# Buk — API surface > Buk (Buk SpA, Santiago, Chile) is a Latin American HR and payroll platform covering payroll, > employee records, contracts and digital signature, time and attendance, absences and > vacations, benefits, recruiting, onboarding, training and performance. It operates country > editions for Chile, Peru, Mexico, Colombia and Brazil. > > Generated by API Evangelist on 2026-08-08 from Buk's own published contracts. Buk publishes an > llms.txt at https://www.buk.cl/llms.txt, but it indexes marketing pages only and says nothing > about the API — this file covers the API surface. Method: generated. Nothing below is > invented; every URL was fetched and every count was computed from a harvested spec. ## What Buk publishes - **Three REST APIs**, all with public machine-readable contracts. - **A webhook catalog** of 15 named event types, documented in prose. - **No** developer portal, SDK, CLI, Postman workspace, sandbox, status page, MCP server, GraphQL surface, AsyncAPI document, A2A agent card, or `/.well-known/` discovery surface. ## APIs ### [Buk Data Access API](https://demo.buk.cl/apidocs) The HR and payroll system of record. 151 paths, 206 operations, 40 tag groups. Swagger 2.0. Served **unauthenticated** from every customer tenant at `https://{tenant}.buk.cl/api/{country}/{language}/api_docs` in five country variants (chile, colombia, peru, mexico, brasil) and three languages (es, en, pt). Base URL: `https://{tenant}.buk.cl/api/v1/{country}`. Auth: API key in an `auth_token` header, issued by a tenant administrator under *Configuración → Acceso API*, scoped per entity to *Lectura* or *Lectura y Modificación*. ### [Buk Asistencia API](https://app.swaggerhub.com/apis-docs/BUKASISTENCIA/ApiAsistencia/1.0.0) Time and attendance. 10 operations, OpenAPI 3.0.0, published on SwaggerHub. Base URL: `https://app.ctrlit.cl/ctrl/api` (also `https://app2.ctrlit.cl/ctrl/api`). Auth: API key in a `token` header, requested from the Buk SAC team. ### [Buk Attendance — Biometric Integration API](https://app.swaggerhub.com/apis-docs/BUKASISTENCIA/AttendanceBiometrics/1.0.0) A single vendor-agnostic clocking ingestion endpoint, `POST /v1/clockings`, for biometric device middleware from any manufacturer. OpenAPI 3.0.3. Base URL: `https://zktc.prod.asis.buk.cl/rest`. Auth: header pair `x-provider-name` + `x-provider-token`. ## Machine-readable contracts - https://demo.buk.cl/api/chile/en/api_docs — Swagger 2.0, Chile - https://demo.buk.cl/api/colombia/en/api_docs — Swagger 2.0, Colombia - https://demo.buk.cl/api/peru/en/api_docs — Swagger 2.0, Peru - https://demo.buk.cl/api/mexico/en/api_docs — Swagger 2.0, Mexico - https://demo.buk.cl/api/brasil/en/api_docs — Swagger 2.0, Brazil - https://api.swaggerhub.com/apis/BUKASISTENCIA/ApiAsistencia/1.0.0 — OpenAPI 3.0.0 - https://api.swaggerhub.com/apis/BUKASISTENCIA/AttendanceBiometrics/1.0.0 — OpenAPI 3.0.3 ## Documentation - [Swagger UI](https://demo.buk.cl/apidocs): served from every tenant at `/apidocs`, with a country selector, a language selector, and a Webhooks tab. - [Cómo integrarse a Buk a través de API](https://supportcenter.buk.cl/hc/es-419/articles/36657679009307-C%C3%B3mo-integrarse-a-Buk-a-trav%C3%A9s-de-API): getting started. - [¿Cómo funciona nuestra API?](https://supportcenter.buk.cl/hc/es-419/articles/46268700701723--C%C3%B3mo-funciona-nuestra-API): token issuance and permission levels. - [APIs de Buk Asistencia](https://supportcenter.buk.cl/hc/es-419/articles/50240904785051-APIs-de-Buk-Asistencia): attendance API. - [Support Center](https://supportcenter.buk.cl/hc/es-419) ## Conventions an agent needs - **Multi-tenant, multi-country by URL.** Country is a path segment; the tenant is a subdomain. Each country is a separate contract with a different definition set. - **Pagination**: `page` and `page_size` in; `pagination.{next,previous,count,page,totalPages}` out. Default 25, documented maximum 100 on Buk Asistencia. - **No idempotency.** No `Idempotency-Key` or equivalent exists on any operation. Retrying a POST creates a duplicate record. Re-read before every retry. - **No documented rate limit.** No `429` response appears in any of the 217 operations and no rate-limit headers are described. - **Errors are plain JSON with free-text messages**, mixing Spanish and English, with no machine-readable error code. Branch on HTTP status: 400, 401, 404, 409, 422, 503 are the documented set. - **Security is declared but not applied**: the Swagger 2.0 contracts define `securityDefinitions.auth_token` and then attach no `security` block to any operation, so a generated client will not send the header. - **No operationIds**: all 206 Data Access operations lack `operationId`. Address them as METHOD + path. The Asistencia contract does carry operationIds. ## Events Webhooks only — no AsyncAPI. Configured by a tenant admin in the UI (*Configuración → Acceso API → Urls Webhooks*); there is no subscription API. Notification-only: the body carries a record id, an ISO 8601 `date`, an `event_type` and the `tenant_url`, and the integrator must call the API to read the changed record. Events: `employee_create`, `employee_update`, `employee_plan_update`, `employee_responsibility_update`, `job_hire`, `job_termination`, `job_movement`, `area_create`, `area_update`, `vacation_create`, `vacation_update`, `vacation_destroy`, `{licence|absence|permission}_{create|update|destroy}`, `document_create`. No signature, no shared secret, no documented retry or ordering guarantee. ## Security and compliance - [Trust Center](https://trust.buk.cl/) (SafeBase by Drata): ISO/IEC 27001:2022, SOC 2 Type 2, B Corp. - **No** `/.well-known/security.txt` on any Buk host, and no published vulnerability-disclosure or bug-bounty programme. ## Company - [Website](https://www.buk.cl/) · [Peru](https://www.buk.pe/) · [Mexico](https://www.buk.mx/) · [Colombia](https://www.buk.co/) - [Pricing](https://www.buk.cl/precios) · [Buk Starter sign-up](https://www.buk.cl/starter) - [Blog](https://www.buk.cl/blog) · [Engineering blog](https://buk.engineering/) - [Product roadmap and release notes](https://www.buk.cl/productos/roadmap-novedades-productos) - [GitHub](https://github.com/bukhr) · [Terms](https://www.buk.cl/starter/terminos-y-condiciones) · [Privacy](https://www.buk.cl/privacidad)