{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/greenhouse.json",
        "name": "Greenhouse",
        "score": 64.8,
        "shared": [
          "recruiting.candidates",
          "recruiting.jobs",
          "recruiting.applications",
          "recruiting.interviews",
          "recruiting.offer-letters"
        ],
        "slug": "greenhouse"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/ashby.json",
        "name": "Ashby",
        "score": 61.3,
        "shared": [
          "recruiting.candidates",
          "recruiting.jobs",
          "recruiting.applications",
          "recruiting.interviews",
          "recruiting.offer-letters"
        ],
        "slug": "ashby"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/lever.json",
        "name": "Lever",
        "score": 53.6,
        "shared": [
          "recruiting.candidates",
          "recruiting.jobs",
          "recruiting.applications",
          "recruiting.interviews",
          "recruiting.offer-letters"
        ],
        "slug": "lever"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/workable.json",
        "name": "Workable",
        "score": 61.7,
        "shared": [
          "recruiting.candidates",
          "recruiting.jobs",
          "recruiting.applications",
          "recruiting.offer-letters"
        ],
        "slug": "workable"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/bamboohr.json",
        "name": "BambooHR",
        "score": 61.7,
        "shared": [
          "recruiting.applications",
          "recruiting.jobs"
        ],
        "slug": "bamboohr"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/rippling.json",
        "name": "Rippling",
        "score": 60.8,
        "shared": [
          "recruiting.candidates"
        ],
        "slug": "rippling"
      }
    ],
    "tool": {
      "slug": "smartrecruiters",
      "name": "SmartRecruiters",
      "vendor": "SmartRecruiters, Inc. (an SAP company)",
      "vendorUrl": "https://www.smartrecruiters.com",
      "kind": "http-api",
      "category": "recruiting",
      "summary": "Applicant tracking and recruiting platform from SmartRecruiters, an SAP company. Its Customer API covers jobs, candidates, applications, interviews, offer records, reports and webhooks over REST, with API key or OAuth 2.0 access for customers and approved partners.",
      "url": "https://www.anchorterminal.com/tools/smartrecruiters",
      "markdownUrl": "https://www.anchorterminal.com/tools/smartrecruiters.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/smartrecruiters.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/smartrecruiters.json",
      "license": "Proprietary service under the SmartRecruiters Master Subscription Agreement",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.smartrecruiters.com",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is granted by a paying customer's administrator, who creates an API key or an OAuth client ID in Credential Manager. The API key goes in the `X-SmartToken` header, has full access to company data and doesn't expire. OAuth 2.0 client credentials are limited by 49 scopes, a system role and an optional access group, and their access tokens last 1,799 seconds. Partners distributing an app to all customers use the authorisation code grant, and new partner integrations are managed through the SAP PartnerEdge Build programme. The Posting API needs no credential.",
      "pricing": "paid",
      "pricingNotes": "No free tier, trial or self-serve signup found, so an agent can't start without a customer contract. The pricing page lists Essential \"starting at $14,995\" with no billing period stated, and Professional, High Volume and Complete on request. No separate API charge is published. Sandbox Management is listed as a product and Advanced Sandbox sits in the Complete plan. Only the Posting API, which returns published jobs, works without an account.",
      "priceSummary": "Paid",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the developer docs, llms.txt or the pricing page (checked 2026-10-07).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-07"
      },
      "docsUrl": "https://developers.smartrecruiters.com",
      "llmsTxt": "https://developers.smartrecruiters.com/llms.txt",
      "openapi": "https://developers.smartrecruiters.com/page/swagger",
      "capabilities": [
        "recruiting.candidates",
        "recruiting.jobs",
        "recruiting.applications",
        "recruiting.interviews",
        "recruiting.offer-letters"
      ],
      "tags": [
        "hosted",
        "enterprise",
        "oauth",
        "api-key",
        "openapi",
        "llms-txt",
        "webhooks",
        "sales-led",
        "status-page",
        "soc2",
        "closed-source"
      ],
      "lastRelease": "2026-10-05",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 60.4,
        "grade": "C",
        "agentReady": false,
        "rank": 356,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 51,
          "maintenance": 58,
          "payments": 8,
          "reliability": 78,
          "schema": 75,
          "security": 65,
          "transparency": 79
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 78,
            "points": 15.6,
            "reason": "Graded on the public REST API. Statuspage at status.smartrecruiters.com with 11 components, among them Customer API and Marketplace API (20). Two incidents in the 90 days to 7 October, both on Recruiter Apps. Errors on the People, Job and Communities pages in the EU datacentre for 84 minutes on 21 July, marked major, and a 20-minute login fault on 7 September. Neither names the Customer API, so we scored between a minor record and one major outage (15). Limits are published at 10 requests a second and 8 concurrent per credential (15). X-RateLimit headers on every response and exponential backoff guidance, but Retry-After is documented only for the deprecated Analytics API and no idempotency keys were found for writes (8). SLA of 99.9 per cent annual availability for paid subscriptions (10). The API is generally available, with single fields marked alpha (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 75,
            "points": 12.19,
            "reason": "Each reference page carries an OpenAPI 3.0.1 definition and a Swagger page exists. We found no single downloadable spec file (23). llms.txt of 511 lines and every docs page served as Markdown (10). Descriptions are uneven. Candidate search and status updates explain behaviour, while creating an interview has an empty description (9). Inputs are typed with enums, minimum and maximum values, patterns and required fields (12). Error codes are named per operation, such as REQUIRED_SUB_STATUS_OMITTED, with an ErrorResponse schema, but the definitions we read had no examples and the Get Started example posts a user body to `/jobs` (8). Dated changelog with an RSS feed, and a written breaking changes policy with versioned endpoints (13)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 51,
            "points": 8.29,
            "reason": "List endpoints take `limit` up to 100 with a default of 10, and webhooks carry IDs only. No field selection found (12). Cursor paging by `pageId` and filters such as `status`, `jobId` and `updatedAfter`, though some endpoints still page by `offset` (16). Errors return a code and message, with the codes listed per operation (14). No idempotency keys found. The docs advise backoff and a 128-second client timeout (3). Few required parameters and sensible defaults, but no official SDK in any language (6)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 65,
            "points": 11.38,
            "reason": "OAuth 2.0 client credentials with 49 scopes, a system role and an optional access group, 1,799-second access tokens and revocation in Credential Manager. An unscoped API key with full company access and no expiry is also available, and secrets travel in headers only (26). Read scopes are separate from write and manage scopes, and access groups limit which records a credential sees. No confirmation step for deletes found (13). The API returns CVs and screening answers written by candidates, and no prompt-injection guidance was found (2). Audit API for administrators with at least 26 months of retention, and a webhook callback log (11). The trust centre lists SOC 2 Type 2, ISO 27001, TISAX and UK Cyber Essentials with yearly external penetration tests. No security.txt or bug bounty found (13)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 8,
            "points": 1,
            "reason": "No x402, MPP or L402 (0). The pricing page gives one figure, Essential \"starting at $14,995\" with no period stated, and the other three plans on request (5). No free tier or trial found (0). A customer administrator has to create the credential in a browser. The Posting API returns published jobs with no credential, which earns partial credit (3)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 58,
            "points": 5.08,
            "reason": "Newest changelog entry 5 October 2026, on offer property details (30). Nine dated entries between 24 August and 5 October (20). Closed service with a changelog and RSS feed. API issues go through Contact Support inside a customer account, and no public developer forum was found (8). No official SDKs (0). No packages to assess (0)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 79,
            "points": 6.91,
            "note": "editorial 75, provenance 82",
            "reason": "Editorial half. Closed service with a public Master Subscription Agreement (version 15 November 2024) and an archive of earlier versions (15). Privacy notice updated 2 March 2026, a pre-signed DPA, 30 days of API access after termination followed by deletion, and 26 months of audit retention. The AI addendum lets SmartRecruiters train on anonymised or pseudonymised data, and the detailed retention documents sit in the trust centre (24). Written policy of at least 10 months' notice before a sunset and 24 months of support for earlier versions (18). Sub-processor list with purposes and locations, default hosting in Frankfurt with Ohio and Sydney as alternatives (18)."
          }
        ],
        "assessment": {
          "date": "2026-10-07",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "List endpoints take `limit` up to 100 with a default of 10, and webhooks carry IDs only. No field selection found (12). Cursor paging by `pageId` and filters such as `status`, `jobId` and `updatedAfter`, though some endpoints still page by `offset` (16). Errors return a code and message, with the codes listed per operation (14). No idempotency keys found. The docs advise backoff and a 128-second client timeout (3). Few required parameters and sensible defaults, but no official SDK in any language (6).",
            "maintenance": "Newest changelog entry 5 October 2026, on offer property details (30). Nine dated entries between 24 August and 5 October (20). Closed service with a changelog and RSS feed. API issues go through Contact Support inside a customer account, and no public developer forum was found (8). No official SDKs (0). No packages to assess (0).",
            "payments": "No x402, MPP or L402 (0). The pricing page gives one figure, Essential \"starting at $14,995\" with no period stated, and the other three plans on request (5). No free tier or trial found (0). A customer administrator has to create the credential in a browser. The Posting API returns published jobs with no credential, which earns partial credit (3).",
            "reliability": "Graded on the public REST API. Statuspage at status.smartrecruiters.com with 11 components, among them Customer API and Marketplace API (20). Two incidents in the 90 days to 7 October, both on Recruiter Apps. Errors on the People, Job and Communities pages in the EU datacentre for 84 minutes on 21 July, marked major, and a 20-minute login fault on 7 September. Neither names the Customer API, so we scored between a minor record and one major outage (15). Limits are published at 10 requests a second and 8 concurrent per credential (15). X-RateLimit headers on every response and exponential backoff guidance, but Retry-After is documented only for the deprecated Analytics API and no idempotency keys were found for writes (8). SLA of 99.9 per cent annual availability for paid subscriptions (10). The API is generally available, with single fields marked alpha (10).",
            "schema": "Each reference page carries an OpenAPI 3.0.1 definition and a Swagger page exists. We found no single downloadable spec file (23). llms.txt of 511 lines and every docs page served as Markdown (10). Descriptions are uneven. Candidate search and status updates explain behaviour, while creating an interview has an empty description (9). Inputs are typed with enums, minimum and maximum values, patterns and required fields (12). Error codes are named per operation, such as REQUIRED_SUB_STATUS_OMITTED, with an ErrorResponse schema, but the definitions we read had no examples and the Get Started example posts a user body to `/jobs` (8). Dated changelog with an RSS feed, and a written breaking changes policy with versioned endpoints (13).",
            "security": "OAuth 2.0 client credentials with 49 scopes, a system role and an optional access group, 1,799-second access tokens and revocation in Credential Manager. An unscoped API key with full company access and no expiry is also available, and secrets travel in headers only (26). Read scopes are separate from write and manage scopes, and access groups limit which records a credential sees. No confirmation step for deletes found (13). The API returns CVs and screening answers written by candidates, and no prompt-injection guidance was found (2). Audit API for administrators with at least 26 months of retention, and a webhook callback log (11). The trust centre lists SOC 2 Type 2, ISO 27001, TISAX and UK Cyber Essentials with yearly external penetration tests. No security.txt or bug bounty found (13).",
            "transparency": "Editorial half. Closed service with a public Master Subscription Agreement (version 15 November 2024) and an archive of earlier versions (15). Privacy notice updated 2 March 2026, a pre-signed DPA, 30 days of API access after termination followed by deletion, and 26 months of audit retention. The AI addendum lets SmartRecruiters train on anonymised or pseudonymised data, and the detailed retention documents sit in the trust centre (24). Written policy of at least 10 months' notice before a sunset and 24 months of support for earlier versions (18). Sub-processor list with purposes and locations, default hosting in Frankfurt with Ohio and Sydney as alternatives (18)."
          },
          "sources": [
            {
              "what": "developer docs index (llms.txt)",
              "url": "https://developers.smartrecruiters.com/llms.txt",
              "seen": "2026-10-07"
            },
            {
              "what": "authentication methods",
              "url": "https://developers.smartrecruiters.com/docs/authentication.md",
              "seen": "2026-10-07"
            },
            {
              "what": "API key",
              "url": "https://developers.smartrecruiters.com/docs/authentication-api-key.md",
              "seen": "2026-10-07"
            },
            {
              "what": "OAuth client credentials",
              "url": "https://developers.smartrecruiters.com/docs/authentication-oauth-client-credential.md",
              "seen": "2026-10-07"
            },
            {
              "what": "access scopes",
              "url": "https://developers.smartrecruiters.com/docs/access-scopes.md",
              "seen": "2026-10-07"
            },
            {
              "what": "partner app registration and SAP notice",
              "url": "https://developers.smartrecruiters.com/docs/register-an-app.md",
              "seen": "2026-10-07"
            },
            {
              "what": "rate limits",
              "url": "https://developers.smartrecruiters.com/docs/rate-limiting.md",
              "seen": "2026-10-07"
            },
            {
              "what": "throttling policies",
              "url": "https://developers.smartrecruiters.com/docs/throttling-policies.md",
              "seen": "2026-10-07"
            },
            {
              "what": "pagination",
              "url": "https://developers.smartrecruiters.com/docs/pagination.md",
              "seen": "2026-10-07"
            },
            {
              "what": "error handling",
              "url": "https://developers.smartrecruiters.com/docs/error-handling.md",
              "seen": "2026-10-07"
            },
            {
              "what": "breaking changes policy",
              "url": "https://developers.smartrecruiters.com/docs/breaking-changes.md",
              "seen": "2026-10-07"
            },
            {
              "what": "deprecation and sunset policy",
              "url": "https://developers.smartrecruiters.com/docs/deprecation-and-sunset-policies.md",
              "seen": "2026-10-07"
            },
            {
              "what": "MCP page",
              "url": "https://developers.smartrecruiters.com/docs/mcp.md",
              "seen": "2026-10-07"
            },
            {
              "what": "candidate search reference with OpenAPI definition",
              "url": "https://developers.smartrecruiters.com/reference/candidatesall-1.md",
              "seen": "2026-10-07"
            },
            {
              "what": "candidate status update reference",
              "url": "https://developers.smartrecruiters.com/reference/candidatesstatusupdate-1.md",
              "seen": "2026-10-07"
            },
            {
              "what": "webhook subscription reference and events",
              "url": "https://developers.smartrecruiters.com/reference/subscriptionscreate-1.md",
              "seen": "2026-10-07"
            },
            {
              "what": "Audit API reference",
              "url": "https://developers.smartrecruiters.com/reference/auditget-1.md",
              "seen": "2026-10-07"
            },
            {
              "what": "changelog feed",
              "url": "https://developers.smartrecruiters.com/changelog.rss",
              "seen": "2026-10-07"
            },
            {
              "what": "status incidents",
              "url": "https://status.smartrecruiters.com/api/v2/incidents.json",
              "seen": "2026-10-07"
            },
            {
              "what": "pricing",
              "url": "https://www.smartrecruiters.com/pricing/",
              "seen": "2026-10-07"
            },
            {
              "what": "service level agreement",
              "url": "https://www.smartrecruiters.com/legal/service-level-agreement/",
              "seen": "2026-10-07"
            },
            {
              "what": "Master Subscription Agreement",
              "url": "https://www.smartrecruiters.com/legal/terms-and-conditions/",
              "seen": "2026-10-07"
            },
            {
              "what": "privacy notice",
              "url": "https://www.smartrecruiters.com/legal/general-privacy-policy/",
              "seen": "2026-10-07"
            },
            {
              "what": "sub-processors",
              "url": "https://www.smartrecruiters.com/legal/subprocessors/",
              "seen": "2026-10-07"
            },
            {
              "what": "AI addendum",
              "url": "https://www.smartrecruiters.com/legal/artificial-intelligence-addendum/",
              "seen": "2026-10-07"
            },
            {
              "what": "trust centre",
              "url": "https://trust.smartrecruiters.com/",
              "seen": "2026-10-07"
            },
            {
              "what": "SAP acquisition page",
              "url": "https://www.smartrecruiters.com/about-us/sap-acquires-smartrecruiters/",
              "seen": "2026-10-07"
            },
            {
              "what": "GitHub organisation",
              "url": "https://github.com/smartrecruiters",
              "seen": "2026-10-07"
            }
          ],
          "openQuestions": [
            "unchecked: the SmartSandbox product page returned 403 to our reader, so sandbox terms and price are not established",
            "unchecked: trust centre documents (SOC 2 report, data retention policy, penetration test reports) are behind an access request",
            "unchecked: the billing period for the $14,995 Essential starting price, which the pricing page doesn't state",
            "unchecked: the tools on https://developers.smartrecruiters.com/mcp, which answers 401. The vendor's MCP page says it isn't supported for the public API",
            "Whether a single downloadable OpenAPI file exists beyond the per-page definitions and the Swagger page",
            "The date SAP's acquisition closed, which the vendor's acquisition page doesn't give",
            "Whether the Audit API records API calls by credential or only the account and MFA events it lists",
            "Whether any endpoint accepts an idempotency key. None appeared in the seven reference pages read"
          ]
        },
        "negative": 0,
        "verdict": "OAuth client credentials limited by 49 scopes, a system role and an access group, with per-operation OpenAPI definitions, llms.txt and a dated changelog. Access needs a paid SmartRecruiters account, with the lowest plan starting at $14,995, and no free tier, official SDK or idempotency key was found.",
        "bestFor": "An agent working inside a company that already runs SmartRecruiters, for reading jobs and candidates, adding candidates, moving applications between stages, creating interviews and pulling reports.",
        "strengths": [
          "OAuth 2.0 client credentials with 49 scopes, a system role and an optional access group. Access tokens last 1,799 seconds",
          "Every reference page is served as Markdown with an OpenAPI 3.0.1 definition, indexed by a 511-line llms.txt",
          "Limits are published. 10 requests a second and 8 concurrent per credential, with X-RateLimit headers on every response",
          "Written policy of at least 10 months' notice before an endpoint is sunset, and 24 months of support for earlier versions",
          "Audit API with at least 26 months of retention, and 54 webhook events with optional HMAC SHA256 signatures"
        ],
        "weaknesses": [
          "No free tier, trial or self-serve signup found. The Essential plan starts at $14,995 and the other three plans are quoted on request",
          "No idempotency keys in the reference pages we read, so a create retried after a timeout can duplicate a candidate or interview",
          "No official SDK, and the vendor's MCP page says the MCP server isn't supported for the public API",
          "An API key has full access to company data with no scopes and no expiry",
          "Offer endpoints are read-only, and new partner apps now go through the SAP PartnerEdge Build programme"
        ],
        "agentNotes": [
          "Ask the customer's admin for an OAuth client ID with only the scopes needed. An API key reads and writes all company data and never expires",
          "Exchange the client ID and secret at https://api.smartrecruiters.com/identity/oauth/token and refresh every 30 minutes",
          "Stay under 10 requests a second and 8 concurrent. `GET /candidates` allows 1 concurrent request, and job publication 2 a second",
          "Move a candidate with `PUT /candidates/{id}/jobs/{jobId}/status`. The variants without `jobId` act on the most recently updated application",
          "Page with `limit` (maximum 100, default 10) and `pageId` from `nextPageId`. Use the Reporting API for bulk reads, which returns CSV"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 60.4
          }
        ],
        "editorialScores": {
          "ergonomics": 51,
          "maintenance": 58,
          "payments": 8,
          "reliability": 78,
          "schema": 75,
          "security": 65,
          "transparency": 75
        },
        "provenanceScore": 82
      },
      "connect": {
        "http": "curl https://api.smartrecruiters.com/identity/oauth/token \\\n  -X POST \\\n  -H 'Content-Type: application/x-www-form-urlencoded' \\\n  -d \"client_id=$SMARTRECRUITERS_CLIENT_ID\" \\\n  -d \"client_secret=$SMARTRECRUITERS_CLIENT_SECRET\" \\\n  -d 'grant_type=client_credentials'"
      },
      "letme": {
        "capability": "https://letme.dev/recruiting.candidates",
        "tool": "https://letme.dev/smartrecruiters"
      },
      "notable": [
        "The developer docs say SAP has acquired SmartRecruiters and that new technology partnerships and integrations are managed through the SAP PartnerEdge Build programme (https://developers.smartrecruiters.com/docs/register-an-app.md, page updated 28 September 2026)",
        "The MCP page in the developer docs reads \"The MCP Server is not supported for the Public API\", and https://developers.smartrecruiters.com/mcp answers 401 without a token (https://developers.smartrecruiters.com/docs/mcp.md)",
        "Each API reference page is served as Markdown with an OpenAPI 3.0.1 definition, and llms.txt indexes 326 reference pages across 30 API groups (https://developers.smartrecruiters.com/llms.txt)",
        "Rate limits are 10 requests a second and 8 concurrent requests per credential, 2 a second for job publication and 1 concurrent for `GET /candidates` (https://developers.smartrecruiters.com/docs/rate-limiting.md)",
        "The breaking changes policy promises at least 10 months' notice before an endpoint is sunset and support for earlier API versions for at least 24 months (https://developers.smartrecruiters.com/docs/breaking-changes.md)",
        "The pricing page lists Essential \"starting at $14,995\" with no billing period stated, and Professional, High Volume and Complete on request (https://www.smartrecruiters.com/pricing/)"
      ],
      "area": "business",
      "details": [
        {
          "label": "Surface graded",
          "value": "The public REST API (Customer API) at https://api.smartrecruiters.com. The vendor's MCP page says the MCP server isn't supported for the public API"
        },
        {
          "label": "API groups",
          "value": "30 groups in llms.txt, among them Jobs, Candidates, Job Applications, Interviews, Self Scheduling, Offer, Reviews, Approvals, Messages, Reporting, Configuration, Users, Audit, Webhooks and SmartOnboard, 326 reference pages in all"
        },
        {
          "label": "Credentials",
          "value": "API key in the `X-SmartToken` header (full company access, no scopes, no expiry, revocable), or OAuth 2.0 client credentials and authorisation code grants with 49 scopes. Both are created by an administrator in Credential Manager"
        },
        {
          "label": "Token lifetime",
          "value": "Client credentials access tokens expire after 1,799 seconds. The client ID and secret don't expire and can be revoked"
        },
        {
          "label": "Rate limits",
          "value": "10 requests a second and 8 concurrent per credential. 2 a second on job publication and offer document downloads. 1 concurrent on `GET /candidates`"
        },
        {
          "label": "Pagination",
          "value": "Cursor paging with `limit` (maximum 100, default 10 on candidate search) and `pageId` from `nextPageId` or the `Link` header. Some endpoints still use `offset`"
        },
        {
          "label": "Webhooks",
          "value": "54 events on `POST /subscriptions` covering jobs, positions, applications, candidates, offer records, approvals, reviews, onboarding and interviews. Notifications carry resource IDs only. Optional HMAC SHA256 signature, and a callback log endpoint"
        },
        {
          "label": "Reports",
          "value": "Reporting API generates report files asynchronously from Report Builder reports and returns CSV"
        },
        {
          "label": "No authentication",
          "value": "The Posting API and common endpoints return published job data without a credential, for example `GET /v1/companies/{companyIdentifier}/postings`"
        },
        {
          "label": "Sandbox",
          "value": "The pricing page lists Sandbox Management as a product and Advanced Sandbox in the Complete plan. No free developer sandbox found"
        },
        {
          "label": "SLA",
          "value": "99.9 per cent annual system availability for paid subscriptions, with a penalty of 10 per cent of 12 months' fees per 1 per cent below it, on written request (https://www.smartrecruiters.com/legal/service-level-agreement/)"
        },
        {
          "label": "Status",
          "value": "status.smartrecruiters.com on Statuspage with 11 components, among them Customer API and Marketplace API"
        },
        {
          "label": "Certifications",
          "value": "The trust centre lists SOC 2 Type 2, ISO 27001, TISAX and UK Cyber Essentials, and says external penetration tests run once a year"
        },
        {
          "label": "Hosting and sub-processors",
          "value": "Default hosting in Frankfurt on AWS, with Ohio and Sydney as alternatives. The sub-processor list names each vendor, its purpose and location"
        },
        {
          "label": "Ownership",
          "value": "Acquired by SAP. The site footer reads \"SmartRecruiters, part of SAP SuccessFactors\" and the copyright line names SmartRecruiters, Inc."
        }
      ],
      "provenance": {
        "legalEntity": "SmartRecruiters, Inc.",
        "domain": "smartrecruiters.com",
        "domainRegistered": "2005-11-20",
        "endpointOnVendorDomain": true,
        "terms": "https://www.smartrecruiters.com/legal/terms-and-conditions/",
        "privacy": "https://www.smartrecruiters.com/legal/general-privacy-policy/",
        "statusPage": "https://status.smartrecruiters.com",
        "changelog": "https://developers.smartrecruiters.com/changelog",
        "securityTxt": "none",
        "checked": "2026-10-07",
        "notes": [
          "The privacy notice names SmartRecruiters, Inc. as owner and data controller and was last updated on 2 March 2026. The site footer reads \"SmartRecruiters, part of SAP SuccessFactors\".",
          "The Master Subscription Agreement is version 15 November 2024 and is governed by Delaware law where the contracting entity is SmartRecruiters, Inc. Earlier versions back to 2017 are archived on the legal page.",
          "The sub-processor list gives SmartRecruiters GmbH's address as c/o SAP SE, Dietmar-Hopp-Allee 16, Walldorf.",
          "www.smartrecruiters.com/.well-known/security.txt returns 404, and the same path on developers.smartrecruiters.com returns a docs page.",
          "Domain registration date from Verisign RDAP. The API answers at api.smartrecruiters.com."
        ],
        "score": 82,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "SmartRecruiters, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "smartrecruiters.com, registered 2005-11-20 (20 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.smartrecruiters.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 4.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 5 of the 8 things a reader expects",
            "points": 7.8,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.smartrecruiters.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.smartrecruiters.com/legal/terms-and-conditions/",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 5885,
            "points": 4.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "…set forth in the Order Form is: (1) SmartRecruiters, Inc., the Agreement will be governed (a) by the laws of the State of Delaware, without giving effect to any conflicts of laws principles that require the application of the law of a different jurisdiction, and the United Nations Convention on Contracts for the Inter…",
                "says": "The law of the State of Delaware"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "TO THE EXTENT PERMITTED UNDER APPLICABLE LAW, IN NO EVENT SHALL EITHER PARTY, OR ITS SUPPLIERS, BE LIABLE TO THE OTHER PARTY FOR ANY SPECIAL, INDIRECT, INCIDENTAL, PUNITIVE, EXEMPLARY, CONSEQUENTIAL DAMAGES, OR REASONABLE ATTORNEY’S FEES, RESULTING FROM OR IN CONNECTION WITH THIS AGREEMENT, REGARDLESS OF THE CAUSE OF…",
                "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Either Party may terminate this Agreement immediately upon written notice if the other Party materially breaches the Agreement and fails to cure such breach within thirty (30) days after receiving written notice of such breach."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Customer shall not: (a) permit any third party to access and/or use SmartRecruiters Applications, other than the Authorized Users authorized under the Agreement or application programming interface access granted by a third party;"
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "“Agreement” means this Master Subscription Agreement, Purchase Documents, the Service Level Agreement, as defined below, any schedules, or other documents attached to this Agreement, and such other documents, attachments and exhibits that the Parties’ authorized representatives may mutually agree to in writing from ti…"
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "(f) introduce software or automated agents or scripts to the SmartRecruiters Applications so as to produce multiple accounts, generate automated searches, requests and queries, or to strip or mine data from the SmartRecruiters Applications;",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "(e) access the SmartRecruiters Applications to build or create a derivative, competitive, or similar product or service, or copy any ideas, features, functions or graphics of the SmartRecruiters Applications;",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "SmartRecruiters may include the customer's name and logo in its lists of customers in any format or media.",
                "quote": "Given the public nature of the relationship between the Parties, SmartRecruiters may include Customer’s name and logo in its lists of customers, regardless of format or media."
              },
              {
                "date": "2026-10-08",
                "text": "Thirty days after termination or expiry, API access for retrieving data ends and SmartRecruiters deletes the customer's data.",
                "quote": "After thirty (30) days, Customer agrees that no access to SmartRecruiters’ Customer API will be granted to Customer any further, SmartRecruiters will remove Customer’s access, and SmartRecruiters will delete Customer’s data."
              },
              {
                "date": "2026-10-08",
                "text": "Authorised users may not be competitors of SmartRecruiters, described as any talent acquisition related software company.",
                "quote": "Notwithstanding the foregoing, Authorized Users shall not be SmartRecruiters’ competitors (any talent acquisition related software company)."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.smartrecruiters.com/legal/general-privacy-policy/",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 2761,
            "points": 7.8,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "As a Website Visitor, we may collect different types of data directly from you or through third parties such as:"
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Unless specified otherwise in this document, Personal Data shall be processed and stored for as long as required by the purpose they have been collected for and may be retained for longer due to applicable legal obligation or based on the Users’ consent.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Explore and find trusted service providers, apps, technologies to help you hire better."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": false
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Therefore, the right of access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "For all questions about the services, you can send an email to [email protected].",
                "says": "Gives an email address, hidden from our reader by the page"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/smartrecruiters.json",
      "live": {
        "slug": "smartrecruiters",
        "probe": {
          "target": "https://api.smartrecruiters.com",
          "method": "get",
          "lastAt": "2026-10-08T17:36:45.618742025Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 574,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 572,
          "p95ms24h": 896,
          "samples24h": 25,
          "samples30d": 25,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 25,
              "ok": 25
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.smartrecruiters.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T17:25:48.37967365Z"
        },
        "securityTxt": {
          "url": "https://smartrecruiters.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:41.34049374Z"
        },
        "updatedAt": "2026-10-08T17:36:45.618742025Z"
      }
    },
    "verify": {
      "accepts": "a page on smartrecruiters.com or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/smartrecruiters.svg",
      "body": {
        "slug": "smartrecruiters",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/smartrecruiters",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/smartrecruiters\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/smartrecruiters.svg\" alt=\"SmartRecruiters on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![SmartRecruiters on Anchor Terminal](https://www.anchorterminal.com/badges/smartrecruiters.svg)](https://www.anchorterminal.com/tools/smartrecruiters)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/smartrecruiters\"\u003eSmartRecruiters on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/smartrecruiters",
    "json": "https://www.anchorterminal.com/tools/smartrecruiters.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/smartrecruiters.md",
    "slim": "https://www.anchorterminal.com/tools/smartrecruiters.min.md"
  },
  "markdown": "## Overview\n\n**Grade C · 60.4/100 · rank #356 of 629 · #4 in Recruiting \u0026 applicant tracking · not agent-ready · confidence medium**\n\n\n## Assessment\n\nOAuth client credentials limited by 49 scopes, a system role and an access group, with per-operation OpenAPI definitions, llms.txt and a dated changelog. Access needs a paid SmartRecruiters account, with the lowest plan starting at $14,995, and no free tier, official SDK or idempotency key was found.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | SmartRecruiters, Inc. (an SAP company) (https://www.smartrecruiters.com) |\n| Kind | HTTP API |\n| Category | Recruiting \u0026 applicant tracking (https://www.anchorterminal.com/categories/recruiting) |\n| Transport | HTTP |\n| Endpoint | `https://api.smartrecruiters.com` |\n| Auth | OAuth or key · Access is granted by a paying customer's administrator, who creates an API key or an OAuth client ID in Credential Manager. The API key goes in the `X-SmartToken` header, has full access to company data and doesn't expire. OAuth 2.0 client credentials are limited by 49 scopes, a system role and an optional access group, and their access tokens last 1,799 seconds. Partners distributing an app to all customers use the authorisation code grant, and new partner integrations are managed through the SAP PartnerEdge Build programme. The Posting API needs no credential. |\n| Pricing | Paid (Paid) · No free tier, trial or self-serve signup found, so an agent can't start without a customer contract. The pricing page lists Essential \"starting at $14,995\" with no billing period stated, and Professional, High Volume and Complete on request. No separate API charge is published. Sandbox Management is listed as a product and Advanced Sandbox sits in the Complete plan. Only the Posting API, which returns published jobs, works without an account. |\n| x402 | No · No x402, MPP or L402 in the developer docs, llms.txt or the pricing page (checked 2026-10-07). |\n| Licence | Proprietary service under the SmartRecruiters Master Subscription Agreement |\n| Docs | https://developers.smartrecruiters.com |\n| llms.txt | https://developers.smartrecruiters.com/llms.txt |\n| Last release | 2026-10-05 |\n| Surface graded | The public REST API (Customer API) at https://api.smartrecruiters.com. The vendor's MCP page says the MCP server isn't supported for the public API |\n| API groups | 30 groups in llms.txt, among them Jobs, Candidates, Job Applications, Interviews, Self Scheduling, Offer, Reviews, Approvals, Messages, Reporting, Configuration, Users, Audit, Webhooks and SmartOnboard, 326 reference pages in all |\n| Credentials | API key in the `X-SmartToken` header (full company access, no scopes, no expiry, revocable), or OAuth 2.0 client credentials and authorisation code grants with 49 scopes. Both are created by an administrator in Credential Manager |\n| Token lifetime | Client credentials access tokens expire after 1,799 seconds. The client ID and secret don't expire and can be revoked |\n| Rate limits | 10 requests a second and 8 concurrent per credential. 2 a second on job publication and offer document downloads. 1 concurrent on `GET /candidates` |\n| Pagination | Cursor paging with `limit` (maximum 100, default 10 on candidate search) and `pageId` from `nextPageId` or the `Link` header. Some endpoints still use `offset` |\n| Webhooks | 54 events on `POST /subscriptions` covering jobs, positions, applications, candidates, offer records, approvals, reviews, onboarding and interviews. Notifications carry resource IDs only. Optional HMAC SHA256 signature, and a callback log endpoint |\n| Reports | Reporting API generates report files asynchronously from Report Builder reports and returns CSV |\n| No authentication | The Posting API and common endpoints return published job data without a credential, for example `GET /v1/companies/{companyIdentifier}/postings` |\n| Sandbox | The pricing page lists Sandbox Management as a product and Advanced Sandbox in the Complete plan. No free developer sandbox found |\n| SLA | 99.9 per cent annual system availability for paid subscriptions, with a penalty of 10 per cent of 12 months' fees per 1 per cent below it, on written request (https://www.smartrecruiters.com/legal/service-level-agreement/) |\n| Status | status.smartrecruiters.com on Statuspage with 11 components, among them Customer API and Marketplace API |\n| Certifications | The trust centre lists SOC 2 Type 2, ISO 27001, TISAX and UK Cyber Essentials, and says external penetration tests run once a year |\n| Hosting and sub-processors | Default hosting in Frankfurt on AWS, with Ohio and Sydney as alternatives. The sub-processor list names each vendor, its purpose and location |\n| Ownership | Acquired by SAP. The site footer reads \"SmartRecruiters, part of SAP SuccessFactors\" and the copyright line names SmartRecruiters, Inc. |\n| Capabilities | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters |\n| Tags | hosted, enterprise, oauth, api-key, openapi, llms-txt, webhooks, sales-led, status-page, soc2, closed-source |\n| JSON | https://www.anchorterminal.com/api/v1/tools/smartrecruiters.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 78 | 15.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 75 | 12.2 |\n| Agent ergonomics | 13% | 16.2 | 51 | 8.3 |\n| Security \u0026 auth | 14% | 17.5 | 65 | 11.4 |\n| Payments \u0026 pricing | 10% | 12.5 | 8 | 1.0 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 58 | 5.1 |\n| Transparency \u0026 trust (editorial 75, provenance 82) | 7% | 8.8 | 79 | 6.9 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **60.4 → C** |\n\n### Why each score\n\n- Reliability 78: Graded on the public REST API. Statuspage at status.smartrecruiters.com with 11 components, among them Customer API and Marketplace API (20). Two incidents in the 90 days to 7 October, both on Recruiter Apps. Errors on the People, Job and Communities pages in the EU datacentre for 84 minutes on 21 July, marked major, and a 20-minute login fault on 7 September. Neither names the Customer API, so we scored between a minor record and one major outage (15). Limits are published at 10 requests a second and 8 concurrent per credential (15). X-RateLimit headers on every response and exponential backoff guidance, but Retry-After is documented only for the deprecated Analytics API and no idempotency keys were found for writes (8). SLA of 99.9 per cent annual availability for paid subscriptions (10). The API is generally available, with single fields marked alpha (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 75: Each reference page carries an OpenAPI 3.0.1 definition and a Swagger page exists. We found no single downloadable spec file (23). llms.txt of 511 lines and every docs page served as Markdown (10). Descriptions are uneven. Candidate search and status updates explain behaviour, while creating an interview has an empty description (9). Inputs are typed with enums, minimum and maximum values, patterns and required fields (12). Error codes are named per operation, such as REQUIRED_SUB_STATUS_OMITTED, with an ErrorResponse schema, but the definitions we read had no examples and the Get Started example posts a user body to `/jobs` (8). Dated changelog with an RSS feed, and a written breaking changes policy with versioned endpoints (13).\n- Agent ergonomics 51: List endpoints take `limit` up to 100 with a default of 10, and webhooks carry IDs only. No field selection found (12). Cursor paging by `pageId` and filters such as `status`, `jobId` and `updatedAfter`, though some endpoints still page by `offset` (16). Errors return a code and message, with the codes listed per operation (14). No idempotency keys found. The docs advise backoff and a 128-second client timeout (3). Few required parameters and sensible defaults, but no official SDK in any language (6).\n- Security \u0026 auth 65: OAuth 2.0 client credentials with 49 scopes, a system role and an optional access group, 1,799-second access tokens and revocation in Credential Manager. An unscoped API key with full company access and no expiry is also available, and secrets travel in headers only (26). Read scopes are separate from write and manage scopes, and access groups limit which records a credential sees. No confirmation step for deletes found (13). The API returns CVs and screening answers written by candidates, and no prompt-injection guidance was found (2). Audit API for administrators with at least 26 months of retention, and a webhook callback log (11). The trust centre lists SOC 2 Type 2, ISO 27001, TISAX and UK Cyber Essentials with yearly external penetration tests. No security.txt or bug bounty found (13).\n- Payments \u0026 pricing 8: No x402, MPP or L402 (0). The pricing page gives one figure, Essential \"starting at $14,995\" with no period stated, and the other three plans on request (5). No free tier or trial found (0). A customer administrator has to create the credential in a browser. The Posting API returns published jobs with no credential, which earns partial credit (3).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 58: Newest changelog entry 5 October 2026, on offer property details (30). Nine dated entries between 24 August and 5 October (20). Closed service with a changelog and RSS feed. API issues go through Contact Support inside a customer account, and no public developer forum was found (8). No official SDKs (0). No packages to assess (0).\n- Transparency \u0026 trust 79: Editorial half. Closed service with a public Master Subscription Agreement (version 15 November 2024) and an archive of earlier versions (15). Privacy notice updated 2 March 2026, a pre-signed DPA, 30 days of API access after termination followed by deletion, and 26 months of audit retention. The AI addendum lets SmartRecruiters train on anonymised or pseudonymised data, and the detailed retention documents sit in the trust centre (24). Written policy of at least 10 months' notice before a sunset and 24 months of support for earlier versions (18). Sub-processor list with purposes and locations, default hosting in Frankfurt with Ohio and Sydney as alternatives (18).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/smartrecruiters.md (JSON https://www.anchorterminal.com/fixes/smartrecruiters.json)\n\n### What we couldn't check\n\n- unchecked: the SmartSandbox product page returned 403 to our reader, so sandbox terms and price are not established\n- unchecked: trust centre documents (SOC 2 report, data retention policy, penetration test reports) are behind an access request\n- unchecked: the billing period for the $14,995 Essential starting price, which the pricing page doesn't state\n- unchecked: the tools on https://developers.smartrecruiters.com/mcp, which answers 401. The vendor's MCP page says it isn't supported for the public API\n- Whether a single downloadable OpenAPI file exists beyond the per-page definitions and the Swagger page\n- The date SAP's acquisition closed, which the vendor's acquisition page doesn't give\n- Whether the Audit API records API calls by credential or only the account and MFA events it lists\n- Whether any endpoint accepts an idempotency key. None appeared in the seven reference pages read\n\n### Sources\n\n- developer docs index (llms.txt): \u003chttps://developers.smartrecruiters.com/llms.txt\u003e (seen 2026-10-07)\n- authentication methods: \u003chttps://developers.smartrecruiters.com/docs/authentication.md\u003e (seen 2026-10-07)\n- API key: \u003chttps://developers.smartrecruiters.com/docs/authentication-api-key.md\u003e (seen 2026-10-07)\n- OAuth client credentials: \u003chttps://developers.smartrecruiters.com/docs/authentication-oauth-client-credential.md\u003e (seen 2026-10-07)\n- access scopes: \u003chttps://developers.smartrecruiters.com/docs/access-scopes.md\u003e (seen 2026-10-07)\n- partner app registration and SAP notice: \u003chttps://developers.smartrecruiters.com/docs/register-an-app.md\u003e (seen 2026-10-07)\n- rate limits: \u003chttps://developers.smartrecruiters.com/docs/rate-limiting.md\u003e (seen 2026-10-07)\n- throttling policies: \u003chttps://developers.smartrecruiters.com/docs/throttling-policies.md\u003e (seen 2026-10-07)\n- pagination: \u003chttps://developers.smartrecruiters.com/docs/pagination.md\u003e (seen 2026-10-07)\n- error handling: \u003chttps://developers.smartrecruiters.com/docs/error-handling.md\u003e (seen 2026-10-07)\n- breaking changes policy: \u003chttps://developers.smartrecruiters.com/docs/breaking-changes.md\u003e (seen 2026-10-07)\n- deprecation and sunset policy: \u003chttps://developers.smartrecruiters.com/docs/deprecation-and-sunset-policies.md\u003e (seen 2026-10-07)\n- MCP page: \u003chttps://developers.smartrecruiters.com/docs/mcp.md\u003e (seen 2026-10-07)\n- candidate search reference with OpenAPI definition: \u003chttps://developers.smartrecruiters.com/reference/candidatesall-1.md\u003e (seen 2026-10-07)\n- candidate status update reference: \u003chttps://developers.smartrecruiters.com/reference/candidatesstatusupdate-1.md\u003e (seen 2026-10-07)\n- webhook subscription reference and events: \u003chttps://developers.smartrecruiters.com/reference/subscriptionscreate-1.md\u003e (seen 2026-10-07)\n- Audit API reference: \u003chttps://developers.smartrecruiters.com/reference/auditget-1.md\u003e (seen 2026-10-07)\n- changelog feed: \u003chttps://developers.smartrecruiters.com/changelog.rss\u003e (seen 2026-10-07)\n- status incidents: \u003chttps://status.smartrecruiters.com/api/v2/incidents.json\u003e (seen 2026-10-07)\n- pricing: \u003chttps://www.smartrecruiters.com/pricing/\u003e (seen 2026-10-07)\n- service level agreement: \u003chttps://www.smartrecruiters.com/legal/service-level-agreement/\u003e (seen 2026-10-07)\n- Master Subscription Agreement: \u003chttps://www.smartrecruiters.com/legal/terms-and-conditions/\u003e (seen 2026-10-07)\n- privacy notice: \u003chttps://www.smartrecruiters.com/legal/general-privacy-policy/\u003e (seen 2026-10-07)\n- sub-processors: \u003chttps://www.smartrecruiters.com/legal/subprocessors/\u003e (seen 2026-10-07)\n- AI addendum: \u003chttps://www.smartrecruiters.com/legal/artificial-intelligence-addendum/\u003e (seen 2026-10-07)\n- trust centre: \u003chttps://trust.smartrecruiters.com/\u003e (seen 2026-10-07)\n- SAP acquisition page: \u003chttps://www.smartrecruiters.com/about-us/sap-acquires-smartrecruiters/\u003e (seen 2026-10-07)\n- GitHub organisation: \u003chttps://github.com/smartrecruiters\u003e (seen 2026-10-07)\n\n## Who's behind it (provenance 82/100, checked 2026-10-07)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | SmartRecruiters, Inc. | 20/20 |\n| Domain age | smartrecruiters.com, registered 2005-11-20 (20 years) | 15/15 |\n| Endpoint on the vendor's domain | api.smartrecruiters.com | 15/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points | 4.3/10 |\n| Privacy policy | read, states 5 of the 8 things a reader expects | 7.8/10 |\n| Status page | status.smartrecruiters.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe privacy notice names SmartRecruiters, Inc. as owner and data controller and was last updated on 2 March 2026. The site footer reads \"SmartRecruiters, part of SAP SuccessFactors\".\n\nThe Master Subscription Agreement is version 15 November 2024 and is governed by Delaware law where the contracting entity is SmartRecruiters, Inc. Earlier versions back to 2017 are archived on the legal page.\n\nThe sub-processor list gives SmartRecruiters GmbH's address as c/o SAP SE, Dietmar-Hopp-Allee 16, Walldorf.\n\nwww.smartrecruiters.com/.well-known/security.txt returns 404, and the same path on developers.smartrecruiters.com returns a docs page.\n\nDomain registration date from Verisign RDAP. The API answers at api.smartrecruiters.com.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.smartrecruiters.com/legal/terms-and-conditions/), read 2026-10-08, gives no date, states 5 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"(f) introduce software or automated agents or scripts to the SmartRecruiters Applications so as to produce multiple accounts, generate automated searches, requests and queries, or to strip or mine data from the SmartRecruiters Applications;\"\n- To know. Restricts benchmarking or competitive use (costs points). \"(e) access the SmartRecruiters Applications to build or create a derivative, competitive, or similar product or service, or copy any ideas, features, functions or graphics of the SmartRecruiters Applications;\"\n- Not found in the text. Gives the date it was last updated.\n- Names the governing law or courts. The law of the State of Delaware.\n- States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence.\n- Not found in the text. Says how changes to the terms are announced.\n- Also in the text (2026-10-08). SmartRecruiters may include the customer's name and logo in its lists of customers in any format or media. \"Given the public nature of the relationship between the Parties, SmartRecruiters may include Customer’s name and logo in its lists of customers, regardless of format or media.\"\n- Also in the text (2026-10-08). Thirty days after termination or expiry, API access for retrieving data ends and SmartRecruiters deletes the customer's data. \"After thirty (30) days, Customer agrees that no access to SmartRecruiters’ Customer API will be granted to Customer any further, SmartRecruiters will remove Customer’s access, and SmartRecruiters will delete Customer’s data.\"\n- Also in the text (2026-10-08). Authorised users may not be competitors of SmartRecruiters, described as any talent acquisition related software company. \"Notwithstanding the foregoing, Authorized Users shall not be SmartRecruiters’ competitors (any talent acquisition related software company).\"\n\n**Privacy policy** (https://www.smartrecruiters.com/legal/general-privacy-policy/), read 2026-10-08, gives no date, states 5 of the 8 things a reader expects.\n\n- Not found in the text. Gives the date it was last updated.\n- Says how long data is kept. For as long as needed, with no period named.\n- Not found in the text. Says whether personal data is sold or shared for advertising.\n- Gives a privacy contact. Gives an email address, hidden from our reader by the page.\n- Not found in the text. Says where data is transferred or stored.\n\n## Live (updated 2026-10-08 17:36 UTC)\n\n- Right now: up, HTTP 200, 574 ms, checked 2026-10-08 17:36 UTC (get on `https://api.smartrecruiters.com`)\n- Uptime 24h 100.0% (25 probes) · 30 days 100.0% (25 probes) · p50 572 ms · p95 896 ms\n- Vendor status page: none, All Systems Operational\n- security.txt: none\n- Always current: https://www.anchorterminal.com/api/v1/live/smartrecruiters.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- OAuth 2.0 client credentials with 49 scopes, a system role and an optional access group. Access tokens last 1,799 seconds\n- Every reference page is served as Markdown with an OpenAPI 3.0.1 definition, indexed by a 511-line llms.txt\n- Limits are published. 10 requests a second and 8 concurrent per credential, with X-RateLimit headers on every response\n- Written policy of at least 10 months' notice before an endpoint is sunset, and 24 months of support for earlier versions\n- Audit API with at least 26 months of retention, and 54 webhook events with optional HMAC SHA256 signatures\n\n## Weaknesses\n\n- No free tier, trial or self-serve signup found. The Essential plan starts at $14,995 and the other three plans are quoted on request\n- No idempotency keys in the reference pages we read, so a create retried after a timeout can duplicate a candidate or interview\n- No official SDK, and the vendor's MCP page says the MCP server isn't supported for the public API\n- An API key has full access to company data with no scopes and no expiry\n- Offer endpoints are read-only, and new partner apps now go through the SAP PartnerEdge Build programme\n\n## Before you call it (notes for agents)\n\n1. Ask the customer's admin for an OAuth client ID with only the scopes needed. An API key reads and writes all company data and never expires\n2. Exchange the client ID and secret at https://api.smartrecruiters.com/identity/oauth/token and refresh every 30 minutes\n3. Stay under 10 requests a second and 8 concurrent. `GET /candidates` allows 1 concurrent request, and job publication 2 a second\n4. Move a candidate with `PUT /candidates/{id}/jobs/{jobId}/status`. The variants without `jobId` act on the most recently updated application\n5. Page with `limit` (maximum 100, default 10) and `pageId` from `nextPageId`. Use the Reporting API for bulk reads, which returns CSV\n\n## Connect\n\nFirst request:\n\n```bash\ncurl https://api.smartrecruiters.com/identity/oauth/token \\\n  -X POST \\\n  -H 'Content-Type: application/x-www-form-urlencoded' \\\n  -d \"client_id=$SMARTRECRUITERS_CLIENT_ID\" \\\n  -d \"client_secret=$SMARTRECRUITERS_CLIENT_SECRET\" \\\n  -d 'grant_type=client_credentials'\n```\n\nThrough letme (picks today, calling later): https://letme.dev/smartrecruiters. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Greenhouse | B | 64.8 | 248 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters | no | https://www.anchorterminal.com/tools/greenhouse.md |\n| Ashby | C | 61.3 | 328 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters | no | https://www.anchorterminal.com/tools/ashby.md |\n| Lever | D | 53.6 | 478 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters | no | https://www.anchorterminal.com/tools/lever.md |\n| Workable | C | 61.7 | 320 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.offer-letters | no | https://www.anchorterminal.com/tools/workable.md |\n| BambooHR | C | 61.7 | 319 | recruiting.applications, recruiting.jobs | no | https://www.anchorterminal.com/tools/bamboohr.md |\n| Rippling | C | 60.8 | 341 | recruiting.candidates | no | https://www.anchorterminal.com/tools/rippling.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The developer docs say SAP has acquired SmartRecruiters and that new technology partnerships and integrations are managed through the SAP PartnerEdge Build programme (source: \u003chttps://developers.smartrecruiters.com/docs/register-an-app.md, page updated 28 September 2026\u003e)\n- The MCP page in the developer docs reads \"The MCP Server is not supported for the Public API\", and https://developers.smartrecruiters.com/mcp answers 401 without a token (source: \u003chttps://developers.smartrecruiters.com/docs/mcp.md\u003e)\n- Each API reference page is served as Markdown with an OpenAPI 3.0.1 definition, and llms.txt indexes 326 reference pages across 30 API groups (source: \u003chttps://developers.smartrecruiters.com/llms.txt\u003e)\n- Rate limits are 10 requests a second and 8 concurrent requests per credential, 2 a second for job publication and 1 concurrent for `GET /candidates` (source: \u003chttps://developers.smartrecruiters.com/docs/rate-limiting.md\u003e)\n- The breaking changes policy promises at least 10 months' notice before an endpoint is sunset and support for earlier API versions for at least 24 months (source: \u003chttps://developers.smartrecruiters.com/docs/breaking-changes.md\u003e)\n- The pricing page lists Essential \"starting at $14,995\" with no billing period stated, and Professional, High Volume and Complete on request (source: \u003chttps://www.smartrecruiters.com/pricing/\u003e)\n\n## Compare\n\n- [Ashby vs SmartRecruiters](https://www.anchorterminal.com/compare/ashby-vs-smartrecruiters.md): C 61.3 vs C 60.4\n- [Greenhouse vs SmartRecruiters](https://www.anchorterminal.com/compare/greenhouse-vs-smartrecruiters.md): B 64.8 vs C 60.4\n- [Lever vs SmartRecruiters](https://www.anchorterminal.com/compare/lever-vs-smartrecruiters.md): D 53.6 vs C 60.4\n- [SmartRecruiters vs Workable](https://www.anchorterminal.com/compare/smartrecruiters-vs-workable.md): C 60.4 vs C 61.7\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on smartrecruiters.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"smartrecruiters\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/smartrecruiters\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/smartrecruiters.svg\" alt=\"SmartRecruiters on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![SmartRecruiters on Anchor Terminal](https://www.anchorterminal.com/badges/smartrecruiters.svg)](https://www.anchorterminal.com/tools/smartrecruiters)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/smartrecruiters\"\u003eSmartRecruiters on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say SmartRecruiters is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/smartrecruiters-dark.png\n- Light: https://www.anchorterminal.com/assets/share/smartrecruiters-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Recruiting \u0026 applicant tracking",
        "url": "https://www.anchorterminal.com/categories/recruiting"
      },
      {
        "name": "SmartRecruiters",
        "url": ""
      }
    ],
    "description": "Applicant tracking and recruiting platform from SmartRecruiters, an SAP company. Its Customer API covers jobs, candidates, applications, interviews, offer records, reports and webhooks over REST, with API key or OAuth 2.0 access for customers and approved partners.",
    "facts": [
      "rank #356 of 629",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "SmartRecruiters",
    "image": "https://www.anchorterminal.com/assets/og/tools-smartrecruiters.png",
    "path": "/tools/smartrecruiters",
    "published": "2026-10-01",
    "section": "tools",
    "title": "SmartRecruiters review for AI agents, grade C (60.4/100)",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/smartrecruiters"
  },
  "tokens": {
    "markdown": 7100,
    "slim": 1880
  },
  "version": 1
}
