A REST API, webhooks for every event, OAuth for secure access, and a sandbox to develop against. Build the integrations your business needs — to IT systems, payroll, BI tools, or anywhere else your data lives.
Employee data lives in HR, but IT, payroll, and finance need it too. You end up with three slightly-different copies and reconciliation pain.
Every payroll run starts with someone exporting a CSV and re-importing it elsewhere. Errors creep in. Hours wasted.
Need a custom integration to your IT-provisioning tool? Vendor quotes you £10k and three months. Painful.
Other systems can't subscribe to events. They poll the API every hour, miss changes in between, drift out of sync.
The API & Webhooks add-on opens HeimdallHR up to your wider stack: a clean REST API covers every resource, webhooks fire on every event, OAuth handles auth properly, and a sandbox environment lets your engineering team build and test without touching production. Comprehensive docs and SDKs (Node, Python, .NET) shorten time-to-integration.
Resource-oriented, predictable URLs, JSON in/out. Covers employees, leave, performance, comp, expenses, recruitment — everything.
Subscribe to events like hire, leave approval, role change, leaver. We POST to your URL with the payload. Retry on failure.
Standards-based auth. Per-app credentials, scoped permissions, refresh tokens. No password-in-config nonsense.
Generous defaults, clearly documented. Bursts allowed. Rate-limit headers on every response so clients can back off cleanly.
A fully-featured sandbox with seeded test data. Develop and test without touching production employees.
Reference docs, quick-starts, recipes, OpenAPI spec. SDKs in Node, Python, and .NET. Try-it-out console in the docs.
Create an OAuth app from your admin panel. Sandbox + production keys.
Use the API / SDK to read & write HR data. Subscribe webhooks to events.
Develop against the sandbox with seeded data. No risk to production.
Same code, production credentials, real data. Monitor via the audit log.
HR data flows automatically to where it's needed. No more reconciliation pain.
Your team builds integrations in days, not months. No vendor lock-in.
Webhooks push changes immediately. Other systems stay in sync without polling.
OAuth + scoped permissions + audit logs. Compliant with your security team's expectations.
HeimdallHR is most powerful when used together.
Default 100 requests/min sustained with bursts up to 500. Webhook deliveries don't count against your rate limit. Higher limits available on request — talk to us.
Yes. Exponential backoff over 24 hours. After final failure, the event lands in a dead-letter queue you can replay from the admin panel.
Yes. OAuth scopes let you create read-only tokens, employee-only tokens, etc. Principle-of-least-privilege by design.
We follow semver. Breaking changes only in major versions with 12-month deprecation notice. Backwards-compatible additions can land any time and are documented in the changelog.
See the API and webhooks in action in a personalised demo, or talk to our team about connecting HeimdallHR to your stack.
No commitment — we’ll get back to you within one business day.