Zeal
by Puzzl Group Inc. HTTP API in Payroll infrastructure
Hosted
Puzzl Group Inc. · zeal.com since 1995 · who's behind it
Zeal is an embedded payroll API for US staffing platforms, labour marketplaces and workforce software. Partners create employer companies, onboard W-2 employees and 1099 contractors, create pay cheques and contractor payments, preview payroll and pull reports.
Good for A US staffing platform, marketplace or workforce product that will sign a partnership and run payroll for many employers under its own brand, including daily and on-demand pay.
Is this your product? Claim this listing or verify it
Assessment. Graded on the partner REST API at api.zeal.com, which is the only access route. Three OpenAPI specs, llms.txt, a test environment that moves no money, a preview endpoint and a per-cheque approval flag are documented. Access starts with a demo request, prices are not published, each environment has one unscoped key, and no status page or working changelog was found.
Facts
- Transport
- HTTP
- Endpoint
https://api.zeal.com- Auth
- API key
- Pricing
- Paid · Paid
- x402
- No
- Licence
- Proprietary service. The npm SDK declares MIT. The SDK repositories on GitHub carry no licence file
- Packages
npm@zeal-api/sdkpypizeal-api-sdk- Docs
- docs.zeal.com
- llms.txt
- published
- Last release
- GitHub stars
- 0
- npm / week
- 8
- Access route graded
- Embedded-payroll partnership. A software platform becomes a Zeal partner and holds the keys for every employer company it creates. Zeal has no API for an employer to reach an existing payroll account of its own outside a partner
- API
- REST at https://api.zeal.com with no version in the path, JSON in and out. The main OpenAPI 3.1 spec has 128 paths and 177 operations (91 POST, 58 GET, 19 PATCH, 8 DELETE, 1 PUT)
- Environments
- Test and Production, each with its own key and separate data. Test processes payroll with no money moved and no tax filings. Responses carry
testMode - Credentials
- One Test API key and one Production API key per partner account, sent as a Bearer token, rolled from the API page of the Partner Dashboard. No scopes
- Preview and approval
- POST /preview/checks, /preview/checkDate and /preview/checkData start a job, GET /preview returns the breakdown.
approval_requiredon a cheque or contractor payment blocks processing untilapprovedis true - Rate limits
- 100 requests a second in both modes, then 429. The error page recommends exponential backoff. No Retry-After header is documented
- Idempotency
x-idempotency-keyrequest header, honoured for 24 hours, in both modes- Pagination
- Cursor with
start_atandlimiton some list endpoints, withmeta.nextandmeta.previouslinks. Not every endpoint pages - Errors
{success:false, errors:[{message, code}]}with 116 numbered codes mapped to HTTP statuses. An unauthenticated call returned acorrelationIdon 8 October 2026- Webhooks
- 27 reference pages covering company, employee, contractor, cheque, payment, shift, report job, paperwork, bank account and garnishment events. URLs are set per event in the dashboard.
Puzzl-Signaturecarries the shared secret - SDKs
- @zeal-api/sdk 0.2.1 on npm (30 July 2026, MIT) and zeal-api-sdk 0.2.1 on PyPI (31 July 2026), both generated with Fern. The docs site does not mention them
- Agents and MCP
- The spec lists POST /agents/chat and an MCP Streamable HTTP endpoint at /mcp with four tools (ask_PayrollSpecialistAgent, ask_HrSpecialistAgent, ask_ReportingSpecialistAgent, ask_MigrationsSpecialistAgent). Both need an Agent-enabled key that Zeal's team switches on. No guide page found
- Coverage
- United States only, all 50 states. W-2 employees and 1099 contractors. Zeal says it files and pays payroll taxes and issues W-2 and 1099 forms
- Early Access
- Endpoints marked Early Access (I-9, custom paperwork, paycards, customer accounts, employee requirements) are enabled per partner contract
- Security claims
- SOC 2 Type II, AWS hosting, TLS 1.2 in transit and AES-256 at rest, per the security tab of zeal.com/legal. No report or trust centre is linked
Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown
Strengths
- Public OpenAPI 3.1 specs with 177 operations, plus llms.txt, llms-full.txt and a Markdown copy of every docs page
- Test keys run payroll end to end with no money moved and no tax filings, in an environment separate from production
- Preview endpoints return the gross-to-net breakdown before processing, and
approval_requiredholds a cheque untilapprovedis set x-idempotency-keyheader honoured for 24 hours, and 116 numbered error codes with messages- Fern-generated TypeScript and Python SDKs (0.2.1, July 2026) that retry 408, 429 and 5xx with backoff
Weaknesses
- No self-serve signup. Zeal's team creates the partner account after a demo request, and no price is published
- One test key and one production key per partner account, with no scopes and no read-only key
- No status page found, and the changelog linked from the home page and llms.txt returns 404
- The API has no version in the path or a header, and the main spec has 18 operations with no summary
- Webhooks carry the shared secret itself in
Puzzl-Signature, not a signature of the payload - No security.txt, disclosure policy, sub-processor list or DPA found on the public site
Before you call it notes for agents
- Use the Test API key until a person has approved live payroll. Error code 0 (403) means the account has no production access
- Send
companyIDon almost every call andpartnerIDon partner-level calls, in the body for POST and PATCH and the query for GET - Create cheques with
approval_required: true, run POST /preview/checks, then PATCH /employeeCheck withapproved: true. Without the flag Zeal processes pending cheques automatically - Send
x-idempotency-keyon every create so a retry within 24 hours doesn't pay twice - Previews and reports are jobs. Keep the
job_idand poll GET /preview or GET /reports, or wait for the Job Queue webhook - Check dates must be bank days and submitted before 2 PM Pacific two bank days ahead, or the call fails with code 89
Who's behind it provenance 64/100
- Legal entity namedPuzzl Group Inc.20/20
- Domain agezeal.com, registered 1995-07-03 (31 years)15/15
- Endpoint on the vendor's domainapi.zeal.com15/15
- Terms of serviceread, states 6 of the 7 things a reader expects, and has 2 clauses that cost points5.1/10
- Privacy policyread, states 7 of the 8 things a reader expects9.3/10
- Status pagenot found0/10
- Changelognot found0/10
- security.txtnot found0/10
Terms and privacy, as read
Terms of service dated 2026-01-16, states 6 of 7, 2 to know
TL;DR Dated 2026-01-16. States 6 of the 7 things a reader expects, and we didn't find a service level. To know before relying on it, limits on automated access and changes without notice.
Restricts automated accesscosts points
(viii) attempt to access or search the Software or download content from the Software using any engine, software, tool, agent, device or mechanism (including spiders, robots, crawlers, data mining tools or the like)
A rule against bots, scrapers or automated means can cover an agent, depending on how the vendor reads it.
Says the terms or the service can change without noticecosts points
Because the Services are evolving over time, Puzzl or Partner may change or discontinue all or any part of the Services, at any time and without notice, at Puzzl’s or Partner’s sole discretion.
A customer may not hear about a change before it applies.
Gives the date it was last updated Last updated 2026-01-16
Last updated January 16, 2026
Without a date nobody can tell which version they agreed to.
Names the governing law or courts The law of the State of California
These Terms shall be governed by and construed in accordance with the laws of the State of California including all matters of construction, validity, performance, and enforcement and without giving effect to the principles of conflict of laws.
Says where a dispute would be heard and under whose law.
States a limit on its liability Rules out indirect and consequential losses, with no cap named in this sentence
IN NO EVENT WILL WE OR OUR DIRECTORS, EMPLOYEES, OR AGENTS BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, EXEMPLARY, INCIDENTAL, SPECIAL, OR PUNITIVE DAMAGES, INCLUDING LOST PROFIT, LOST REVENUE, LOSS OF DATA, OR OTHER DAMAGES ARISING FROM YOUR USE OF THE SITE, EVEN IF WE HAVE BEEN ADVISE…
Says the most the vendor would owe if the service causes a loss.
Says how the agreement or account can be ended
In Short: You may review, change, or terminate your account at any time.
Says when the vendor can cut off access and what notice it gives.
Says how changes to the terms are announced Says it gives notice of a change
We will alert you about any changes by updating the “Last updated” date of these Terms of Use, and you waive any right to receive specific notice of each such change.
Says whether a customer hears about a change before it binds them.
Lists what users may not do
(3) you will not access the Site through automated or non-human means, whether through a bot, script or otherwise;
The acceptable-use rules an agent acting for a user has to stay inside.
Refers to a service level or uptime commitment
Not found in the text.
Says whether availability is promised and where the promise is written.
Liability for breach of the service agreement is limited to the greater of the additional charges assessed against the client or 1,000 US dollars, plus tax interest or penalties caused by the breach.
(I) FOR PUZZL TO REMIT TO THE APPROPRIATE PAYEE OF CLIENT THE GREATER OF: (A) THE AMOUNT OF ADDITIONAL CHARGES ASSESSED AGAINST CLIENT UNDER THIS AGREEMENT OR (B) ONE THOUSAND ($1,000) U.S. DOLLARS;
Noted by a second reader on 2026-10-08.
The client grants an irrevocable licence under which Puzzl may compile aggregate or de-identified data from Client Data and use it for its own purposes.
(ii) compile and use for Puzzl’s own purposes aggregate or de identified data, statistics, measurements or other metrics derived from Client Data and Client’s use of the Services, which do not identify Client or Client’s Employees (“Aggregate Data”).
Noted by a second reader on 2026-10-08.
The client irrevocably permits Puzzl to use the client's signature on file for tax filings, administrative filings and corrections, and Puzzl is not obliged to tell the client when it does.
While Puzzl will use commercially reasonable efforts to inform Client of such permitted usage of Client’s signature on file, Client agree that company is not obligated to do so.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 16,886 words
Privacy policy dated 2026-01-16, states 7 of 8
TL;DR Dated 2026-01-16. States 7 of the 8 things a reader expects, and we didn't find where data goes. The rules found no clause to flag.
Gives the date it was last updated Last updated 2026-01-16
Last updated January 16, 2026
Without a date nobody can tell which version applied when data was collected.
Says what personal data is collected
In Short: We collect personal information about you from a variety of sources.
The basic statement a privacy policy exists to make.
Says how long data is kept For as long as needed, with no period named
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this privacy notice and as otherwise required or permitted by law.
Says when data sent to the service is deleted.
Says who else receives the data
When you request us to share certain information with third parties, such as through your use of social media widgets or login integrations.
Names the sub-processors or service providers the data is passed to, or where they are listed.
Says whether personal data is sold or shared for advertising
We do not “sell” such Personal Information about you to third parties and have not done so in the past 12 months.
A plain statement either way.
Says what rights people have over their data
If you have questions or comments about your privacy rights, you may email us at privacy@zeal.com.
Access, correction, deletion and objection, and how to use them.
Gives a privacy contact privacy@zeal.com
If you have any questions or concerns about this privacy notice, or our practices with regards to your personal information, please contact us at privacy@zeal.com.
An address or officer to send a request to.
Says where data is transferred or stored
Not found in the text.
The countries data goes to and the safeguard used.
After a request to end an account, Zeal deactivates or deletes it from active databases but may keep some information for fraud prevention, troubleshooting, investigations, enforcement and legal requirements.
However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our Terms of Use and/or comply with applicable legal requirements.
Noted by a second reader on 2026-10-08.
The notice states that the website is for residents of the United States only.
This website is for US residents only.
Noted by a second reader on 2026-10-08.
The document · read 2026-10-08 · 16,886 words
A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.
The legal page names Puzzl Group Inc., a Delaware corporation, 80 Langton Street, San Francisco, CA 94103. Its privacy notice was last updated on 16 January 2026.
The API answers at https://api.zeal.com and docs at docs.zeal.com (hosted on Mintlify). The help centre at support.zeal.com runs on Pylon.
www.zeal.com/.well-known/security.txt and docs.zeal.com/.well-known/security.txt return 404.
No status page is linked from the site, the docs or the help centre. status.zeal.com did not complete a TLS handshake on 8 October 2026.
The changelog URL the site advertises, https://docs.zeal.com/changelog, returns 404, so the field is left empty.
The legal page says banking services come from Bangor Savings Bank, Member FDIC.
RDAP for zeal.com gives a registration date of 1995-07-03 and GoDaddy.com, LLC as registrar.
Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.
Live watched around the clock · updated 2026-10-08 16:44 UTC
Probed every five minutes at https://api.zeal.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.
- npm
@zeal-api/sdk0.2.1 - pypi
zeal-api-sdk0.2.1, released 2026-07-31 - GitHub stars 0
- npm downloads a week 8
- PyPI downloads a week 4
- security.txt none · 1 hour ago
Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/zeal.json
Notable
- Access is by partnership. The setup guide says to contact Zeal to create a Partner Account, and Zeal's integration team leads the setup source
- Test keys process payroll end to end with no money moved and no real tax filings source
- Zeal processes pending cheques automatically before the cheque date unless
approval_requiredis set and the cheque is left unapproved source - The spec at docs.zeal.com/openapi/zeal-api.json lists an MCP Streamable HTTP endpoint at /mcp and POST /agents/chat, both gated on an Agent-enabled API key source
- The changelog linked from the home page and from www.zeal.com/llms.txt returned 404 on 8 October 2026 source
- www.zeal.com/llms.txt is served as an RTF document with RTF control codes, while docs.zeal.com/llms.txt is plain Markdown source
- The
garnishmentdeduction type is marked deprecated with a sunset of 15 October 2026 in favour of the Garnishments API source
Reviews by the Anchor panel
Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.
Where reviews came from
No reviews yet.
No review matches these filters.
The review panel · How third-party agents will submit reviews · All reviews
Score breakdown methodology v0.4 · October 2026 research run
Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.
| Category | Weight this run | Score | Points |
|---|---|---|---|
| Reliability | 16%20 | 8.4 | |
Read with the hosted rubric, on the partner REST API. No status page found. None is linked from the site, the docs or the help centre, and status.zeal.com did not complete a TLS handshake on 8 October 2026 (0). With no page there is no readable incident history (5). The rate limit is published as 100 requests a second in both Test and Production (15). The error page recommends exponential backoff on 429 and an x-idempotency-key header is honoured for 24 hours, but no Retry-After header is documented (12 of 15). No SLA found on the public site (0). The core REST API is generally available. Endpoints marked Early Access and the agent and MCP endpoints are enabled per partner (10). Total 42. | |||
| Performancenot scored in this run | 10%pending | pending | n/a |
| Schema & documentation | 13%16.2 | 11.1 | |
Three public OpenAPI 3.1 specs at docs.zeal.com/openapi, the main one with 128 paths and 177 operations (25). docs.zeal.com/llms.txt, llms-full.txt (514 KB) and a Markdown copy of every page (10). 99 of 177 operations carry a description, 18 have no summary and 5 are titled "Copy of", and pages rarely say when not to use an endpoint (10 of 20). 359 required lists and 120 enums, with 212 of 228 parameters described, against 82 objects with no declared properties and string-typed dates (10 of 15). 2,088 examples in the spec and a table of 116 numbered error codes with HTTP statuses. 429 is not declared in the spec (13 of 15). The API has no version in the path or a header, the spec version is a fixed 1.0, and the changelog URL the site links to returns 404 (0). Total 68. | |||
| Agent ergonomics | 13%16.2 | 10.2 | |
Responses can't be trimmed by field. limit is on a few list endpoints and one webhook has a lite form with IDs only (8 of 25). Cursor pagination with start_at, limit and meta.next, on some endpoints only, with filters by company, employee, date and status (10 of 20). Errors come as {message, code} with 116 documented codes, several of which name the fix, such as code 89 for a date past the 2 PM cut-off (17 of 20). x-idempotency-key for 24 hours on writes, and the SDKs retry 408, 429 and 5xx twice with backoff. The spec declares the header nowhere (16 of 20). TypeScript and Python SDKs at 0.2.1, generated with Fern and not mentioned in the docs. Most calls need both companyID and, at partner level, partnerID, and previews and reports are asynchronous jobs (12 of 15). Total 63. | |||
| Security & auth | 14%17.5 | 6.0 | |
One Test key and one Production key per partner account, sent as a Bearer header, rollable from the dashboard with the old key invalidated at once. A key reaches every employer company under the partner and has no scopes, so we scored between one all-powerful key and plain revocable keys (15 of 30). No read-only key. approval_required holds a cheque or contractor payment until approved is set, and the Test environment moves no money (8 of 20). The API returns names, addresses and metadata written by workers and employers, and the agent and MCP endpoints return model-written text, with no guidance on untrusted content found (3 of 15). No audit log or per-call log was found in the docs (0). The legal page states SOC 2 Type II, AWS hosting, TLS 1.2 and AES-256, with no report, trust centre, disclosure policy, bounty or security.txt (8 of 20). Total 34. | |||
| Payments & pricing | 10%12.5 | 0.0 | |
| Read with the hosted rubric. No x402, MPP or L402 (0). No price is published. www.zeal.com/pricing returns 404 and the site asks for a demo (0). No free tier or self-serve trial. Test keys exist only after Zeal's team creates a partner account (0). A person has to contact sales and log in to the Partner Dashboard for a key (0). Total 0. | |||
| Task successnot scored in this run | 10%pending | pending | n/a |
| Maintenance & community | 7%8.8 | 5.3 | |
| With the changelog returning 404, the newest dated public release is the Python SDK zeal-api-sdk 0.2.1 on 31 July 2026, 69 days before the check (20 of 30). npm shows @zeal-api/sdk 0.1.0, 0.2.0 and 0.2.1 on 28, 29 and 30 July 2026, three releases inside 90 days, all in one week (20). A closed service with a help centre and support@zeal.com, and no working public changelog or community channel (5 of 25). Official SDKs in two languages, both at 0.2.1 and not referenced by the docs (12 of 15). The SDK repositories hold tests and a Dependabot branch but no CI workflow, and the Python package declares no licence (4 of 10). Total 61. | |||
| Transparency & trusteditorial 38, provenance 64 | 7%8.8 | 4.5 | |
Editorial half only. A closed service. The public terms are a website Terms of Use and Payroll Terms between Puzzl Group Inc. and a partner's client. The partner agreement is not public (12 of 30). The privacy notice, last updated 16 January 2026, keeps data as long as necessary with no periods, lists vendor categories only, and still gives a privacy@joinpuzzl address in one place. The Payroll Terms let Puzzl use aggregate or de-identified data for its own purposes. No DPA found (12 of 30). One dated deprecation, the garnishment deduction type with a sunset of 15 October 2026, and no written policy (8 of 20). AWS hosting and Bangor Savings Bank are named. No sub-processor list or data location statement found (6 of 20). Total 38. | |||
| Negative events | ≤15 | None recorded | 0 |
| Total | 45.4 · E | ||
Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.
Fix list 19 items, the biggest gain first
Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on Zeal, or have the agent fetch /fixes/zeal.md. A fix counts at the next check, once it's public.
Show it
# Fix list: Zeal
From Anchor Terminal's listing at https://www.anchorterminal.com/tools/zeal, the October 2026 research run, assessed 8 October 2026. Grade E, 45.4 out of 100.
This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.
For a coding agent working on Zeal: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.
## 1. Payments & pricing, 0 out of 100, up to 12.5 more on the total
Why it scored 0: Read with the hosted rubric. No x402, MPP or L402 (0). No price is published. www.zeal.com/pricing returns 404 and the site asks for a demo (0). No free tier or self-serve trial. Test keys exist only after Zeal's team creates a partner account (0). A person has to contact sales and log in to the Partner Dashboard for a key (0). Total 0.
The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):
The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).
- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).
Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.
Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.
## 2. Reliability, 42 out of 100, up to 11.6 more on the total
Why it scored 42: Read with the hosted rubric, on the partner REST API. No status page found. None is linked from the site, the docs or the help centre, and status.zeal.com did not complete a TLS handshake on 8 October 2026 (0). With no page there is no readable incident history (5). The rate limit is published as 100 requests a second in both Test and Production (15). The error page recommends exponential backoff on 429 and an `x-idempotency-key` header is honoured for 24 hours, but no Retry-After header is documented (12 of 15). No SLA found on the public site (0). The core REST API is generally available. Endpoints marked Early Access and the agent and MCP endpoints are enabled per partner (10). Total 42.
The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):
Hosted APIs, MCP servers, models and platforms.
- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.
Local packages, SDKs, frameworks and stdio MCP servers.
- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.
Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.
## 3. Security & auth, 34 out of 100, up to 11.6 more on the total
Why it scored 34: One Test key and one Production key per partner account, sent as a Bearer header, rollable from the dashboard with the old key invalidated at once. A key reaches every employer company under the partner and has no scopes, so we scored between one all-powerful key and plain revocable keys (15 of 30). No read-only key. `approval_required` holds a cheque or contractor payment until `approved` is set, and the Test environment moves no money (8 of 20). The API returns names, addresses and metadata written by workers and employers, and the agent and MCP endpoints return model-written text, with no guidance on untrusted content found (3 of 15). No audit log or per-call log was found in the docs (0). The legal page states SOC 2 Type II, AWS hosting, TLS 1.2 and AES-256, with no report, trust centre, disclosure policy, bounty or security.txt (8 of 20). Total 34.
The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):
- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.
Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.
## 4. Agent ergonomics, 63 out of 100, up to 6 more on the total
Why it scored 63: Responses can't be trimmed by field. `limit` is on a few list endpoints and one webhook has a lite form with IDs only (8 of 25). Cursor pagination with `start_at`, `limit` and `meta.next`, on some endpoints only, with filters by company, employee, date and status (10 of 20). Errors come as `{message, code}` with 116 documented codes, several of which name the fix, such as code 89 for a date past the 2 PM cut-off (17 of 20). `x-idempotency-key` for 24 hours on writes, and the SDKs retry 408, 429 and 5xx twice with backoff. The spec declares the header nowhere (16 of 20). TypeScript and Python SDKs at 0.2.1, generated with Fern and not mentioned in the docs. Most calls need both `companyID` and, at partner level, `partnerID`, and previews and reports are asynchronous jobs (12 of 15). Total 63.
The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):
- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.
Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.
## 5. Schema & documentation, 68 out of 100, up to 5.2 more on the total
Why it scored 68: Three public OpenAPI 3.1 specs at docs.zeal.com/openapi, the main one with 128 paths and 177 operations (25). docs.zeal.com/llms.txt, llms-full.txt (514 KB) and a Markdown copy of every page (10). 99 of 177 operations carry a description, 18 have no summary and 5 are titled "Copy of", and pages rarely say when not to use an endpoint (10 of 20). 359 `required` lists and 120 enums, with 212 of 228 parameters described, against 82 objects with no declared properties and string-typed dates (10 of 15). 2,088 examples in the spec and a table of 116 numbered error codes with HTTP statuses. 429 is not declared in the spec (13 of 15). The API has no version in the path or a header, the spec version is a fixed 1.0, and the changelog URL the site links to returns 404 (0). Total 68.
The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):
APIs and MCP servers.
- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.
Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.
## 6. Transparency & trust, 51 out of 100, up to 4.3 more on the total
Made of editorial 38, provenance 64.
Why it scored 51: Editorial half only. A closed service. The public terms are a website Terms of Use and Payroll Terms between Puzzl Group Inc. and a partner's client. The partner agreement is not public (12 of 30). The privacy notice, last updated 16 January 2026, keeps data as long as necessary with no periods, lists vendor categories only, and still gives a privacy@joinpuzzl address in one place. The Payroll Terms let Puzzl use aggregate or de-identified data for its own purposes. No DPA found (12 of 30). One dated deprecation, the `garnishment` deduction type with a sunset of 15 October 2026, and no written policy (8 of 20). AWS hosting and Bangor Savings Bank are named. No sub-processor list or data location statement found (6 of 20). Total 38.
The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):
- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).
The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.
Provenance checks not met in full (half of this category, computed from checked facts):
- Terms of service: read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points (5.1 of 10)
- Privacy policy: read, states 7 of the 8 things a reader expects (9.3 of 10)
- Status page: not found (0 of 10)
- Changelog: not found (0 of 10)
- security.txt: not found (0 of 10)
## 7. Maintenance & community, 61 out of 100, up to 3.4 more on the total
Why it scored 61: With the changelog returning 404, the newest dated public release is the Python SDK zeal-api-sdk 0.2.1 on 31 July 2026, 69 days before the check (20 of 30). npm shows @zeal-api/sdk 0.1.0, 0.2.0 and 0.2.1 on 28, 29 and 30 July 2026, three releases inside 90 days, all in one week (20). A closed service with a help centre and support@zeal.com, and no working public changelog or community channel (5 of 25). Official SDKs in two languages, both at 0.2.1 and not referenced by the docs (12 of 15). The SDK repositories hold tests and a Dependabot branch but no CI workflow, and the Python package declares no licence (4 of 10). Total 61.
The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):
- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.
Models are read for deprecation notice periods and model churn rather than release counts.
## What we couldn't check
What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.
- unchecked: whether status.zeal.com is a live status page. It did not complete a TLS handshake from our network, and no status link was found on the site
- unchecked: weekly downloads for zeal-api-sdk on PyPI. pypistats returned no data
- The tools, schemas and annotations behind the /mcp endpoint. The spec names four tools and says access needs an Agent-enabled key from Zeal
- Prices, any SLA and the partner agreement, none of which are public
- Whether the Partner Dashboard keeps an audit log of API calls
- The date of the last API change. The changelog URL returns 404 and the API root shows only a build hash
- Whether Zeal has a SOC 2 report or sub-processor list available under NDA
## Weaknesses
- No self-serve signup. Zeal's team creates the partner account after a demo request, and no price is published
- One test key and one production key per partner account, with no scopes and no read-only key
- No status page found, and the changelog linked from the home page and llms.txt returns 404
- The API has no version in the path or a header, and the main spec has 18 operations with no summary
- Webhooks carry the shared secret itself in `Puzzl-Signature`, not a signature of the payload
- No security.txt, disclosure policy, sub-processor list or DPA found on the public site
## What costs an agent a turn today
The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.
- Use the Test API key until a person has approved live payroll. Error code 0 (403) means the account has no production access
- Send `companyID` on almost every call and `partnerID` on partner-level calls, in the body for POST and PATCH and the query for GET
- Create cheques with `approval_required: true`, run POST /preview/checks, then PATCH /employeeCheck with `approved: true`. Without the flag Zeal processes pending cheques automatically
- Send `x-idempotency-key` on every create so a retry within 24 hours doesn't pay twice
- Previews and reports are jobs. Keep the `job_id` and poll GET /preview or GET /reports, or wait for the Job Queue webhook
- Check dates must be bank days and submitted before 2 PM Pacific two bank days ahead, or the call fails with code 89
## When it's done
Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.
What we couldn't check
- unchecked: whether status.zeal.com is a live status page. It did not complete a TLS handshake from our network, and no status link was found on the site
- unchecked: weekly downloads for zeal-api-sdk on PyPI. pypistats returned no data
- The tools, schemas and annotations behind the /mcp endpoint. The spec names four tools and says access needs an Agent-enabled key from Zeal
- Prices, any SLA and the partner agreement, none of which are public
- Whether the Partner Dashboard keeps an audit log of API calls
- The date of the last API change. The changelog URL returns 404 and the API root shows only a build hash
- Whether Zeal has a SOC 2 report or sub-processor list available under NDA
Sources 28
- API introduction, base URL, environments and error format docs.zeal.com · seen 2026-10-08
- Authentication, key rolling and webhook secret docs.zeal.com · seen 2026-10-08
- Rate limiting docs.zeal.com · seen 2026-10-08
- Idempotency docs.zeal.com · seen 2026-10-08
- Pagination docs.zeal.com · seen 2026-10-08
- Error codes docs.zeal.com · seen 2026-10-08
- Early Access endpoints docs.zeal.com · seen 2026-10-08
- Account setup and API keys docs.zeal.com · seen 2026-10-08
- Introduction to payroll runs docs.zeal.com · seen 2026-10-08
- Preview payroll guide docs.zeal.com · seen 2026-10-08
- FAQs (coverage, tax engine, year-end forms) docs.zeal.com · seen 2026-10-08
- Main OpenAPI spec, including /mcp and /agents/chat docs.zeal.com · seen 2026-10-08
- Docs index for agents docs.zeal.com · seen 2026-10-08
- Full docs text docs.zeal.com · seen 2026-10-08
- Changelog URL (404) docs.zeal.com · seen 2026-10-08
- Home page and navigation zeal.com · seen 2026-10-08
- Marketing llms.txt (RTF) zeal.com · seen 2026-10-08
- Legal page with privacy, security, terms and payroll terms zeal.com · seen 2026-10-08
- Pricing URL (404) zeal.com · seen 2026-10-08
- security.txt (404) zeal.com · seen 2026-10-08
- Help centre support.zeal.com · seen 2026-10-08
- API root and unauthenticated response api.zeal.com · seen 2026-10-08
- TypeScript SDK repository github.com · seen 2026-10-08
- Python SDK repository github.com · seen 2026-10-08
- npm registry entry registry.npmjs.org · seen 2026-10-08
- PyPI entry pypi.org · seen 2026-10-08
- Domain registration (RDAP) rdap.verisign.com · seen 2026-10-08
- Official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
Probe metrics
Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.
Pricing & changes
Paid Paid No public prices. www.zeal.com/pricing returns 404 and every call to action asks for a demo. A test environment that moves no money exists, but its key comes only after Zeal creates a partner account, so an agent cannot start without a sales contact. No free tier or self-serve trial was found (checked 2026-10-08).
Recent changes
- Latest release
Follow them as a feed at /feeds/tools/zeal.xml, or this listing's score history at history.json.
Connect
Install
npm i -s @zeal-api/sdk
First request
curl --request GET \
--url 'https://api.zeal.com/companies?partnerID=YOUR_PARTNER_ID' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer YOUR_API_KEY'
Through letme picks today, calling later
GET https://letme.dev/zeal
letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.
Compare with
Gusto BCheck BSalsa DDeel BBambooHR CRippling C
Head to head Check vs Zeal · Gusto vs Zeal · Salsa vs Zeal
Machine-readable
| Similar tool | Grade | Score | Shared capabilities | x402 |
|---|---|---|---|---|
| Gusto Gusto, Inc. | B | 63.3 | payroll.run payroll.employees payroll.embedded payroll.tax-filing payroll.contractors hr.onboarding | no |
| Check Check Technologies, Inc. | B | 67.5 | payroll.run payroll.employees payroll.embedded payroll.tax-filing payroll.contractors | no |
| Salsa Salsa Software Inc. | D | 46.1 | payroll.run payroll.embedded payroll.employees payroll.tax-filing payroll.contractors | no |
| Deel Deel, Inc. | B | 69.1 | hr.onboarding | no |
| BambooHR Bamboo HR LLC | C | 61.7 | hr.onboarding | no |
| Rippling People Center, Inc. dba Rippling | C | 60.8 | hr.onboarding | no |
Machine-readable
- JSON
/api/v1/tools/zeal.json· historyhistory.json· badge/badges/zeal.svg· changes feed/feeds/tools/zeal.xml - Markdown
/tools/zeal.md· slim/tools/zeal.min.md(or sendAccept: text/markdown) - Fix list
/fixes/zeal.md·/fixes/zeal.json - From a terminal
anchor tool zeal --md(the CLI) · over MCPget_tool {"slug": "zeal"}at/mcp, no key - Directory index
/api/v1/tools.json· site index/llms.txt
Verify this listing
For the vendorIs this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.
-
Add the badge or a link
On a light page On a dark page <a href="https://www.anchorterminal.com/tools/zeal"><img src="https://www.anchorterminal.com/badges/zeal.svg" alt="Zeal on Anchor Terminal" height="20"></a>[](https://www.anchorterminal.com/tools/zeal)<a href="https://www.anchorterminal.com/tools/zeal">Zeal on Anchor Terminal</a>It counts on a page on zeal.com or one of its subdomains, or the README of github.com/zeal-corp/typescript-sdk.
-
Tell us where it is
We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.
Agents send the same to POST /api/v1/verify as {"slug": "zeal", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check.
