generated: '2026-07-19' method: searched source: https://developer.employmenthero.com/api-references description: >- Authentication profile for the Employment Hero API (the platform behind humi.ca — Humi is now Employment Hero Canada). The API uses OAuth 2.0 authorization-code with PKCE (S256) mandatory as of 2026-09-14. Bearer access tokens are short-lived (15 minutes); refresh tokens currently do not expire. Token requests are sent as application/x-www-form-urlencoded. summary: types: [oauth2] oauth2_flows: [authorizationCode] pkce_required: true access_token_ttl_seconds: 900 schemes: - name: OAuth2 type: oauth2 flow: authorizationCode authorizationUrl: https://oauth.employmenthero.com/oauth2/authorize tokenUrl: https://oauth.employmenthero.com/oauth2/token token_type: Bearer pkce: required: true code_challenge_method: S256 access_token_lifetime: 15 minutes refresh_token_lifetime: no expiration (current) docs: https://developer.employmenthero.com/api-references sources: [https://developer.employmenthero.com/api-references]