# Kolay İK > Kolay İK (Kolay Yazılım A.Ş.) is an Istanbul-based cloud HR / human-capital-management SaaS platform used by 4,500+ companies and 300,000+ employees, mostly in Türkiye. It covers personnel records, payroll, performance, shifts, compensation review, applicant tracking, HR analytics, time and attendance, leave, expenses and training. Kolay publishes one official public REST API — the Kolay Public API (v2) at https://api.kolayik.com — documented as a public Postman collection. Generated by the API Evangelist enrichment pipeline on 2026-07-19. Kolay publishes no llms.txt of its own; this file is generated from the catalog and the artifacts in this repository. Source of record: https://apidocs.kolayik.com/ ## APIs - [Kolay Public API](https://apidocs.kolayik.com/): 46 operations under https://api.kolayik.com/v2/ covering person, unit, leave, timelog, transaction, approval process, calendar, training, expense and payroll. ## Authentication - Bearer API token: `Authorization: Bearer ` - Create a token at https://app.kolayik.com/settings/developer-settings - Effective authorization is bounded by the account's Kolay access type: owner (full read/write), manager (as owner, minus payment and tax details), employee (own record only). - No OAuth 2.0, no OpenID Connect, no scopes. ## Conventions - All responses use the envelope `{"error": , "data": }`. - Versioning is uri-path: `/v2/`. - Dates are `YYYY-MM-DD`; datetimes are `YYYY-MM-DD HH:MM:SS`. - List operations page with `limit` and `page`; some also take `sortType` and `sortOrder`. - Identifiers are opaque 32-character hexadecimal strings with no type prefix. - No idempotency key, no documented rate limits, no webhooks, no sandbox or test mode — every write hits live HR data. ## Specs and artifacts - [OpenAPI 3.1](openapi/kolayik-public-api-openapi.yml) — converted faithfully from the official Postman collection - [Postman collection](postman/kolayik-public-api-postman.json) — the official published collection, verbatim - [OpenAPI Overlay](overlays/kolayik-public-api-overlay.yaml) - [Authentication profile](authentication/kolayik-authentication.yml) - [API conventions](conventions/kolayik-conventions.yml) - [Error semantics](errors/kolayik-problem-types.yml) - [Data model](data-model/kolayik-data-model.yml) - [Lifecycle](lifecycle/kolayik-lifecycle.yml) - [Conformance](conformance/kolayik-conformance.yml) - [Agentic access contracts](agentic-access/kolayik-agentic-access.yml) - [Agent skills](skills/_index.yml) - [MCP candidate surface](mcp/kolayik-mcp.yml) - [Packages](packages/kolayik-packages.yml) - [CLI (community)](cli/kolayik-cli.yml) - [Domain security](security/kolayik-domain-security.yml) - [Well-known probe results](well-known/kolayik-well-known.yml) ## Docs and developer surfaces - [API documentation](https://apidocs.kolayik.com/) - [Developer settings / API tokens](https://app.kolayik.com/settings/developer-settings) - [API support email](mailto:apisupport@kolay.io) - [Help center](https://destek.kolayik.com/tr/) - [Product changelog](https://updates.kolayik.com/tr) - [Status page](https://status.kolayik.com) - [GitHub organization](https://github.com/kolayik) ## Company - [Website](https://kolayik.com) - [About](https://kolayik.com/hakkimizda) - [Pricing](https://kolayik.com/insan-kaynaklari-yazilimi-fiyatlari) - [Sign up](https://kolayik.com/kayit-ol) - [Log in](https://app.kolayik.com/home) - [Blog](https://kolayik.com/blog) - [Academy](https://akademi.kolayik.com/) - [Terms of service](https://kolayik.com/kullanici-sozlesmesi) - [Privacy / KVKK notice](https://kolayik.com/internet-sitesi-kvkk) - [Information security policy](https://kolayik.com/bilgi-guvenligi-politikasi) — TS ISO/IEC 27001:2013, TS ISO/IEC 27701:2019, TS EN/ISO 9001:2015 ## Cautions for agents - This API reads and writes personal data, salary and payroll records for real employees, under Türkiye's KVKK regime. Treat every write as high consequence. - There is no sandbox. Confirm with a human before any create, update, terminate or delete. - There is no idempotency key. Never retry a write blindly — re-read first. - `personTerminate`, `personDeleteFile` and `personDeleteFolder` are the most destructive operations in the surface.