openapi: 3.0.3 info: title: Nmbrs Public REST API (HR & Payroll) Absences Wage Components API description: 'Modeled OpenAPI for the Visma Nmbrs public REST API - the current, forward-looking interface to Nmbrs HR and payroll software (Netherlands and Sweden). The REST API is served from https://api.nmbrsapp.com and is authenticated with the OAuth 2.0 Authorization Code flow (identityservice.nmbrs.com) plus a per-product subscription key sent on every request. It exposes HRIS and payroll resources - companies, employees, employments, personal and salary info, wage components, payruns, and absences - scoped by granular OAuth scopes such as employee.info, employee.employment, and employee.payment. HONESTY NOTE: The Nmbrs REST API reference is published as an interactive Stoplight project rather than a downloadable OpenAPI file, and the live endpoints are gated behind OAuth + a subscription key (GET https://api.nmbrsapp.com/api/companies returns 401 unauthenticated). The paths, parameters, and schemas below are MODELED from the published resource groups and the confirmed base URL / auth model; they are a faithful representation for discovery, not a byte-for-byte copy of the vendor spec. Nmbrs also operates a separate, older SOAP API (api.nmbrs.nl/soap/v3, EmployeeService / CompanyService / DebtorService) that is deprecated and scheduled to be retired on 1 March 2027 - it is described in the repository README and review, not in this REST document.' version: 1.0-modeled contact: name: Nmbrs Developer Portal url: https://developer.nmbrs.com servers: - url: https://api.nmbrsapp.com description: Nmbrs Public REST API security: - oauth2: [] subscriptionKey: [] tags: - name: Wage Components description: Fixed and variable wage components used in payroll. paths: /api/employees/{employeeId}/wagecomponents: get: operationId: listWageComponents tags: - Wage Components summary: List wage components description: Lists fixed and variable wage components for an employee. parameters: - $ref: '#/components/parameters/EmployeeId' responses: '200': description: A list of wage components. content: application/json: schema: type: object properties: data: type: array items: $ref: '#/components/schemas/WageComponent' '401': $ref: '#/components/responses/Unauthorized' post: operationId: createWageComponent tags: - Wage Components summary: Add a wage component description: Adds a fixed or variable wage component to an employee. parameters: - $ref: '#/components/parameters/EmployeeId' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/WageComponent' responses: '201': description: The created wage component. content: application/json: schema: $ref: '#/components/schemas/WageComponent' '401': $ref: '#/components/responses/Unauthorized' components: responses: Unauthorized: description: Missing or invalid OAuth token or subscription key. content: application/json: schema: type: object properties: statusCode: type: integer example: 401 message: type: string example: Access denied due to invalid subscription key or bearer token. schemas: WageComponent: type: object properties: code: type: integer value: type: number kind: type: string enum: - fixed - variable period: type: integer year: type: integer parameters: EmployeeId: name: employeeId in: path required: true description: Unique identifier of the employee. schema: type: string securitySchemes: oauth2: type: oauth2 description: OAuth 2.0 Authorization Code flow via identityservice.nmbrs.com. flows: authorizationCode: authorizationUrl: https://identityservice.nmbrs.com/connect/authorize tokenUrl: https://identityservice.nmbrs.com/connect/token scopes: employee.info: Read/write employee personal information employee.info.read: Read employee personal information employee.employment: Read/write employment data employee.employment.read: Read employment data employee.payment: Read/write salary and payment data subscriptionKey: type: apiKey in: header name: X-Subscription-Key description: Per-product subscription key generated in the Nmbrs developer portal, required on every request in addition to the OAuth bearer token.