# Harri > Harri is a hospitality-first HCM and workforce management platform for enterprise restaurants, hotels, > retailers, grocers and care operators. Its public Open API Hub covers the employee record and the labor > data around it: employees, locations, positions, job titles, pay types, hourly and annual rates, tronc and > tip distribution, employment periods, absences, max weekly hours and working patterns, external-system ID > mappings, platform events and webhook subscriptions, plus an employer/brand-management surface for > above-store admin users. Every corporate resource is mirrored under a franchisee-scoped path set. Generated by API Evangelist from the Harri developer portal on 2026-08-04. This is a third-party profile. Harri publishes no llms.txt of its own. ## Getting started - [Harri Developer Portal](https://developer.harri.com/): APIs, feeds and developer documentation - [Harri APIs Overview](https://developer.harri.com/about-api/): the portal entry page (member-gated body) - [Authentication](https://developer.harri.com/authentication/): OAuth 2.0 client credentials, token reuse, troubleshooting - [Developer sign-up](https://developer.harri.com/sign-up/): request a developer-portal account - [API Release Notes](https://developer.harri.com/api-release-notes/): dated changelog (member-gated body) ## APIs - [Harri Employee API](https://developer.harri.com/employees/): 363 operations over the employee record and its labor data. Base URL https://gateway.harri.com/open-api-hub. OpenAPI 3.0.1. - [Harri External Brand Management API](https://developer.harri.com/employer/): 22 operations over employer and brand records and above-store admin users. Base URL https://gateway.harri.com/open-api-hub. OpenAPI 3.0.3. ## Specs - openapi/harri-employee-openapi.yml: OpenAPI 3.0.1, 255 paths, 363 operations, 100 schemas - openapi/harri-employer-openapi.json: OpenAPI 3.0.3, 10 paths, 22 operations, 5 schemas - overlays/harri-employee-overlay.yaml, overlays/harri-employer-overlay.yaml: API Evangelist enhancements ## How to call it - Auth: POST https://oauth.harri.com/oauth2/token with client_id, client_secret, grant_type=client_credentials. Response carries access_token, expires_in (1800) and token_type Bearer. Send Authorization: Bearer . Reuse one token for its whole expiry window — Harri discourages per-request token minting. - No OAuth scopes exist. Reach is bound to the credential: Harri Support associates corporate IDs with it. - Rate limit: 400 requests per minute. HTTP 403 historically, HTTP 429 after 4 June 2026. No rate-limit headers. - Pagination: limit + page query parameters on some list operations; responses are bare JSON arrays. - No idempotency key, no request-id header, no field expansion, no RFC 9457 problem details. - Versioning is per-resource in the URI path: /api/v1/ through /api/v7/ all serve side by side, and 150 of the 363 Employee API operations are flagged deprecated. - Franchisee operators call the mirrored /api/v{n}/franchisees/{franchiseeId}/... path set. ## Artifacts in this profile - authentication/harri-authentication.yml: the OAuth 2.0 client-credentials profile - scopes/harri-scopes.yml: records that Harri runs OAuth without a scope surface - conventions/harri-conventions.yml: cross-cutting request/response semantics - rate-limits/harri-rate-limits.yml: the 400/minute limit and the 403 to 429 change - errors/harri-problem-types.yml: 4xx responses derived from the specs, plus documented-but-unmodeled errors - lifecycle/harri-lifecycle.yml: versioning, the 150 deprecated operations, status page, release notes - asyncapi/harri-webhooks.yml: the event and subscription surface; no AsyncAPI is published - data-model/harri-data-model.yml: entity graph derived from the component schemas - conformance/harri-conformance.yml: standards asserted and denied, with evidence - security/harri-domain-security.yml: TLS, HSTS, DNSSEC, CAA, SPF, DMARC probe results - well-known/harri-well-known.yml: every /.well-known/ path probed; Harri publishes none - packages/harri-packages.yml: no first-party SDK exists in any public registry - mcp/harri-mcp.yml: candidate MCP tool surface derived from the OpenAPI; Harri ships no MCP server - agentic-access/harri-agentic-access.yml: recommended x-agentic-access contracts for 385 operations - skills/: packaged Agent Skills grounded in real Harri operationIds ## Operational - [Status page](https://status.harri.com/): Login & SSO, Talent Acquisition, Workforce Management, CoreHR, Carri, TeamHub, HarriIQ. RSS, Atom, JSON, webhook and Slack subscriptions available. - [Terms of Service](https://harri.com/terms/) - [Privacy Policy](https://harri.com/privacy/) - [GitHub organization](https://github.com/HarriLLC): infrastructure forks only, no API client libraries ## Optional - [Harri](https://harri.com/): the product site - [Harri Insider blog](https://resources.harri.com/blog) - [Agentic AI](https://harri.com/agentic-ai/): Salli and Harri's in-product agents. No developer-facing agent protocol surface — no MCP server, no A2A agent card. - [Partners](https://harri.com/partners/)