HiBob HR platform People & leave REST API & webhooks

Custom Bob HR integration development

Appfront builds custom integrations with Bob, the HR platform from HiBob. Using the official REST API and webhooks, we synchronise employees, leave, compensation and documents between Bob and your payroll, identity provider, scheduling software or in-house application. Your HR team keeps Bob as the source of truth, while data flows automatically and securely to the right systems, with no double entry.

What is a Bob HR integration?

Bob is HiBob's HR platform: a HRIS aimed at mid-market and fast-growing tech and scale-up organisations. The platform brings people management, leave, compensation, onboarding and documents together in one system, often for international teams. In practice, the names Bob and HiBob are used interchangeably: HiBob is the company, Bob is the product.

In practice, a custom integration means reading employee data from Bob and passing it on to payroll or an identity provider, sending leave and absence data to scheduling software, making compensation and payroll fields available to finance, automating documents and onboarding steps, and reacting in real time via webhooks to events such as a new employee or an approved leave request. Authentication runs through a Service User with scoped permissions.

Appfront builds in line with the official HiBob Bob API documentation and the OWASP ASVS security standard. We align the fields to be integrated, the synchronisation logic and the error handling with your actual HR processes, so the integration grows with your organisation and keeps running reliably, even as teams expand or go international.

Bob as the single source of truth

Your HR team manages employees, leave and compensation in one place, in Bob. The integration ensures connected systems pick up that data, so you never enter anything twice and your people data stays consistent everywhere.

Real-time events via webhooks

Bob sends events such as a new employee or an approved leave request straight to your systems. Onboarding and provisioning therefore run automatically, with no periodic manual checks or delays.

Secure with a Service User

The integration authenticates through a Service User with exactly the permissions it needs. It isn't tied to an individual, so it won't break if someone leaves the organisation, and the data flow is limited to what is genuinely necessary.

Our development process for Bob HR integrations

We work to a proven methodology that removes uncertainty early and delivers a stable integration. From an initial analysis of your HR processes, the Bob fields required and the connected systems, through to go-live and ongoing management, every step is aimed at an integration your team can understand and trust.

1
Analysis & scope

We map out which employee, leave, payroll and document fields you want to integrate, which systems Bob needs to talk to, and which events need to come through in real time via webhooks.

2
Architecture

We design the integration architecture, set up a Service User with least-privilege permissions, and define an error handling and retry strategy.

3
Development

Implementation with automated tests, structured logging and monitoring. You see working builds along the way.

4
Go-live & management

Controlled go-live with data validation and a safety net, followed by ongoing management and further development.

What a Bob HR integration delivers in practice

Every Bob HR integration is set up specifically for your HR processes, the fields to be synchronised and the connected systems. Below are the capabilities we most often deliver for organisations that use Bob as their central HR platform.

REST API & Service User token

The integration talks to the Bob REST API via a Service User that authenticates with a token using basic authentication. We scope permissions so that each integration can only access the fields and endpoints it genuinely needs.

Employees & people sync

We synchronise employee profiles from Bob to payroll, identity providers or in-house systems, including standard and custom fields. New and changed employees flow through automatically, so the same people data is held everywhere.

Leave & absence

Retrieve leave requests, balances and absences from the Time Off API and pass them on to planning, payroll or a shared calendar. This way teams can see straight away who is away, and leave administration stays in sync everywhere.

+

Payroll & compensation

Make compensation and payroll data such as salary history and bank details available to your payroll or finance system. Changes made in Bob flow through in a controlled way, with tight permissions because the data is sensitive.

Webhooks & events

Subscribe to Bob events such as a new employee, or a leave request being submitted, approved or cancelled. Bob calls your listener with a payload, so connected systems update directly and automatically.

Documents & onboarding

Connect documents and onboarding information from Bob to your DMS or accounts. As soon as a new employee appears in Bob, accounts, documents and access can be set up automatically for a smooth first day.

Typical use cases in practice

A Bob HR integration varies a great deal from one organisation to the next. We regularly see a number of recurring patterns, and for each of them we have a working setup with careful attention to the right fields, permissions and real-time events.

CRM

Tech and scale-up organisations

Fast-growing tech and scale-up companies that use Bob as their HRIS and want to automate their stack. Synchronise employees with an identity provider, provision accounts when someone joins and deactivate them when they leave. See also our API integrations.

Mid-market organisations

Organisations with several hundred employees that use Bob as their central HR platform and want to connect it to payroll and finance. Employee and compensation data flows in a controlled way to payroll administration, with a documented and auditable data flow. Discover our middleware.

International teams

Companies with employees in several countries that manage leave, absence and local arrangements centrally in Bob. Leave data flows to planning and payroll per region, so teams across time zones can see who is available and administration is accurate everywhere.

Professional services

Consultancies, IT service providers and agencies that connect staff data from Bob to resource and project planning. Availability and leave flow into planning, so consultants are scheduled based on up-to-date HR data from Bob.

Technology we use

We build Bob HR integrations using HiBob's official REST API and webhooks, combined with the backend stack that suits you. The exact choice depends on the systems Bob needs to talk to, so your own team can manage or further develop the integration.

Bob REST API Bob webhooks Service User & token (basic auth) People & employee fields API Time off API Payroll & compensation data Documents API Node.js / Python / PHP / .NET / Ruby / Go Identity providers (SSO / SCIM) Payroll integrations Planning & resource management Middleware & message queues Secrets management & vaults Webhook signature validation Retry & dead-letter queues GitHub Actions

Why choose Appfront for your Bob HR integration?

Appfront has extensive experience building API integrations for a wide range of organisations in the Netherlands. We always start with a thorough analysis of your existing systems and processes. An integration should not only work technically, but also add practical value to the way you work.

For every integration, we write clear documentation and make sure your own team, or any future supplier, can understand and manage it. No black box, just transparent code and clear agreements on monitoring, alerting and maintenance.

You work with a dedicated point of contact who understands both the technical and the functional side. This keeps communication short, prevents misunderstandings and speeds up decisions when choices need to be made during development.

See also our broader services around API integrations, middleware, custom software and web app development, or browse all the integrations we build.

  • Experience with the Bob REST API, people, time off and payroll endpoints
  • Secure by default: Service User with scoped permissions, token rotation and webhook validation
  • Experienced with integrations to payroll, identity providers and planning software
  • Clear documentation that your HR and IT team can read and manage themselves

Security and privacy in Bob HR integrations

A Bob HR integration inherently processes personal data, and often sensitive personal information such as salary, bank details and leave. Appfront builds in line with the OWASP ASVS. That means, among other things: storing the Service User token in secure vaults, validating webhook signatures, scoping permissions on a least-privilege basis, and regularly auditing the data flows between Bob and your systems.

Because this involves HR and personal data, we limit the data flow to the fields the integration genuinely needs and grant the Service User only the permissions that go with them. We document every data flow between Bob and your systems so your record of processing activities is complete and you can demonstrate compliance with the GDPR. We clearly establish in advance which party acts as processor or controller.

More on our security approach: information security policy and CVD policy.

  • GDPR-compliant data processing and data minimisation
  • Encryption in transit (TLS 1.2+) and at rest
  • Role-based access and least-privilege principles
  • Audit logs with traceable data flows
  • Token rotation and webhook signature validation
  • Monitoring and alerting for anomalies
  • Secrets management in line with best practice
  • Documentation for your record of processing activities

Frequently asked questions about Bob HR integrations

Answers to the questions we are asked most often about Bob HR integrations.

A Bob HR integration is a technical link between Bob, the HR platform from HiBob, and another system, such as your payroll tool, identity provider, planning software or your own application. Bob's REST API is used to read and update employee data, leave, compensation and documents programmatically. Webhooks push real-time events, such as a new employee or an approved leave request. An integration can range from simple (synchronising employees in one direction) to extensive (leave, payroll, onboarding and events combined in a continuous flow).

HiBob is the vendor; Bob is the name of the HR platform they build. Colloquially the two are often used interchangeably. Bob is a HRIS aimed at mid-market and tech/scale-up organisations, with modules for people management, time off, compensation, onboarding and documents. When we speak of a Bob HR integration, we mean an integration with this HiBob platform via the official public API.

Access to the Bob API runs through a Service User: a dedicated account that is not linked to a real employee and only authenticates API requests. You create a service user with an ID and token and assign it exactly the permissions the integration requires. Authentication uses basic access authentication with that ID and token. Because a service user stays active regardless of the status of the person who created it, an integration won't break when an employee leaves. We set permissions as narrowly as possible, following least privilege.

Via the Bob API you can, among other things, read or update employee data (people), time off and absence, compensation and payroll data, documents and onboarding information. Which fields are available depends on the permissions you assign to the service user; the data the API returns reflects what is visible in the Bob interface under comparable rights. Together we decide which fields the integration needs, and we deliberately keep the data flow to a minimum.

A simple integration, for example syncing employees one way to another system, can go live within a few weeks. More extensive scenarios involving time off, payroll, documents, onboarding flows and real-time webhook events usually take longer. After an intake meeting in which we map out the data flows and systems, we give you a realistic estimate.

Yes. Employee data is personal data by definition and often sensitive personal information such as salary and leave. Appfront builds to the OWASP ASVS: service user tokens are stored in secure vaults, webhooks are validated, permissions are scoped, and each integration follows least privilege. We limit the data flow to the fields the integration genuinely needs and document every flow so that your record of processing activities stays complete and you can demonstrably comply with the GDPR. We clarify upfront which party acts as processor or controller.

Yes. Appfront regularly takes over existing integrations, even when they were originally set up by another party. We review the service user permissions, the endpoints in use, the webhook configuration and the error handling, document the current setup and propose improvements. From there we can handle adjustments, extensions and monitoring, including timely token rotation.

Bob is a good fit for mid-market and fast-growing tech and scale-up organisations, often with international teams and a modern approach to HR. Typical use cases for an integration include syncing employees with an identity provider or payroll tool, sending time-off data to planning software, making compensation data available to finance, and automating onboarding by setting up documents and accounts as soon as a new employee appears in Bob.

Ready to build your Bob HR integration?

Tell us which data you want to pull from Bob and which systems it needs to connect with, whether payroll, identity, planning or your own application. We're happy to think along with you about the Service User, the required fields and the webhook events. A no-obligation first conversation via contact will quickly give you a clear picture of what's possible.

Edit content