{
 "categories": [
  "hr",
  "hcm"
 ],
 "deployment": "saas",
 "evidence": [
  {
   "date": "2026-09-10",
   "fact": "homepage",
   "note": "HiBob presents Bob as all-in-one HR software for people, payroll, and finance, including core HR, workflows, time and attendance, UK and US payroll, and people analytics.",
   "source": "https://www.hibob.com/",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "vendor",
   "note": "The public homepage identifies the vendor and product as HiBob / Bob.",
   "source": "https://www.hibob.com/",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "deployment",
   "note": "HiBob is sold as a hosted people platform with public marketing pages and demo booking. The page does not present a self-host edition.",
   "source": "https://www.hibob.com/",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "license",
   "note": "The homepage offers a demo and sales path. No public free-tier product is published on that page.",
   "source": "https://www.hibob.com/",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "modalities.api.exists",
   "note": "HiBob documents Bob's API as a REST API for customer integrations and Marketplace partner apps.",
   "source": "https://apidocs.hibob.com/docs/getting-started.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "modalities.api.kinds[0]",
   "note": "The People Search reference publishes production host https://api.hibob.com/v1 and sandbox https://api.sandbox.hibob.com/v1.",
   "source": "https://apidocs.hibob.com/reference/post_people-search",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "modalities.api.auth[0]",
   "note": "Customer-built integrations must use basic access authentication. The header is authorization: Basic plus Base64(SERVICE-USER-ID:TOKEN).",
   "source": "https://apidocs.hibob.com/reference/authorization",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "modalities.api.auth[1]",
   "note": "Approved Marketplace partners use OAuth 2.0 authorization code. Tokens are exchanged at https://auth.app.hibob.com/oauth2/v1/apps/token. Access tokens expire in five minutes.",
   "source": "https://apidocs.hibob.com/reference/oauth-20",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "modalities.api.coverage",
   "note": "The developer index lists Employee data, Time Off, Attendance, Tasks, Reports, Docs, Goals, Skills, Job Catalog, Employer, Workforce Planning, Hiring, and Learning APIs. Field access follows service-user permission groups.",
   "source": "https://apidocs.hibob.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "modalities.api.docs",
   "note": "This page is HiBob's current getting-started guide for Bob customers creating a service user and for vendors joining the partner program.",
   "source": "https://apidocs.hibob.com/docs/getting-started.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "modalities.integrations.zapier",
   "note": "Zapier lists a Hibob app with employee activated, created, deleted, inactivated, joined, left, temporary-leave, and updated triggers.",
   "source": "https://zapier.com/apps/hibob/integrations",
   "tier": "scraped"
  },
  {
   "date": "2026-09-10",
   "fact": "modalities.extensibility.webhooks",
   "note": "Bob webhooks v2 POST JSON events for employee, time off, task, docs, and workforce-planning changes, signed with HMAC SHA512 in the Bob-Signature header, with retries for up to three days.",
   "source": "https://apidocs.hibob.com/reference/getting-started-webhooks.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "modalities.data_access.export[0]",
   "note": "People Search returns matching employees in one JSON employees array.",
   "source": "https://apidocs.hibob.com/reference/post_people-search",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "modalities.data_access.import[0]",
   "note": "The getting-started guide and API reference describe REST write endpoints for customer integrations; payloads are JSON.",
   "source": "https://apidocs.hibob.com/docs/getting-started.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "modalities.agent_docs.llms_txt",
   "note": "https://apidocs.hibob.com/llms.txt is a first-party documentation index. HiBob's docs tell agents to fetch it before exploring further.",
   "source": "https://apidocs.hibob.com/llms.txt",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "verdict.scores.api",
   "note": "The public REST API is documented across people, time off, attendance, and related modules with service-user Basic auth. Permission groups, People Search limits, and partner-only OAuth keep coverage broad but not complete.",
   "source": "https://apidocs.hibob.com/docs/api-service-users",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "verdict.scores.integrations",
   "note": "The opened Zapier listing documents employee lifecycle triggers. Write actions were not listed on that page, and other iPaaS catalogs were not opened.",
   "source": "https://zapier.com/apps/hibob/integrations",
   "tier": "scraped"
  },
  {
   "date": "2026-09-10",
   "fact": "freshness.watch[0].url",
   "note": "Opened and verified as HiBob's current getting-started guide for Bob's API.",
   "source": "https://apidocs.hibob.com/docs/getting-started.md",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "freshness.watch[1].url",
   "note": "Opened and verified as the current API service-user guide, including permission groups and token handling.",
   "source": "https://apidocs.hibob.com/docs/api-service-users",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "freshness.watch[2].url",
   "note": "Opened and verified as the current Basic-auth header guide for service users.",
   "source": "https://apidocs.hibob.com/reference/authorization",
   "tier": "declared"
  },
  {
   "date": "2026-09-10",
   "fact": "freshness.watch[3].url",
   "note": "Opened and verified as HiBob's current first-party llms.txt documentation index.",
   "source": "https://apidocs.hibob.com/llms.txt",
   "tier": "declared"
  }
 ],
 "freshness": {
  "last_verified": "2026-09-10",
  "volatility": "medium",
  "watch": [
   {
    "type": "docs",
    "url": "https://apidocs.hibob.com/docs/getting-started.md"
   },
   {
    "type": "docs",
    "url": "https://apidocs.hibob.com/docs/api-service-users"
   },
   {
    "type": "docs",
    "url": "https://apidocs.hibob.com/reference/authorization"
   },
   {
    "type": "docs",
    "url": "https://apidocs.hibob.com/llms.txt"
   }
  ]
 },
 "homepage": "https://www.hibob.com/",
 "id": "hibob",
 "license": "commercial",
 "modalities": {
  "agent_docs": {
   "llms_txt": true
  },
  "api": {
   "auth": [
    "service-user",
    "oauth2"
   ],
   "coverage": "partial",
   "docs": "https://apidocs.hibob.com/docs/getting-started.md",
   "exists": true,
   "kinds": [
    "rest"
   ]
  },
  "cli": {
   "exists": "unknown"
  },
  "computer_use": {
   "issues": [],
   "viability": "unknown"
  },
  "data_access": {
   "export": [
    "json"
   ],
   "import": [
    "json"
   ]
  },
  "extensibility": {
   "scripting": [],
   "webhooks": true
  },
  "integrations": {
   "make": "unknown",
   "n8n": "unknown",
   "power_automate": "unknown",
   "zapier": true
  },
  "mcp": {
   "first_party": "unknown",
   "third_party": [],
   "verdict": "unknown"
  },
  "rpa": {
   "drivability": "unknown",
   "notes": "No repeatable UI probe was run. Bob's public REST API, webhooks, and service-user or partner OAuth authentication cover HR automation without browser control.\n",
   "ui_stack": [
    "web-dom"
   ],
   "vendor_support": []
  },
  "sdk": {
   "exists": "unknown",
   "languages": [],
   "official": "unknown"
  }
 },
 "name": "HiBob",
 "platforms": [
  "web"
 ],
 "related": {
  "alternatives": [
   "bamboohr",
   "personio",
   "4human-hrm",
   "workday"
  ],
  "our_products": []
 },
 "schema_version": 1,
 "score_version": 1,
 "status": "active",
 "vendor": "HiBob",
 "verdict": {
  "best_path": "api",
  "scores": {
   "api": 8,
   "cli": null,
   "computer_use": null,
   "integrations": 5,
   "mcp": null,
   "overall": 8,
   "rpa": null
  },
  "summary": "HiBob (Bob) is automatable today through a public REST API. This record is HiBob, not BambooHR, Personio, 4human HRM, or Workday. Customer-built integrations authenticate as API service users with HTTP Basic: Base64-encoded service-user ID and token in the Authorization header. Service users cannot log in to Bob; access is set by permission groups on features, people's fields, and whose data they may see. Approved Marketplace partners use OAuth 2.0 authorization code instead, exchanging codes at https://auth.app.hibob.com/oauth2/v1/apps/token. Access tokens expire in five minutes and are refreshed. The People Search API and related employee, time-off, attendance, tasks, reports, docs, goals, skills, job-catalog, employer, workforce-planning, hiring, and learning resources live under https://api.hibob.com/v1. Coverage is partial because field access is permission-gated, People Search has no pagination and documents large-company batching limits, and OAuth is partner-only. Webhooks v2 POST JSON events for employee, time off, task, docs, and workforce-planning changes, signed with HMAC SHA512. Zapier lists a Hibob app with employee lifecycle triggers. First-party MCP ownership is not established. Computer-use viability is unassessed. API scores 8 and is the best path. The opened Zapier listing is trigger-heavy, so integrations scores 5.\n"
 }
}