canonical: https://jentic.com/apis/sage.hr/sage-hr

# Sage HR API

Sage HR (formerly CakeHR) API for managing employees, leave requests, timesheets, and HR data. The API exposes 7 endpoints secured with apiKey authentication.

## For AI agents

Programmatically list employees, get employee. Covers 7 operations with apiKey authentication.

## Scope

Does not handle payments, communications, or crm - use for hr and recruiting only.

## Capabilities

- List employees
- Get employee
- Integrate Sage HR API into automated workflows
- Query and filter Sage HR API records by parameters
- Monitor Sage HR API operational status and events

## Use cases

### HR and Recruiting Operations

Use the Sage HR API to perform hr recruiting operations programmatically. The API provides 7 endpoints covering core functionality including list employees, get employee, list leave requests.

Example prompt: Call GET /employees to list employees

### Automated Employees Management

Automate employees operations by combining multiple Sage HR API endpoints. Agents can get employee and then list leave requests in a single workflow.

Example prompt: Call GET `/employees/{id}` to get employee, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Sage HR API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle apiKey tokens manually.

Example prompt: Search Jentic for 'list employees', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| GET | `/employees` | List employees |
| GET | `/employees/{id}` | Get employee |
| GET | `/leave-requests` | List leave requests |
| GET | `/leave-requests/{id}` | Get leave request |
| GET | `/timesheets` | List timesheets |
| GET | `/teams` | List teams |
| GET | `/positions` | List positions |

## Key resources

- **Employees** — Operations related to Employees
- **Leave** — Operations related to Leave
- **Organization** — Operations related to Organization
- **Timesheets** — Operations related to Timesheets

## AI readiness

This API is usable in Jentic One now. Its AI-readiness score against Jentic's framework shows where it stands today and where improvements would make it even easier for agents to use.

- **Score:** 65 / 100
- **Maturity:** AI-Aware
- **Dimensions:**
  - Foundational Compliance: 87 / 100
  - Developer Experience & Jentic Compatibility: 63 / 100
  - AI-Readiness & Agent Experience: 47 / 100
  - Agent Usability: 94 / 100
  - Security: 50 / 100
  - AI Discoverability: 100 / 100
- **View full report:** https://jentic.com/apis/sage.hr/sage-hr/scorecard
- **How the score is calculated:** https://docs.jentic.com/reference/api-readiness-framework/overview/
- **More about the dimensions:** https://docs.jentic.com/reference/api-readiness-framework/specification/#dimensional-model-overview

### Score it yourself

Every API in the directory is allowlisted, so you can re-score it with no key required.

- **Score your own API:** https://jentic.com/scorecard.md
- **Scoring CLI agent skill:** https://github.com/jentic/jentic-api-scorecard/blob/main/skills/jentic-api-scorecard/SKILL.md

```sh
npx @jentic/api-scorecard-cli score <openapi-url>
```

## Why Jentic

- **Setup:** Wiring the Sage HR API by hand means managing its API key, attaching it to each call against api.sage.hr, and handling your own retries. Through Jentic you install once, import the Sage HR API from the API Directory, store the key once, and your agent calls it.
- **Permission scoping:** Sage HR puts the employee id in the URL path (`/employees/{id}`), so a rule can pin your agent to reading one employee. You choose the operations it may call, so it can read employees, leave requests, and timesheets without any write access unless you add it.
- **Credential handling:** Your Sage HR API key is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'list employees' or 'look up leave requests', and Jentic returns the matching Sage HR API operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Greenhouse** — Alternative hr recruiting API
- **Lever** — Alternative hr recruiting API
- **Workday** — Complementary hr recruiting API

## FAQ

### What authentication does the Sage HR API use?

The Sage HR API uses an API key passed in the `X-Auth-Token` header. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I list employees with the Sage HR API?

Yes. Use the GET /employees endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Sage HR API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I list employees through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'list employees'. Jentic returns the matching Sage HR API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Sage HR API have?

The Sage HR API exposes 7 endpoints covering employees, leave, organization operations.

### Can I limit what my agent is allowed to do with the Sage HR API?

Yes. Because you run Jentic One yourself, your own rules decide which Sage HR operations and credentials the agent may use. Since Sage HR carries the employee id in the URL path (`/employees/{id}`), you can pin the agent to reading a single employee, and you can grant only read calls such as GET /employees, GET /leave-requests, and GET /timesheets while withholding any write access. The agent can call nothing you have not explicitly allowed.
