Skip to content

API overview

Read and change jobs, applications, candidates and hiring numbers in your workspace from your own systems.

The Tahoe API is an HTTP API over the jobs, applications, candidates and pipelines in a Tahoe workspace. It comes with a change feed and webhooks so you can stay current, and with Sign in with Tahoe so your users can log in with the Tahoe account they already have.

Base URL and version

There is one base URL for every environment: https://tahoe.workonward.com/api/partner/v1. There is no separate sandbox host. A test key and a live key read the same workspace through the same path, and the prefix on the key tells them apart in your logs.

Every response carries the API version in the Tahoe-Api-Version header, and GET /ping reports it without a key. The version is a date. It changes only for a breaking change: new fields, endpoints and event types are added without one.

Three things to know before you start

It reads, and it writes only where you allow it

Most endpoints are a GET, plus two POST reads whose input is too large or too sensitive for a query string: /people/resolve:batch and /pool/search.

Writes are separate, and each one needs its own scope, which is a paid plan scope. You can push job postings, publish, close and reopen jobs, add a candidate to a job, move, reject, reopen and annotate applications, send an email to a person who applied, create and fill lists, and register your own webhook endpoints. A write is attributed to the person who created the key, so recruiters see it, and it is an API key that writes: a Sign in with Tahoe token writes only when writes for connected apps are switched on. Nothing the API does deletes data, and nothing is sent to a candidate except through POST /messages. Send an Idempotency-Key with a write so that a retry cannot do it twice. See Scopes that write.

Personal data is metered and audited

Emails, phone numbers and resumes sit behind their own scopes, and every read of one is recorded with the key, the record and the field. Personal data also has a daily budget that is separate from the request rate limit, so you can page through jobs all day without being able to bulk-copy phone numbers.

The API never hands out contact details the workspace has not already revealed in Tahoe. A field that was never revealed is reported as withheld, with a reason. It is not silently empty.

It shows nothing a recruiter could not already see

The API is a view onto one workspace’s own data. It is not a way into other customers’ data or into the content of a phone screen. What is never exposed lists what has no place in the API at all.

What you can read and change

AreaWhat you getMain scope
JobsJob postings, their sections, application forms, pipeline stages and pre-screen questions. Push postings, and publish, unpublish, close and reopen jobsjobs:read, jobs:write, jobs:manage
ApplicationsApplications, stage and status, form answers, match scores, stage history, resumes. Move, reject, reopen and annotate themapplications:read, applications:write, notes:write, scorecards:write
Create an applicationUpload a resume and add a candidate to a job from your own systemapplications:write
MessagesSend an email to a person who applied, with the unsubscribe link and a daily capmessages:send
ApplicantsThe people who applied, their applications, resumes and contact detailsapplicants:read
Sourced profilesCandidates the workspace found and saved, with revealed contact details and attachmentssourced_profiles:read
Shared poolPublic professional profiles Tahoe already holds, and a free search over thempool:read
PeopleMatch your own records to a Tahoe person by email or LinkedIn URLpeople:resolve
Projects and listsProjects, candidate lists, members and their stage. Create lists and fill themlists:read, lists:write
AnalyticsHiring funnel totals, time in stage and time to hireanalytics:read
EventsThe change feed, erasure notices, and your webhook endpoints and their delivery statusevents:read, webhooks:read, webhooks:write
Sign in with TahoeStandard OpenID Connect sign-in with PKCEno API key

Getting access

Workspace owners and admins create API keys in Settings, under Developer. Pick the scopes you need and a term, and the key reads that workspace. Scopes that write need a paid plan. If the Developer tab is missing, email [email protected].

Your first call

GET /me tells you exactly what the key in your hand can do: its scopes, which workspaces it can reach, whether it must name one, and its current limits. It is the quickest way to tell a setup problem from a code problem.

Request
curl https://tahoe.workonward.com/api/partner/v1/me \
  -H "Authorization: Bearer $TAHOE_API_KEY"
Response
{
  "object": "credential",
  "id": "pk_9tRc4mQx7Lb2",
  "name": "Acme HRIS sync",
  "environment": "live",
  "scopes": ["applications:read", "jobs:read", "workspaces:read"],
  "scope_descriptions": {
    "applications:read": "Applications, their stage and status, and match scores.",
    "jobs:read": "Job postings, their content, application forms and pipeline stages.",
    "workspaces:read": "Workspace name and creation date."
  },
  "workspace_scope": "list",
  "workspace_ids": ["wsp_4Kd8sPm2Qx7L"],
  "workspace_id_required": false,
  "rate_limits": {
    "general_per_minute": 600,
    "expensive_per_minute": 60,
    "download_per_minute": 30,
    "personal_data_reads_per_day": 5000,
    "personal_data_reads_used_today": 128,
    "max_page_size": 100,
    "max_result_window": 10000
  },
  "created_at": "2026-09-09T10:14:22.510Z",
  "expires_at": "2026-12-08T10:14:22.510Z",
  "api_version": "2026-09-09"
}

Getting help

Every response carries a Tahoe-Request-Id header. Include it when you contact us, and we can find the exact request.