# Salsa (slim) > Embedded payroll from Salsa Software Inc. for software platforms. A partner's backend onboards employers and workers, sends pay data, previews and confirms payroll runs and reads pay statements through a REST API, while Salsa files taxes and moves money. - Full: https://www.anchorterminal.com/tools/salsa.md (~7,050 tokens) · this version ~1,780 tokens · JSON https://www.anchorterminal.com/tools/salsa.json · canonical https://www.anchorterminal.com/tools/salsa - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **D · 46.1/100 · rank #565 of 629 · #4 in Payroll infrastructure · not agent-ready · confidence medium** Assessment: Salsa is reached as an embedded-payroll partner, not through an employer's existing payroll account. The REST API has a public OpenAPI 3.1 spec with 123 operations, a payroll preview, a separate confirm step and short-lived user tokens limited by role. Access starts with a sales conversation, and no public price, self-serve sandbox, status page or API changelog was found. ## Facts - Kind: HTTP API · vendor: Salsa Software Inc. · category: Payroll infrastructure · legal entity: Salsa Software Inc. · provenance 70/100 - Endpoint: `https://api.salsa.dev/api/rest/v1` (HTTP) - Auth: API key · pricing: Paid · x402: no · licence: Proprietary service. The website Terms of Use are public and the partner agreement isn't. The browser library @salsa-payroll/salsa-js on npm is MIT - Probe metrics: not measured yet (probes haven't run) - Access graded: Embedded-payroll partner access. A software platform signs with Salsa and runs payroll for its own customers. Salsa has no connector into an employer's existing payroll account at another provider - API: REST v1 under /api/rest/v1, OpenAPI 3.1 at docs.salsa.dev/openapi/salsadev.yaml with 123 operations (63 GET, 32 POST, 11 DELETE, 10 PUT, 7 PATCH) and 78 webhook events. A GraphQL API is mentioned in the docs, and its reference isn't in the public index - Environments: Sandbox at https://api.sandbox.salsa.dev and production at https://api.salsa.dev, each with its own API token - Payroll run: POST /payroll-runs/preview returns totals without creating anything. POST /payroll-runs creates a PENDING run, POST /payroll-runs/{id}/confirm confirms it, and DELETE removes a pending run - Data in: Paystream endpoints take employers, workers, pay, time worked, time off, benefits and deductions, asynchronously by default or inline with synchronous=true - Credentials: Partner API token per environment, plus user tokens with 12 roles, up to 125 employers each and 60 minutes by default (30 days at most for onboarding roles) - Rate limits: 3,000 requests every 5 minutes per IP address and per API token. 429 when exceeded. No Retry-After header documented - Paging and filters: page, size (default 500) and sort on four list endpoints (payroll runs, workers, a worker's payment records, usage). filter[field] syntax with date operators such as onOrAfter(date) - Errors: Every operation documents 400, 404, 422 and 500 with one envelope (message, target, details). No machine-readable error codes - Webhooks: 78 event types, signed with HMAC SHA-256 in a Webhook-Signature header, retried with exponential backoff. Rotating the signing secret means contacting support - SDKs: Salsa.js for the browser (script at https://js.salsa.dev/v0, npm @salsa-payroll/salsa-js 0.3.0, MIT, 11 December 2025). No server SDK, and the docs point to OpenAPI Generator - Sandbox: Issued by Salsa on request. mock-onboard endpoints complete employer and worker onboarding with sample data - Audit: `auditEntries` GraphQL query, paged, with entity, action, timestamp and actor (user, API client or system) - Certifications: A SOC 2 Type 2 badge image on the home page. No security page, report request page or trust centre was found - Scores: Reliability 36, Performance pending, Schema & documentation 73, Agent ergonomics 48, Security & auth 56, Payments & pricing 5, Task success pending, Maintenance & community 50, Transparency & trust 51 · total over the 7 assessed categories - Why: Reliability, Read with the hosted rubric, for embedded-payroll partner access. · Schema & documentation, Public OpenAPI 3.1 spec with 123 operations and 78 webhook events (25). · Agent ergonomics, No field selection on REST responses, and page size defaults to 500 (10 of 25). · Security & auth, One partner API token per environment that the docs say grants many privileges, plus user tokens with 12 roles in three tiers, a named emplo… · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The OpenAPI spec was last modified on 7 October 2026 and a docs page was updated the same day (30). · Transparency & trust, Closed service. - Sources: 21, open questions: 7, both in the full twin - Capabilities: payroll.run, payroll.embedded, payroll.employees, payroll.tax-filing, payroll.contractors - JSON: https://www.anchorterminal.com/api/v1/tools/salsa.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/salsa.svg` or a link to https://www.anchorterminal.com/tools/salsa from a page on salsa.dev or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Use the sandbox token against https://api.sandbox.salsa.dev and the production token against https://api.salsa.dev. Each environment has its own token 2. Call POST /payroll-runs/preview before creating a run, then confirm the PENDING run in a separate call. Confirming starts the employer debit 3. Send your own externalId on every create. A repeat returns a uniqueness error, which is the only duplicate protection 4. Make sure externalId values are unique across all employers, since each entity type has one namespace 5. Mint a user token with the lowest role and the fewest employerIds the task needs, and keep the partner token on the server ## Connect ```bash curl --location --request GET 'https://api.sandbox.salsa.dev/api/rest/v1/partner-pay-types' \ --header 'Accept: application/json' \ --header 'Authorization: Bearer ${YOUR_API_TOKEN}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/salsa ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Check | B | 67.5 | payroll.run, payroll.employees, payroll.embedded, payroll.tax-filing, payroll.contractors | https://www.anchorterminal.com/tools/check-payroll.min.md | | Gusto | B | 63.3 | payroll.run, payroll.employees, payroll.embedded, payroll.tax-filing, payroll.contractors | https://www.anchorterminal.com/tools/gusto.min.md | | Zeal | E | 45.4 | payroll.run, payroll.embedded, payroll.employees, payroll.contractors, payroll.tax-filing | https://www.anchorterminal.com/tools/zeal.min.md | | Finch | BB | 71.6 | payroll.employees, payroll.contractors | https://www.anchorterminal.com/tools/finch.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)