MCP Server
BambooHR's AI connectors are currently in a closed beta. Interested in joining? Request access.
The BambooHR MCP server lets you connect any Model Context Protocol-compatible AI tool or agent to your BambooHR account. It's the foundation that powers the BambooHR Claude connector and ChatGPT app, and it's also available directly for developers building custom integrations or connecting MCP clients we don't yet support out of the box.
What it does
The MCP server exposes 44 tools across five core areas of BambooHR: employee data and files, time off and availability, reporting and datasets, hiring and applicant tracking, and goals and performance. We picked this starting set by looking at the most common jobs HR teams want help with. We'll add more tools over time as we learn what customers ask for most.
Once connected, an AI assistant can:
- Answer questions about employees, time off, goals, and hiring using natural language
- Pull data from BambooHR datasets and saved reports
- Take actions on your behalf (create time off requests, update employee fields, manage goals) when you have the right permissions
- Combine BambooHR data with other tools the same AI client is connected to
Sample prompts
Here are a few ways you can put the server to work. This isn't an exhaustive list, just a starting point:
- "Who's out of office this week?"
- "What's Alice's remaining PTO balance?"
- "Pull last month's headcount report and summarize it"
- "Show me all open requisitions in the Engineering department"
- "How many candidates are in interview stage right now?"
- "Create a time off request for me from June 10 to June 14"
- "List goals owned by the marketing team and which ones are overdue"
- "Update the work phone number on file for [employee name]"
Server endpoint
https://{your-company}.bamboohr.com/api/mcpReplace {your-company} with your BambooHR subdomain. Each customer has their own MCP endpoint scoped to their account.
Authentication
The MCP server supports two authentication methods.
OAuth (recommended)
OAuth is the right choice for most use cases. The BambooHR Claude connector and ChatGPT app both use OAuth behind the scenes. You click Connect, sign in to BambooHR, and token management happens automatically.
If you're connecting from a different MCP client today, you'll need to configure the OAuth flow manually. We're working on Dynamic Client Registration (DCR) support so other MCP clients can self-discover and connect without setup. We'll update this page when it's ready.
Bearer token
You can also generate a token manually and pass it as a bearer token. This is useful for testing or scripted access, but keep in mind:
- Tokens currently have a 1-hour lifetime and need to be refreshed manually
- Tokens carry the permissions of the user who created them
For long-running or production use, OAuth is the better path.
Prerequisites
Before connecting, make sure you have:
- An active BambooHR account
- Permission to access the data you want the AI tool to see (the server enforces BambooHR's existing permissions, so it can't grant access you don't already have)
- An MCP-compatible client (Claude, Cursor, your own agent, etc.) or the ability to make OAuth-authenticated HTTPS requests
Access model
The MCP server respects BambooHR's permissions exactly. What you can do through an AI assistant matches what you can do when logged into BambooHR directly.
- HR admins get full company-wide access. This is the most powerful experience and what we've optimized for first.
- Managers can see and act on data for themselves and their direct reports.
- Individual contributors can see and act on their own information.
Future updates may expand non-admin access to include basic info about other employees (the same kind of directory info you'd see logged into BambooHR), but for now the IC and manager experience is intentionally scoped.
Guidelines for safe use
A few practices we strongly recommend any time you're connecting BambooHR data to an AI assistant:
- Use trusted, well-established MCP clients. Stick to clients you know and trust (Claude, ChatGPT, Cursor, etc.). Unverified clients can expose your data in ways you don't intend.
- Keep your session focused. If you mix the BambooHR MCP server with several other connected servers in the same session, data can move between them in ways that are hard to predict. For sensitive HR work, keep the session scoped to BambooHR.
- Require confirmation before tool calls run. Most MCP clients let you approve each tool call before it executes. Leave that turned on, especially for any write action (creating time off requests, updating employee data, modifying goals).
- Verify AI output before acting on it. Treat the assistant's responses as a starting point, not a source of truth. Double-check numbers, names, and policy interpretations before making decisions.
- Opt out of model training in your AI client. Most providers offer a setting to exclude your conversations from training data. Turn it on. HR data is sensitive and shouldn't be used to train third-party models.
- Protect bearer tokens. If you're using a manually generated token, treat it like a password. Don't paste it into untrusted tools or commit it to source control.
Available tools
The server organizes tools into five domains. We'll continue adding tools based on customer feedback. If you'd like to see something that isn't here yet, let us know.
Employee data and files
The foundation. Look up employee details, access tabular records like job history or compensation, and see what files are attached to employees or stored at the company level.
| Tool | Description |
|---|---|
get-employee | Get a single employee by ID |
list-employees | List employees in the company |
update-employee | Update fields on an employee record (write) |
get-employee-table-data | Get tabular data (job, compensation, etc.) for an employee |
list-employee-files | List files attached to an employee |
list-company-files | List company files and their categories |
list-fields | List the fields available on the employee record |
Time off and availability
One of the highest-traffic areas in BambooHR. Check who's out, view balances, submit PTO requests, and approve or deny requests as a manager.
| Tool | Description |
|---|---|
list-whos-out | List who's out of office |
list-time-off-requests | List time off requests |
get-time-off-balance | Get an employee's time off balance |
list-time-off-types | List available time off types |
list-time-off-policies | List time off policies |
list-employee-time-off-policies-v1.1 | List policies assigned to an employee |
create-time-off-request | Create a new time off request (write) |
update-time-off-request-status | Approve or deny a time off request (write) |
Reporting and datasets
Where LLM connectors really shine. Build ad-hoc queries using the Datasets API or pull saved reports built in the BambooHR UI.
| Tool | Description |
|---|---|
list-datasets-v1-2 | List available datasets |
get-fields-from-dataset-v1-2 | Get the fields available in a dataset |
get-field-options-v1-2 | Get the options available for a field |
get-data-from-dataset-v2 | Run a query against a dataset |
list-reports | List saved reports |
get-report-by-id | Get the results of a saved report |
list-tabular-fields | List fields available in tabular records |
list-list-fields | List fields configured as list types |
Hiring and applicant tracking
A natural fit for conversational queries. Hiring managers can check pipeline status, review candidates, and add feedback without switching tools.
| Tool | Description |
|---|---|
get-job-summaries | Get summaries of open jobs |
get-applications | Get job applications |
get-application-details | Get details for a specific application |
get-statuses | Get applicant statuses available in the pipeline |
create-application-comment | Add a comment to an application (write) |
Goals and performance
Full lifecycle management for goals. Create, update, close, and reopen goals, track progress at the goal and milestone level, manage comments, and filter or align goals across the organization.
| Tool | Description |
|---|---|
list-goals | List goals |
get-goals-aggregate-v1.2 | Get aggregate goal data across the company |
get-goal-aggregate | Get aggregate data for a single goal |
get-goals-filters-v1.2 | Get available goal filters |
get-alignable-goal-options | List goals available for alignment |
list-goal-comments | List comments on a goal |
create-goal | Create a new goal (write) |
update-goal-v1.1 | Update an existing goal (write) |
update-goal-progress | Update progress on a goal (write) |
update-goal-milestone-progress | Update progress on a goal milestone (write) |
create-goal-comment | Add a comment to a goal (write) |
update-goal-comment | Update a goal comment (write) |
delete-goal-comment | Delete a goal comment (write) |
close-goal | Close a goal (write) |
reopen-goal | Reopen a previously closed goal (write) |
delete-goal | Delete a goal (write) |
How it works
When an MCP client calls one of the server's tools, here's what happens:
- The client sends an MCP tool call to
https://{your-company}.bamboohr.com/api/mcpwith an OAuth access token or bearer token - The server authenticates the request and identifies the user
- It validates the request and checks that the user has permission to perform the action
- It calls the appropriate BambooHR API endpoint(s) on the user's behalf
- It returns the result back to the client in MCP format
The server is hosted by BambooHR. There's nothing to install or run locally.
Limitations
- The server exposes about 40 endpoints today. Not every BambooHR API capability is available yet.
- Bearer tokens require manual refresh every hour.
- DCR isn't yet supported for self-discovery from arbitrary MCP clients. OAuth setup may require manual configuration in clients that don't ship with a pre-built BambooHR connector.
- The MCP server can read and write within the scope of the connected user's permissions, but some sensitive actions (like changes that require approvals or workflows inside BambooHR) still go through BambooHR's existing flows.
What's next
We're actively expanding the server. Upcoming work includes:
- More tools across additional BambooHR areas
- DCR support for easier setup from any MCP client
- Longer token lifetimes and refresh handling improvements
If you have feedback or run into something that doesn't work the way you expect, reach out to your BambooHR contact or open a support request.
Disclaimer
The BambooHR MCP server connects you to third-party AI tools, which can produce inaccurate or incomplete responses. BambooHR isn't responsible for errors in AI-generated output or for actions taken in your account based on those responses. Always verify information and review actions before confirming them.