# Worklio (slim) > Embedded US payroll from Worklio, Inc. for software platforms, PEOs and payroll bureaus. A partner's backend creates companies and workers, runs payroll in steps and reads tax forms through a REST API, with white-label screens as an alternative. - Full: https://www.anchorterminal.com/tools/worklio.md (~6,800 tokens) · this version ~1,880 tokens · JSON https://www.anchorterminal.com/tools/worklio.json · canonical https://www.anchorterminal.com/tools/worklio - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **E · 38.6/100 · rank #812 of 842 · #10 in Payroll infrastructure · not agent-ready · confidence medium** Assessment: Worklio documents 853 REST operations with an OpenAPI fragment on every reference page, and a developer can register for the sandbox without a sales call. No rate limits or public SDK were found, the status page is password protected, and the payroll guide tells callers to treat an HTTP 500 as the signal to finalise. ## Facts - Kind: HTTP API · vendor: Worklio, Inc. · category: Payroll infrastructure · legal entity: Worklio, Inc. · provenance 67/100 - Endpoint: `https://api.worklio.com` (HTTP) - Auth: OAuth · pricing: Paid · x402: no · licence: Proprietary service. The public Terms of Use date from 2014 and the partner agreement isn't public. The front-end library sits in a private repository - Probe metrics: not measured yet (probes haven't run) - Access graded: Embedded-payroll partner access through the REST API. A platform, PEO or payroll bureau runs payroll for its own client companies. No connector into an employer's payroll account at another provider - API: REST at https://api.worklio.com, `/wep/...` paths with an `api-version` header (2.0 in the reference) and `/api/public/...` paths for v1.0 list endpoints. 853 operations in 17 groups, among them Company, Employee, Payroll, Reports, Benefits Deductions, Time Attendance, W4 Requests and Client General Ledger - Payroll run: `POST /wep/companies/{companyId}/payroll` starts the default run, `.../payroll/{runId}/next` advances it, `.../finalize` finalises a locked run. Previous-step and discard calls roll a run back, and a locked run can't be discarded after its deadline - Credentials: OAuth 2.0 bearer JWT from `POST /connect/token`. Password grant for a System user (scope `api`, 24 hours), or an OpenID Connect browser flow for Admin and Employee users through the unpublished `@worklio/sdk` - User levels: System (all companies it created, suited to machine-to-machine use), Admin and ClientAdmin (one company), Employee (own data only) - Rate limits: None found in the reviewed documentation - Paging and filters: `limit`, `skip`, `filter` and `sort` as query parameters or `x-api-*` headers on `/api/public` endpoints, with a `DataToken` that expires after 60 seconds. Most `/wep` endpoints return everything - Errors: One JSON envelope with `status`, `code`, `errorCode`, `message` and per-field `validationErrors`. The reference pages sampled document only the 200 response - Webhooks: Company-level or system-wide, filtered by category (all, payroll, employee, client). HMAC-SHA256 signature in `WEP-Sign`. Payroll events are `Started`, `OnTimeSheet`, `Calculated`, `Approved`, `Locked` and `Finalized` - SDKs: None public. `@worklio/sdk`, `@worklio/wep`, `@worklio/wep-vue` and `@worklio/wep-react` are not on npm, and the docs send developers to support for access to a private GitHub repository - Sandbox: Self-serve developer registration at apiweb.worklio.com/RegisterDeveloper, then a dashboard of test companies. Production credentials and single sign-on are set up by Worklio - Certifications: SOC 2 Type 2, ISO/IEC 27001:2013, ISO/IEC 27018:2019 and ISO 9001:2015 claimed on the security page. Hosted on Microsoft Azure in the United States - Scores: Reliability 25, Performance pending, Schema & documentation 71, Agent ergonomics 44, Security & auth 48, Payments & pricing 25, Task success pending, Maintenance & community 25, Transparency & trust 48 · negative events -3 · total over the 7 assessed categories - Why: Reliability, Read with the hosted rubric, for embedded-payroll partner access. · Schema & documentation, Each of the 853 reference pages embeds an OpenAPI 3.0.4 fragment with schemas and the bearer scheme. · Agent ergonomics, No field selection, and the pagination guide says most `/wep` endpoints return their full result set on every call (8 of 25). · Security & auth, Bearer JWTs with one scope, `api`, lasting 24 hours. · Payments & pricing, Read with the hosted rubric. · Maintenance & community, The last dated API change is the pair of changelog entries of 30 June 2026, 101 days before the check (10 of 30). · Transparency & trust, Closed service. - Sources: 23, open questions: 10, both in the full twin - Capabilities: payroll.run, payroll.embedded, payroll.employees, payroll.tax-filing, payroll.contractors - JSON: https://www.anchorterminal.com/api/v1/tools/worklio.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/worklio.svg` or a link to https://www.anchorterminal.com/tools/worklio from a page on worklio.com or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send `api-version: 2.0` on `/wep` calls. The reference marks the header as required 2. Get a token from `POST https://api.worklio.com/connect/token` with the password grant and scope `api`. It lasts 24 hours, so fetch a new one daily 3. Run payroll as start, `next` until it answers 500 with "Next step operation is not allowed", then `finalize`. Don't treat that 500 as a failure 4. Don't retry bonus, off-cycle, void or termination payroll starts blindly. The reference says those calls are not idempotent 5. Most `/wep` list endpoints return the whole result set. Paging, `filter` and `sort` work only under `/api/public`, and a `DataToken` expires after 60 seconds ## Connect ```bash curl -s -X POST "https://api.worklio.com/connect/token" \ -H "accept: application/json" \ -H "content-type: application/x-www-form-urlencoded" \ --data-urlencode "grant_type=password" \ --data-urlencode "username=$WORKLIO_USERNAME" \ --data-urlencode "password=$WORKLIO_PASSWORD" \ --data-urlencode "scope=api" \ --data-urlencode "client_id=wep_resourceowner.public.api" \ --data-urlencode "client_secret=$WORKLIO_CLIENT_SECRET" ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/worklio ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Check | B | 67.5 | payroll.run, payroll.employees, payroll.embedded, payroll.tax-filing, payroll.contractors | https://www.anchorterminal.com/tools/check-payroll.min.md | | Gusto | B | 63.3 | payroll.run, payroll.employees, payroll.embedded, payroll.tax-filing, payroll.contractors | https://www.anchorterminal.com/tools/gusto.min.md | | Everee | C | 55.1 | payroll.run, payroll.embedded, payroll.employees, payroll.contractors, payroll.tax-filing | https://www.anchorterminal.com/tools/everee.min.md | | Employment Hero Payroll | D | 50.4 | payroll.run, payroll.employees, payroll.embedded, payroll.tax-filing, payroll.contractors | https://www.anchorterminal.com/tools/employment-hero.min.md | | Salsa | D | 46.1 | payroll.run, payroll.embedded, payroll.employees, payroll.tax-filing, payroll.contractors | https://www.anchorterminal.com/tools/salsa.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)