Developer Documentation

Hiriso Public API

REST API for integrating with your Hiriso recruitment data — candidates, positions, and interviews.

Getting Started

1. Create an API Key

Navigate to Settings → API Keys in the Hiriso app and generate a new key. Choose permissions (read-only or read/write) and optional scope restrictions.

2. Authenticate requests

Include your key in the Authorization header:

Authorization: Bearer hsk_your_api_key_here

3. Base URL

https://api.hiriso.com/api/v1/

Authentication & Security

Bearer Token Authentication

All API requests require a valid API key in the Authorization header. Keys are scoped to your company — you can only access data belonging to your organization.

Data Isolation

Strict multi-tenant isolation ensures every query filters by your company ID. You cannot access data from other companies.

Rate Limiting

Default: 60 requests/minute per key. Configurable when creating a key (1–1000). A 429 response includes Retry-After and X-RateLimit-* headers.

Scope Restrictions

Optionally limit keys to specific resource types: candidates, positions, interviews, candidate_positions.

Error Handling

StatusMeaning
200Success
201Created (POST success)
400Bad request — invalid input or missing fields
401Unauthorized — missing or invalid API key
403Forbidden — insufficient permissions or scope
404Not found — resource doesn't exist or belongs to another company
405Method not allowed
429Rate limit exceeded — wait and retry
500Internal server error

Error response format:

{
  "error": "Descriptive error message"
}

Candidates

Positions

Interviews

Coming Soon

OAuth 2.0 Authentication

Public/private key authentication with OAuth 2.0 authorization code flow for third-party integrations. Generate client credentials, authorize via consent screen, and use access/refresh tokens.

Webhooks

Real-time event notifications for candidate status changes, interview completions, and position updates.