# SmartRecruiters > Applicant tracking and recruiting platform from SmartRecruiters, an SAP company. Its Customer API covers jobs, candidates, applications, interviews, offer records, reports and webhooks over REST, with API key or OAuth 2.0 access for customers and approved partners. - Canonical: https://www.anchorterminal.com/tools/smartrecruiters - Markdown: https://www.anchorterminal.com/tools/smartrecruiters.md (~7,150 tokens) - Slim: https://www.anchorterminal.com/tools/smartrecruiters.min.md (~1,880 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/smartrecruiters.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade C · 60.4/100 · rank #356 of 629 · #4 in Recruiting & applicant tracking · not agent-ready · confidence medium** ## Assessment OAuth client credentials limited by 49 scopes, a system role and an access group, with per-operation OpenAPI definitions, llms.txt and a dated changelog. Access needs a paid SmartRecruiters account, with the lowest plan starting at $14,995, and no free tier, official SDK or idempotency key was found. ## Facts | Field | Value | | --- | --- | | Vendor | SmartRecruiters, Inc. (an SAP company) (https://www.smartrecruiters.com) | | Kind | HTTP API | | Category | Recruiting & applicant tracking (https://www.anchorterminal.com/categories/recruiting) | | Transport | HTTP | | Endpoint | `https://api.smartrecruiters.com` | | Auth | OAuth or key · Access is granted by a paying customer's administrator, who creates an API key or an OAuth client ID in Credential Manager. The API key goes in the `X-SmartToken` header, has full access to company data and doesn't expire. OAuth 2.0 client credentials are limited by 49 scopes, a system role and an optional access group, and their access tokens last 1,799 seconds. Partners distributing an app to all customers use the authorisation code grant, and new partner integrations are managed through the SAP PartnerEdge Build programme. The Posting API needs no credential. | | Pricing | Paid (Paid) · No free tier, trial or self-serve signup found, so an agent can't start without a customer contract. The pricing page lists Essential "starting at $14,995" with no billing period stated, and Professional, High Volume and Complete on request. No separate API charge is published. Sandbox Management is listed as a product and Advanced Sandbox sits in the Complete plan. Only the Posting API, which returns published jobs, works without an account. | | x402 | No · No x402, MPP or L402 in the developer docs, llms.txt or the pricing page (checked 2026-10-07). | | Licence | Proprietary service under the SmartRecruiters Master Subscription Agreement | | Docs | https://developers.smartrecruiters.com | | llms.txt | https://developers.smartrecruiters.com/llms.txt | | Last release | 2026-10-05 | | Surface graded | The public REST API (Customer API) at https://api.smartrecruiters.com. The vendor's MCP page says the MCP server isn't supported for the public API | | API groups | 30 groups in llms.txt, among them Jobs, Candidates, Job Applications, Interviews, Self Scheduling, Offer, Reviews, Approvals, Messages, Reporting, Configuration, Users, Audit, Webhooks and SmartOnboard, 326 reference pages in all | | Credentials | API key in the `X-SmartToken` header (full company access, no scopes, no expiry, revocable), or OAuth 2.0 client credentials and authorisation code grants with 49 scopes. Both are created by an administrator in Credential Manager | | Token lifetime | Client credentials access tokens expire after 1,799 seconds. The client ID and secret don't expire and can be revoked | | Rate limits | 10 requests a second and 8 concurrent per credential. 2 a second on job publication and offer document downloads. 1 concurrent on `GET /candidates` | | Pagination | Cursor paging with `limit` (maximum 100, default 10 on candidate search) and `pageId` from `nextPageId` or the `Link` header. Some endpoints still use `offset` | | Webhooks | 54 events on `POST /subscriptions` covering jobs, positions, applications, candidates, offer records, approvals, reviews, onboarding and interviews. Notifications carry resource IDs only. Optional HMAC SHA256 signature, and a callback log endpoint | | Reports | Reporting API generates report files asynchronously from Report Builder reports and returns CSV | | No authentication | The Posting API and common endpoints return published job data without a credential, for example `GET /v1/companies/{companyIdentifier}/postings` | | Sandbox | The pricing page lists Sandbox Management as a product and Advanced Sandbox in the Complete plan. No free developer sandbox found | | SLA | 99.9 per cent annual system availability for paid subscriptions, with a penalty of 10 per cent of 12 months' fees per 1 per cent below it, on written request (https://www.smartrecruiters.com/legal/service-level-agreement/) | | Status | status.smartrecruiters.com on Statuspage with 11 components, among them Customer API and Marketplace API | | Certifications | The trust centre lists SOC 2 Type 2, ISO 27001, TISAX and UK Cyber Essentials, and says external penetration tests run once a year | | Hosting and sub-processors | Default hosting in Frankfurt on AWS, with Ohio and Sydney as alternatives. The sub-processor list names each vendor, its purpose and location | | Ownership | Acquired by SAP. The site footer reads "SmartRecruiters, part of SAP SuccessFactors" and the copyright line names SmartRecruiters, Inc. | | Capabilities | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters | | Tags | hosted, enterprise, oauth, api-key, openapi, llms-txt, webhooks, sales-led, status-page, soc2, closed-source | | JSON | https://www.anchorterminal.com/api/v1/tools/smartrecruiters.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-07 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 78 | 15.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 75 | 12.2 | | Agent ergonomics | 13% | 16.2 | 51 | 8.3 | | Security & auth | 14% | 17.5 | 65 | 11.4 | | Payments & pricing | 10% | 12.5 | 8 | 1.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 58 | 5.1 | | Transparency & trust (editorial 75, provenance 82) | 7% | 8.8 | 79 | 6.9 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **60.4 → C** | ### Why each score - Reliability 78: Graded on the public REST API. Statuspage at status.smartrecruiters.com with 11 components, among them Customer API and Marketplace API (20). Two incidents in the 90 days to 7 October, both on Recruiter Apps. Errors on the People, Job and Communities pages in the EU datacentre for 84 minutes on 21 July, marked major, and a 20-minute login fault on 7 September. Neither names the Customer API, so we scored between a minor record and one major outage (15). Limits are published at 10 requests a second and 8 concurrent per credential (15). X-RateLimit headers on every response and exponential backoff guidance, but Retry-After is documented only for the deprecated Analytics API and no idempotency keys were found for writes (8). SLA of 99.9 per cent annual availability for paid subscriptions (10). The API is generally available, with single fields marked alpha (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 75: Each reference page carries an OpenAPI 3.0.1 definition and a Swagger page exists. We found no single downloadable spec file (23). llms.txt of 511 lines and every docs page served as Markdown (10). Descriptions are uneven. Candidate search and status updates explain behaviour, while creating an interview has an empty description (9). Inputs are typed with enums, minimum and maximum values, patterns and required fields (12). Error codes are named per operation, such as REQUIRED_SUB_STATUS_OMITTED, with an ErrorResponse schema, but the definitions we read had no examples and the Get Started example posts a user body to `/jobs` (8). Dated changelog with an RSS feed, and a written breaking changes policy with versioned endpoints (13). - Agent ergonomics 51: List endpoints take `limit` up to 100 with a default of 10, and webhooks carry IDs only. No field selection found (12). Cursor paging by `pageId` and filters such as `status`, `jobId` and `updatedAfter`, though some endpoints still page by `offset` (16). Errors return a code and message, with the codes listed per operation (14). No idempotency keys found. The docs advise backoff and a 128-second client timeout (3). Few required parameters and sensible defaults, but no official SDK in any language (6). - Security & auth 65: OAuth 2.0 client credentials with 49 scopes, a system role and an optional access group, 1,799-second access tokens and revocation in Credential Manager. An unscoped API key with full company access and no expiry is also available, and secrets travel in headers only (26). Read scopes are separate from write and manage scopes, and access groups limit which records a credential sees. No confirmation step for deletes found (13). The API returns CVs and screening answers written by candidates, and no prompt-injection guidance was found (2). Audit API for administrators with at least 26 months of retention, and a webhook callback log (11). The trust centre lists SOC 2 Type 2, ISO 27001, TISAX and UK Cyber Essentials with yearly external penetration tests. No security.txt or bug bounty found (13). - Payments & pricing 8: No x402, MPP or L402 (0). The pricing page gives one figure, Essential "starting at $14,995" with no period stated, and the other three plans on request (5). No free tier or trial found (0). A customer administrator has to create the credential in a browser. The Posting API returns published jobs with no credential, which earns partial credit (3). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 58: Newest changelog entry 5 October 2026, on offer property details (30). Nine dated entries between 24 August and 5 October (20). Closed service with a changelog and RSS feed. API issues go through Contact Support inside a customer account, and no public developer forum was found (8). No official SDKs (0). No packages to assess (0). - Transparency & trust 79: Editorial half. Closed service with a public Master Subscription Agreement (version 15 November 2024) and an archive of earlier versions (15). Privacy notice updated 2 March 2026, a pre-signed DPA, 30 days of API access after termination followed by deletion, and 26 months of audit retention. The AI addendum lets SmartRecruiters train on anonymised or pseudonymised data, and the detailed retention documents sit in the trust centre (24). Written policy of at least 10 months' notice before a sunset and 24 months of support for earlier versions (18). Sub-processor list with purposes and locations, default hosting in Frankfurt with Ohio and Sydney as alternatives (18). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/smartrecruiters.md (JSON https://www.anchorterminal.com/fixes/smartrecruiters.json) ### What we couldn't check - unchecked: the SmartSandbox product page returned 403 to our reader, so sandbox terms and price are not established - unchecked: trust centre documents (SOC 2 report, data retention policy, penetration test reports) are behind an access request - unchecked: the billing period for the $14,995 Essential starting price, which the pricing page doesn't state - unchecked: the tools on https://developers.smartrecruiters.com/mcp, which answers 401. The vendor's MCP page says it isn't supported for the public API - Whether a single downloadable OpenAPI file exists beyond the per-page definitions and the Swagger page - The date SAP's acquisition closed, which the vendor's acquisition page doesn't give - Whether the Audit API records API calls by credential or only the account and MFA events it lists - Whether any endpoint accepts an idempotency key. None appeared in the seven reference pages read ### Sources - developer docs index (llms.txt): (seen 2026-10-07) - authentication methods: (seen 2026-10-07) - API key: (seen 2026-10-07) - OAuth client credentials: (seen 2026-10-07) - access scopes: (seen 2026-10-07) - partner app registration and SAP notice: (seen 2026-10-07) - rate limits: (seen 2026-10-07) - throttling policies: (seen 2026-10-07) - pagination: (seen 2026-10-07) - error handling: (seen 2026-10-07) - breaking changes policy: (seen 2026-10-07) - deprecation and sunset policy: (seen 2026-10-07) - MCP page: (seen 2026-10-07) - candidate search reference with OpenAPI definition: (seen 2026-10-07) - candidate status update reference: (seen 2026-10-07) - webhook subscription reference and events: (seen 2026-10-07) - Audit API reference: (seen 2026-10-07) - changelog feed: (seen 2026-10-07) - status incidents: (seen 2026-10-07) - pricing: (seen 2026-10-07) - service level agreement: (seen 2026-10-07) - Master Subscription Agreement: (seen 2026-10-07) - privacy notice: (seen 2026-10-07) - sub-processors: (seen 2026-10-07) - AI addendum: (seen 2026-10-07) - trust centre: (seen 2026-10-07) - SAP acquisition page: (seen 2026-10-07) - GitHub organisation: (seen 2026-10-07) ## Who's behind it (provenance 82/100, checked 2026-10-07) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | SmartRecruiters, Inc. | 20/20 | | Domain age | smartrecruiters.com, registered 2005-11-20 (20 years) | 15/15 | | Endpoint on the vendor's domain | api.smartrecruiters.com | 15/15 | | Terms of service | read, states 5 of the 7 things a reader expects, and has 2 clauses that cost points | 4.3/10 | | Privacy policy | read, states 5 of the 8 things a reader expects | 7.8/10 | | Status page | status.smartrecruiters.com | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The privacy notice names SmartRecruiters, Inc. as owner and data controller and was last updated on 2 March 2026. The site footer reads "SmartRecruiters, part of SAP SuccessFactors". The Master Subscription Agreement is version 15 November 2024 and is governed by Delaware law where the contracting entity is SmartRecruiters, Inc. Earlier versions back to 2017 are archived on the legal page. The sub-processor list gives SmartRecruiters GmbH's address as c/o SAP SE, Dietmar-Hopp-Allee 16, Walldorf. www.smartrecruiters.com/.well-known/security.txt returns 404, and the same path on developers.smartrecruiters.com returns a docs page. Domain registration date from Verisign RDAP. The API answers at api.smartrecruiters.com. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.smartrecruiters.com/legal/terms-and-conditions/), read 2026-10-08, gives no date, states 5 of the 7 things a reader expects. - To know. Restricts automated access (costs points). "(f) introduce software or automated agents or scripts to the SmartRecruiters Applications so as to produce multiple accounts, generate automated searches, requests and queries, or to strip or mine data from the SmartRecruiters Applications;" - To know. Restricts benchmarking or competitive use (costs points). "(e) access the SmartRecruiters Applications to build or create a derivative, competitive, or similar product or service, or copy any ideas, features, functions or graphics of the SmartRecruiters Applications;" - Not found in the text. Gives the date it was last updated. - Names the governing law or courts. The law of the State of Delaware. - States a limit on its liability. Rules out indirect and consequential losses, with no cap named in this sentence. - Not found in the text. Says how changes to the terms are announced. - Also in the text (2026-10-08). SmartRecruiters may include the customer's name and logo in its lists of customers in any format or media. "Given the public nature of the relationship between the Parties, SmartRecruiters may include Customer’s name and logo in its lists of customers, regardless of format or media." - Also in the text (2026-10-08). Thirty days after termination or expiry, API access for retrieving data ends and SmartRecruiters deletes the customer's data. "After thirty (30) days, Customer agrees that no access to SmartRecruiters’ Customer API will be granted to Customer any further, SmartRecruiters will remove Customer’s access, and SmartRecruiters will delete Customer’s data." - Also in the text (2026-10-08). Authorised users may not be competitors of SmartRecruiters, described as any talent acquisition related software company. "Notwithstanding the foregoing, Authorized Users shall not be SmartRecruiters’ competitors (any talent acquisition related software company)." **Privacy policy** (https://www.smartrecruiters.com/legal/general-privacy-policy/), read 2026-10-08, gives no date, states 5 of the 8 things a reader expects. - Not found in the text. Gives the date it was last updated. - Says how long data is kept. For as long as needed, with no period named. - Not found in the text. Says whether personal data is sold or shared for advertising. - Gives a privacy contact. Gives an email address, hidden from our reader by the page. - Not found in the text. Says where data is transferred or stored. ## Live (updated 2026-10-08 18:22 UTC) - Right now: up, HTTP 200, 531 ms, checked 2026-10-08 18:20 UTC (get on `https://api.smartrecruiters.com`) - Uptime 24h 100.0% (33 probes) · 30 days 100.0% (33 probes) · p50 568 ms · p95 896 ms - Vendor status page: none, All Systems Operational - security.txt: none - Watching changelog - Always current: https://www.anchorterminal.com/api/v1/live/smartrecruiters.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - OAuth 2.0 client credentials with 49 scopes, a system role and an optional access group. Access tokens last 1,799 seconds - Every reference page is served as Markdown with an OpenAPI 3.0.1 definition, indexed by a 511-line llms.txt - Limits are published. 10 requests a second and 8 concurrent per credential, with X-RateLimit headers on every response - Written policy of at least 10 months' notice before an endpoint is sunset, and 24 months of support for earlier versions - Audit API with at least 26 months of retention, and 54 webhook events with optional HMAC SHA256 signatures ## Weaknesses - No free tier, trial or self-serve signup found. The Essential plan starts at $14,995 and the other three plans are quoted on request - No idempotency keys in the reference pages we read, so a create retried after a timeout can duplicate a candidate or interview - No official SDK, and the vendor's MCP page says the MCP server isn't supported for the public API - An API key has full access to company data with no scopes and no expiry - Offer endpoints are read-only, and new partner apps now go through the SAP PartnerEdge Build programme ## Before you call it (notes for agents) 1. Ask the customer's admin for an OAuth client ID with only the scopes needed. An API key reads and writes all company data and never expires 2. Exchange the client ID and secret at https://api.smartrecruiters.com/identity/oauth/token and refresh every 30 minutes 3. Stay under 10 requests a second and 8 concurrent. `GET /candidates` allows 1 concurrent request, and job publication 2 a second 4. Move a candidate with `PUT /candidates/{id}/jobs/{jobId}/status`. The variants without `jobId` act on the most recently updated application 5. Page with `limit` (maximum 100, default 10) and `pageId` from `nextPageId`. Use the Reporting API for bulk reads, which returns CSV ## Connect First request: ```bash curl https://api.smartrecruiters.com/identity/oauth/token \ -X POST \ -H 'Content-Type: application/x-www-form-urlencoded' \ -d "client_id=$SMARTRECRUITERS_CLIENT_ID" \ -d "client_secret=$SMARTRECRUITERS_CLIENT_SECRET" \ -d 'grant_type=client_credentials' ``` Through letme (picks today, calling later): https://letme.dev/smartrecruiters. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Greenhouse | B | 64.8 | 248 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters | no | https://www.anchorterminal.com/tools/greenhouse.md | | Ashby | C | 61.3 | 328 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters | no | https://www.anchorterminal.com/tools/ashby.md | | Lever | D | 53.6 | 478 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.interviews, recruiting.offer-letters | no | https://www.anchorterminal.com/tools/lever.md | | Workable | C | 61.7 | 320 | recruiting.candidates, recruiting.jobs, recruiting.applications, recruiting.offer-letters | no | https://www.anchorterminal.com/tools/workable.md | | BambooHR | C | 61.7 | 319 | recruiting.applications, recruiting.jobs | no | https://www.anchorterminal.com/tools/bamboohr.md | | Rippling | C | 60.8 | 341 | recruiting.candidates | no | https://www.anchorterminal.com/tools/rippling.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - The developer docs say SAP has acquired SmartRecruiters and that new technology partnerships and integrations are managed through the SAP PartnerEdge Build programme (source: ) - The MCP page in the developer docs reads "The MCP Server is not supported for the Public API", and https://developers.smartrecruiters.com/mcp answers 401 without a token (source: ) - Each API reference page is served as Markdown with an OpenAPI 3.0.1 definition, and llms.txt indexes 326 reference pages across 30 API groups (source: ) - Rate limits are 10 requests a second and 8 concurrent requests per credential, 2 a second for job publication and 1 concurrent for `GET /candidates` (source: ) - The breaking changes policy promises at least 10 months' notice before an endpoint is sunset and support for earlier API versions for at least 24 months (source: ) - The pricing page lists Essential "starting at $14,995" with no billing period stated, and Professional, High Volume and Complete on request (source: ) ## Compare - [Ashby vs SmartRecruiters](https://www.anchorterminal.com/compare/ashby-vs-smartrecruiters.md): C 61.3 vs C 60.4 - [Greenhouse vs SmartRecruiters](https://www.anchorterminal.com/compare/greenhouse-vs-smartrecruiters.md): B 64.8 vs C 60.4 - [Lever vs SmartRecruiters](https://www.anchorterminal.com/compare/lever-vs-smartrecruiters.md): D 53.6 vs C 60.4 - [SmartRecruiters vs Workable](https://www.anchorterminal.com/compare/smartrecruiters-vs-workable.md): C 60.4 vs C 61.7 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on smartrecruiters.com or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "smartrecruiters", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html SmartRecruiters on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![SmartRecruiters on Anchor Terminal](https://www.anchorterminal.com/badges/smartrecruiters.svg)](https://www.anchorterminal.com/tools/smartrecruiters) ``` Plain link: ```html SmartRecruiters on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say SmartRecruiters is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/smartrecruiters-dark.png - Light: https://www.anchorterminal.com/assets/share/smartrecruiters-light.png