 field examples and worked curl tutorials. Every operation documents 400, 404, 422 and 500 with one envelope of message, target and details, with no error codes, and 401, 403 and 429 are missing from the spec (8 of 15). The path is versioned as v1. No API changelog was found, docs.salsa.dev/changelog returns 404, and the product updates blog stops at 11 February 2026 (5 of 15). - Agent ergonomics 48: No field selection on REST responses, and page size defaults to 500 (10 of 25). page, size and sort exist on four list endpoints, payroll runs take six filters, and the filter syntax is documented. Other list endpoints take no paging parameters (13 of 20). Errors carry a message, a target and a details array without machine-readable codes (10 of 20). No Idempotency-Key. Creates can carry an externalId that rejects duplicates, and a payroll run is previewed, created as PENDING, confirmed in a separate call and deletable while pending (10 of 20). No server SDK. The docs point to OpenAPI Generator, and the mock-onboard endpoints shorten sandbox setup (5 of 15). - Security & auth 56: One partner API token per environment that the docs say grants many privileges, plus user tokens with 12 roles in three tiers, a named employer list of up to 125 and a 60-minute default lifetime. No rotation procedure for the partner token was found (20 of 30). Basic roles can't add bank accounts, unmasking needs super-admin, limits are enforced at the API and payment needs a separate confirm call. No read-only role was found (12 of 20). Responses carry text entered by employers and workers, with no injection guidance (3 of 15). Audit entries name the actor, the entity, the action and the time (15). A SOC 2 Type 2 badge image on the home page. No security page, security.txt, disclosure policy or bug bounty found (6 of 20). - Payments & pricing 5: Read with the hosted rubric. No x402, MPP or L402 (0). No public prices, and www.salsa.dev/pricing returns 404 (0). No free tier or trial found. A sandbox exists, issued by Salsa after a contact form, so partial credit (5 of 20). A person contacts sales and Salsa issues the tokens (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 50: The OpenAPI spec was last modified on 7 October 2026 and a docs page was updated the same day (30). There's no dated API changelog. 11 guide pages carry update dates between 27 July and 7 October 2026, which we counted as half (10 of 20). Closed service with support through a partner's Salsa contact, no public issue tracker or community, and a product updates blog that stops at 11 February 2026 (3 of 15). The only official package is the browser library @salsa-payroll/salsa-js 0.3.0 from 11 December 2025, with no server SDK (4 of 15). That package is published from GitHub Actions and its repository isn't public (3 of 10). - Transparency & trust 51: Closed service. The public Terms of Use are dated 7 April 2022 and cover the website and services in general, and the partner agreement for API use isn't public (12 of 30). The privacy policy of 24 September 2025 excludes data processed for platforms, gives no retention periods and still has a vendor name in square brackets. No DPA was found (10 of 30). The spec marks four operations deprecated and the docs list three deprecated roles with replacements, with no removal dates or policy (6 of 20). The policy says Salsa is headquartered in the United States. No subprocessor list or data locations were found (3 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/salsa.md (JSON https://www.anchorterminal.com/fixes/salsa.json) ### What we couldn't check - unchecked: whether status.salsa.dev exists. The host didn't connect from our network, and no status page is linked from the site or docs - Who owns salsa.statuspage.io. It shows example components and a last update of 4 November 2022 - Prices, contract terms and any SLA, which sit in the partner agreement - The GraphQL API's schema and whether it is open to every partner. The public index has no GraphQL reference - Whether a partner can rotate or revoke its API token without contacting Salsa - The scope and date of the SOC 2 Type 2 report shown as a badge - Whether 429 responses carry a Retry-After header. We had no token to test with ### Sources - docs index (llms.txt): (seen 2026-10-08) - OpenAPI 3.1 spec, operations, errors and Last-Modified header: (seen 2026-10-08) - authorisation guide, token types and roles: (seen 2026-10-08) - API rate limits: (seen 2026-10-08) - introduction and how access is granted: (seen 2026-10-08) - REST payroll tutorial (Salsa Advanced): (seen 2026-10-08) - external IDs and duplicate prevention: (seen 2026-10-08) - audit data guide: (seen 2026-10-08) - webhooks guide, signatures and retries: (seen 2026-10-08) - filtering and sorting: (seen 2026-10-08) - usage metrics guide: (seen 2026-10-08) - reference overview: (seen 2026-10-08) - home page, SOC 2 badge and contact form: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - terms of use: (seen 2026-10-08) - product updates blog: (seen 2026-10-08) - signup link from the docs (404): (seen 2026-10-08) - security.txt (404): (seen 2026-10-08) - placeholder Statuspage, ownership not established: (seen 2026-10-08) - Salsa.js on npm: (seen 2026-10-08) - domain registration (RDAP): (seen 2026-10-08) ## Who's behind it (provenance 70/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Salsa Software Inc. | 20/20 | | Domain age | salsa.dev, registered 2021-08-06 (5 years) | 11/15 | | Endpoint on the vendor's domain | api.salsa.dev | 15/15 | | Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 | | Privacy policy | read, states 6 of the 8 things a reader expects | 8.5/10 | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The privacy policy (last modified 24 September 2025) names Salsa Software Inc., 169 Madison Ave #38368, New York, NY 10016, and says it doesn't cover data processed on behalf of platforms, which is governed by Salsa's agreements with them. The Terms of Use are dated 7 April 2022 and governed by California law. The partner agreement that covers API use isn't public. www.salsa.dev/.well-known/security.txt and docs.salsa.dev/.well-known/security.txt return 404. No status page is linked from salsa.dev or docs.salsa.dev. status.salsa.dev didn't connect. salsa.statuspage.io exists with two components marked "(example)" and a last update of 4 November 2022, and nothing ties it to this company. The changelog link is the product updates category of the blog, whose newest entry is 11 February 2026. docs.salsa.dev/changelog returns 404. RDAP for salsa.dev gives a registration date of 2021-08-06 and Squarespace Domains II LLC as registrar. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.salsa.dev/terms-of-use), read 2026-10-08, dated 2022-04-07, states 6 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "Use any robot, spider, or other automatic device, process, or means to access the Services for any purpose, including monitoring or copying any of the material on the Services." - To know. Says the terms or the service can change without notice (costs points). "We reserve the right to withdraw or amend the Services, and any service or material we provide on or through the Services, in our sole discretion without notice." - To know. Says access can be ended without notice or for any reason. "Terminate or suspend your access to all or part of the Services for any or no reason, including without limitation, any violation of these Terms of Use." - To know. Requires arbitration or waives class actions. "…or concerning their interpretation, violation, invalidity, non-performance, or termination, to final and binding arbitration under the Rules of Arbitration of the American Arbitration Association applying California law." - To know. Has not been updated for three years or more. "Last Modified: April 7, 2022" - Gives the date it was last updated. Last updated 2022-04-07. - Names the governing law or courts. The law of the State of California. - States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence. - Says how changes to the terms are announced. Changes are posted, with no other notice named. - Not found in the text. Refers to a service level or uptime commitment. - Also in the text (2026-10-08). Content posted through the services is licensed to Salsa, its affiliates and service providers on a worldwide, perpetual, irrevocable and sublicensable basis for any purpose. "perpetual, irrevocable, transferrable, sublicensable, royalty-free license to sublicense, use, reproduce, copy, modify, create derivative works of, publicly perform, publicly display, distribute, and otherwise disclose to third parties and/or exploit in any manner any such material for any purpose." - Also in the text (2026-10-08). Salsa may use a person's name, likeness and voice together with their feedback, including to promote the services, without compensation. "To the extent that we have your name, likeness, or voice, this will be part of the Feedback and you agree that we may use your name, likeness and voice in the same manner that we can use other Feedback." **Privacy policy** (https://www.salsa.dev/privacy-policy), read 2026-10-08, dated 2025-09-24, states 6 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2025-09-24. - Not found in the text. Says what rights people have over their data. - Not found in the text. Gives a privacy contact. - Says where data is transferred or stored. Data goes to the United States. - Also in the text (2026-10-08). The policy does not apply to information Salsa processes on behalf of business customers, which is governed by its agreements with those customers. "This Privacy Policy does not apply to information that we process on behalf of business customers (such as Platforms) while providing the Salsa services to them." - Also in the text (2026-10-08). Personal information may be shared with service providers that include AI providers, and OpenAI is named among them. "customer support, AI providers, such as online chat functionality providers and other providers of generative AI technologies such as OpenAI, email delivery, marketing, consumer research and website analytics)." ## Live (updated 2026-10-08 17:36 UTC) - Right now: up, HTTP 401, 451 ms, checked 2026-10-08 17:36 UTC (get on `https://api.salsa.dev/api/rest/v1`, asks for auth) - Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 458 ms · p95 539 ms - npm `@salsa-payroll/salsa-js` 0.3.0 - security.txt: none - Always current: https://www.anchorterminal.com/api/v1/live/salsa.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - Public OpenAPI 3.1 spec with 123 operations and 78 webhook events, last modified 7 October 2026, plus llms.txt and a Markdown copy of every docs page - A payroll run is previewed, created as PENDING and paid only after a separate confirm call. A pending run can be deleted - User tokens last 60 minutes by default, carry one of 12 roles in three tiers and name the employers they cover - Audit entries record who changed what and when, with the actor shown as a user, an API client or the system - Sandbox at api.sandbox.salsa.dev with mock-onboard endpoints that fill in employer and worker details for tests ## Weaknesses - API tokens come from Salsa after a sales contact. No self-serve signup, public price, free tier or trial was found - No status page, SLA, API changelog or deprecation policy was found on salsa.dev or docs.salsa.dev - No Idempotency-Key header. The rate-limit page names 429 with no Retry-After or backoff guidance - No server-side SDK. The only official package is the browser library Salsa.js, last published on 11 December 2025 - The signup link used across the docs, www.salsa.dev/get-a-demo, returned 404 on 8 October 2026 - No security.txt, disclosure policy, DPA or subprocessor list was found. SOC 2 Type 2 appears only as a badge image ## Before you call it (notes for agents) 1. Use the sandbox token against https://api.sandbox.salsa.dev and the production token against https://api.salsa.dev. Each environment has its own token 2. Call POST /payroll-runs/preview before creating a run, then confirm the PENDING run in a separate call. Confirming starts the employer debit 3. Send your own externalId on every create. A repeat returns a uniqueness error, which is the only duplicate protection 4. Make sure externalId values are unique across all employers, since each entity type has one namespace 5. Mint a user token with the lowest role and the fewest employerIds the task needs, and keep the partner token on the server ## Connect First request: ```bash curl --location --request GET 'https://api.sandbox.salsa.dev/api/rest/v1/partner-pay-types' \ --header 'Accept: application/json' \ --header 'Authorization: Bearer ${YOUR_API_TOKEN}' ``` Through letme (picks today, calling later): https://letme.dev/salsa. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Check | B | 67.5 | 193 | payroll.run, payroll.employees, payroll.embedded, payroll.tax-filing, payroll.contractors | no | https://www.anchorterminal.com/tools/check-payroll.md | | Gusto | B | 63.3 | 283 | payroll.run, payroll.employees, payroll.embedded, payroll.tax-filing, payroll.contractors | no | https://www.anchorterminal.com/tools/gusto.md | | Zeal | E | 45.4 | 569 | payroll.run, payroll.embedded, payroll.employees, payroll.contractors, payroll.tax-filing | no | https://www.anchorterminal.com/tools/zeal.md | | Finch | BB | 71.6 | 99 | payroll.employees, payroll.contractors | no | https://www.anchorterminal.com/tools/finch.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - API tokens and the client key are issued by Salsa after a sales contact, per the introduction (https://docs.salsa.dev/docs/introduction). The link it gives, https://www.salsa.dev/get-a-demo, returned 404 on 8 October 2026, and the contact form sits on the home page - The OpenAPI 3.1 spec lists 123 operations and 78 webhook events and was last modified on 7 October 2026 (source: ) - User tokens carry one of 12 roles in three tiers, cover up to 125 named employers and last 60 minutes by default. Unmasking a full bank account number or government ID needs a super-admin role (source: ) - Rate limits are 3,000 requests every 5 minutes per IP address and per API token, with a 429 response when exceeded (source: ) - Audit entries are read through an `auditEntries` GraphQL query and name the actor as a user, an API client or the system (source: ) - Sending an externalId on a create makes a repeat fail with a uniqueness error, and the namespace is shared across all of a partner's employers for each entity type (source: ) - docs.salsa.dev/mcp answers only to MCP clients. It belongs to the documentation site, and no MCP server for the payroll API was found (source: ) ## Compare - [Check vs Salsa](https://www.anchorterminal.com/compare/check-payroll-vs-salsa.md): B 67.5 vs D 46.1 - [Gusto vs Salsa](https://www.anchorterminal.com/compare/gusto-vs-salsa.md): B 63.3 vs D 46.1 - [Salsa vs Zeal](https://www.anchorterminal.com/compare/salsa-vs-zeal.md): D 46.1 vs E 45.4 - [Finch vs Salsa](https://www.anchorterminal.com/compare/finch-vs-salsa.md): BB 71.6 vs D 46.1 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on salsa.dev or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "salsa", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Salsa on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Salsa on Anchor Terminal](https://www.anchorterminal.com/badges/salsa.svg)](https://www.anchorterminal.com/tools/salsa) ``` Plain link: ```html Salsa on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Salsa is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/salsa-dark.png - Light: https://www.anchorterminal.com/assets/share/salsa-light.png