REST API for integrating with your Hiriso recruitment data — candidates, positions, and interviews.
Navigate to Settings → API Keys in the Hiriso app and generate a new key. Choose permissions (read-only or read/write) and optional scope restrictions.
Include your key in the Authorization header:
Authorization: Bearer hsk_your_api_key_herehttps://api.hiriso.com/api/v1/Bearer Token Authentication
All API requests require a valid API key in the Authorization header. Keys are scoped to your company — you can only access data belonging to your organization.
Data Isolation
Strict multi-tenant isolation ensures every query filters by your company ID. You cannot access data from other companies.
Rate Limiting
Default: 60 requests/minute per key. Configurable when creating a key (1–1000). A 429 response includes Retry-After and X-RateLimit-* headers.
Scope Restrictions
Optionally limit keys to specific resource types: candidates, positions, interviews, candidate_positions.
| Status | Meaning |
|---|---|
200 | Success |
201 | Created (POST success) |
400 | Bad request — invalid input or missing fields |
401 | Unauthorized — missing or invalid API key |
403 | Forbidden — insufficient permissions or scope |
404 | Not found — resource doesn't exist or belongs to another company |
405 | Method not allowed |
429 | Rate limit exceeded — wait and retry |
500 | Internal server error |
Error response format:
{
"error": "Descriptive error message"
}OAuth 2.0 Authentication
Public/private key authentication with OAuth 2.0 authorization code flow for third-party integrations. Generate client credentials, authorize via consent screen, and use access/refresh tokens.
Webhooks
Real-time event notifications for candidate status changes, interview completions, and position updates.