Partner OAuth integrations only
The Applicant API is for approved HiBob Marketplace partners with Developer Portal access and OAuth credentials. Service users are not supported for this integration.
Bob customers building integrations for their own company should continue to use the legacy Hire API with Service users, not this partner contract.
The Applicant API is the partner-facing Public API for Marketplace ATS, EOR, and onboarding providers. Use it to push a hired candidate into Bob’s ATS Pending Hires flow. An employee is created only after HR runs the New Hire flow.
Before you begin
- Read Submit new hires to Bob with the Applicant API to learn how the integration works end to end.
- Confirm you are an approved Marketplace partner with Developer Portal access and an OAuth app configured for applicant submission.
Applicant API endpoints
| Resource | Endpoint |
|---|---|
| Applicants | Create an applicant |
Supporting endpoints
Use these during one-time setup (field mapping and document folder selection). They are not part of the Applicant API itself.
| Resource | Endpoint |
|---|---|
| Field metadata | Get all employee fields |
| Document folders | Get list of folders with metadata |
Required permissions and scopes
This API supports OAuth only. Service users are not supported.
To submit applicants, your OAuth app requires the following scope:
| Name | Scope | Description |
|---|---|---|
| Applicants write | applicants:write | Submit a hired candidate to ATS Pending Hires |
For a complete setup experience, also request:
| Name | Scope | Description |
|---|---|---|
| Company metadata read | company.metadata:read | Read employee field metadata to power your mapping UI |
| Documents read | documents:read | Read document folders so the customer can choose a destination folder |
If the calling app does not have the required scope, the API returns an authorization error (for example, 403 Forbidden).
Rate limiting
Rate limits are restrictions that our API imposes on the number of times a user can access our endpoints within a specified period of time. To learn more about rate limiting best practices, see Rate limiting.
Rate limit: 10 requests per minute per authenticated company

