CozyHR
Menu
Products
Docs
Resources
Compliance
Company
Support
Developer docsREST API

CozyHR API Authentication

How to authenticate CozyHR REST API calls using API keys, OAuth client credentials, scopes and rate limits.

Last updated: · CozyHR editorial team

Developer documentation
REST
API style
Bearer
auth model
JSON
payloads
API key creation
OAuth client credentials
Scoped access control
API quickstart

Start with a scoped Bearer token

CozyHR public APIs are tenant-scoped. Create a key in the developer console, pass it as a Bearer token and keep secrets out of browser code.

GETRead employees
curl -H "Authorization: Bearer ch_live_..." \
  "https://cozyhr.com/api/public/v1/employees?status=ACTIVE&limit=50"

Sync employee codes, names, emails, departments and locations into internal systems.

POSTIngest attendance punches
curl -H "Authorization: Bearer ch_live_..." \
  -H "Content-Type: application/json" \
  -d '{"employeeCode":"CH-001","punchType":"IN"}' \
  "https://cozyhr.com/api/public/v1/attendance/punches"

Send biometric or middleware IN/OUT punches while keeping raw logs available for recalculation.

POSTIssue OAuth token
curl -H "Authorization: Bearer ch_live_..." \
  -H "Content-Type: application/json" \
  -d '{"employeeCode":"CH-001","punchType":"IN"}' \
  "https://cozyhr.com/api/oauth/token"

Use client credentials when a backend integration needs scoped, revocable API access.

SEO answer block

What this CozyHR page covers

CozyHR API Authentication is a CozyHR.com resource for teams evaluating developer documentation in a modern HRMS. How to authenticate CozyHR REST API calls using API keys, OAuth client credentials, scopes and rate limits. It covers api key creation, oauth client credentials, scoped access control and explains how CozyHR connects api keys and oauth client credentials with employee records, attendance, payroll, compliance workflows and Super Admin controls. The page is written for HR admins, payroll managers, founders and operations teams who need practical software context rather than a thin brochure page.

API key creation
OAuth client credentials
Scoped access control
Developer docs

API keys

Tenant admins create hash-backed API keys with scopes, expiry and per-minute limits. Secrets are shown once for secure storage.

One-time reveal
Scope selection
Rotation workflow
Developer docs

OAuth client credentials

Use OAuth apps when backend systems need client ID and client secret based token issuance with revocation and audit history.

Client ID
Client secret
Access token
Implementation workflow

How teams implement this in CozyHR

A good HRMS page should explain the operational path, not only list features. The steps below show how this workflow moves from evaluation to daily use inside CozyHR.

1

Map the current process

Document how API Authentication works today across HR, finance, managers and employees.

2

Configure CozyHR

Create the required company setup, employee fields, policies, approval paths and role access in CozyHR.

3

Import and validate data

Load employee records, device mappings, salary values, statutory IDs, documents and historical context.

4

Operate with audit trails

Run day-to-day workflows with database-backed records, review states, reports and Super Admin visibility.

Frequently asked questions

Questions HR teams ask before buying

These answers are written as plain, crawlable content for buyers and AI search systems. They keep the page useful even before someone opens the product.

What is CozyHR API Authentication?

CozyHR API Authentication is a CozyHR.com resource for teams evaluating developer documentation in a modern HRMS. How to authenticate CozyHR REST API calls using API keys, OAuth client credentials, scopes and rate limits. It covers api key creation, oauth client credentials, scoped access control and explains how CozyHR connects api keys and oauth client credentials with employee records, attendance, payroll, compliance workflows and Super Admin controls. The page is written for HR admins, payroll managers, founders and operations teams who need practical software context rather than a thin brochure page.

Who should use CozyHR API Authentication?

CozyHR API Authentication is useful for HR admins, payroll managers, operations leaders and tenant owners who want structured software for api key creation.

How does CozyHR support this workflow?

CozyHR connects this page's workflow to employee master data, organization setup, attendance, payroll, approvals, reports and Super Admin configuration so the process stays governed end to end.

Can this be configured for Indian payroll and compliance?

Yes. CozyHR is designed with India-first HR and payroll context including PF, ESI, professional tax, TDS, employee documents, attendance devices, shift policies and payroll review workflows.

CozyHR next step

Build on the CozyHR REST API.

Create API keys in the developer console, test employee and attendance endpoints, then attach webhook delivery logs for production monitoring.

Open developer docs