Partner OAuth integrations only
The Assessments API is for approved HiBob Marketplace partners with Developer Portal access and OAuth credentials. Service users are not supported for this integration.
Bob customers building integrations for their own company should use Service users and the general Hiring API, not this partner contract.
The Assessments API is the partner-facing Public API for marketplace assessment providers. Use it to register your package catalog, fetch assessment context after a webhook, and report status and results back to Bob Hiring.
Before you begin
- Read Integrate with Bob Hiring Assessments API to learn how the integration works end to end.
- Confirm you are an approved Marketplace partner with Developer Portal access and an OAuth app configured for assessments.
Assessments API endpoints
| Resource | Endpoint |
|---|---|
| Packages | Register assessment packages |
| Packages | Delete assessment packages |
| Assessment details | Get assessment details |
| Assessment status | Update assessment status |
Assessments API webhooks
Bob delivers outbound events to your registered HTTPS webhook URL. Requests are signed — verify authenticity using the Bob-Signature header. Delivery is at-least-once; handle duplicates idempotently with assessmentRequestId.
| Event | Webhook |
|---|---|
| Assessment ordered | Assessment triggered |
| Assessment cancelled | Assessment cancelled |
To learn more about partner webhook delivery and retries, see Getting started with partner webhooks.
Required permissions and scopes
This API supports OAuth only. Service users are not supported.
To use the Assessments API, your OAuth app requires the following scope:
| Name | Scope | Description |
|---|---|---|
| Integrations > Manage hiring integrations | hiring.integrations:write | Register packages, fetch assessment details, and report status or results |
If the calling app does not have the required scope, the API returns an authorization error (for example, 403 Forbidden).
Rate limiting
Rate limits are restrictions that our API imposes on the number of times a user can access our endpoints within a specified period of time. To learn more about rate limiting best practices, see Rate limiting.

