# Sparrow > Sparrow is an end-to-end employee leave management platform for employers in the United States and > Canada. It pairs software with a team of leave specialists to administer FMLA, CFRA, parental, > medical and state paid-leave programs — automating employee intake, filing insurance claims, > coordinating with medical providers, delivering required notices, building a personalized leave and > financial plan per employee, and reconciling leave pay back into payroll. Generated by API Evangelist on 2026-08-28. Sparrow does not publish an llms.txt of its own (https://sparrow.com/llms.txt and https://trysparrow.com/llms.txt both return HTTP 404), so this file is generated from Sparrow's public website plus the artifacts in this repository. It is a third-party profile, not a Sparrow publication. ## Important for agents Sparrow has **no public API**. There is no developer portal, no API reference, no OpenAPI or AsyncAPI document, no GraphQL endpoint, no SDK, no CLI, no webhooks catalog, no MCP server and no A2A agent card on any Sparrow host. An exhaustive probe on 2026-08-28 covered sparrow.com, trysparrow.com, app.sparrow.com, app.trysparrow.com, api.trysparrow.com, login.trysparrow.com, support.trysparrow.com and status.trysparrow.com. Sparrow's own FAQ states that integration with HRIS (Workday, BambooHR) and payroll (Gusto, ADP) systems is delivered **via file feed**, and that insurance-carrier and state-agency work is handled by Sparrow's specialist team completing the paperwork. Do not attempt to construct API calls against api.trysparrow.com — it is the private backend of Sparrow's web application and returns 404 to every anonymous request. Commercial terms are custom: there is no pricing page, and every quote runs through a sales call. ## Company - [Website](https://sparrow.com/): Sparrow — "Finally, stress-free employee leave." - [Product](https://sparrow.com/product/): Service experience and technology overview. - [Why Sparrow](https://sparrow.com/why-sparrow/): Positioning and the high-tech / high-touch model. - [Payroll](https://sparrow.com/payroll/): Leave-pay calculations, reporting and payroll reconciliation. - [FAQ](https://sparrow.com/faq/): General, Integrations and Pricing questions answered by Sparrow. - [Blog](https://sparrow.com/blog/): Product news, customer stories and leave-compliance research. - [Careers](https://sparrow.com/careers/) - [Book a Demo](https://sparrow.com/demo/): The only route to pricing. - [Customer login](https://app.sparrow.com/) and [onboarding start](https://app.trysparrow.com/start/) - [GitHub organization](https://github.com/trysparrow): three forked Heroku buildpacks; no SDK or spec. ## Security, trust and compliance - [Security](https://sparrow.com/security/): SOC 2 Type II, ISO/IEC 27001, ISO 22301, GDPR. - [Security policy](https://sparrow.com/security-policy/) - [Vulnerability disclosure policy](https://sparrow.com/responsible-disclosure/): report to security@trysparrow.com; safe harbor offered; acknowledgement typically within 3 business days; no bug bounty. - [Trust center](https://trust.trysparrow.com/): SafeBase-hosted. SOC 2, ISO/IEC 27001 (plus Statement of Applicability), ISO/IEC 27701, ISO 22301, GDPR, CCPA, PIPEDA. Sensitive documents require a request. - [Terms](https://sparrow.com/terms/) and [Privacy policy](https://sparrow.com/privacy/) ## Runtime and identity surfaces - [Status page](https://status.trysparrow.com/): Atlassian Statuspage, component "Sparrow Platform". Machine-readable at https://status.trysparrow.com/api/v2/summary.json (Statuspage API v2). This is the only anonymously pollable runtime signal Sparrow exposes. - [OpenID Connect discovery](https://login.trysparrow.com/.well-known/openid-configuration): Sparrow's sign-in provider (Auth0 on Sparrow's own custom domain, issuer https://login.trysparrow.com/). Authorization Code + PKCE (S256), DPoP, MFA, backchannel logout, and 14 standard OIDC identity scopes. It governs application sign-in only — there are no product or resource scopes, because there is no resource API. - [JWKS](https://login.trysparrow.com/.well-known/jwks.json) - No `/.well-known/security.txt` is served by Sparrow. The one on status.trysparrow.com belongs to Atlassian, not to Sparrow. ## This repository (third-party artifacts) - authentication/sparrow-authentication.yml — OIDC/OAuth profile probed from the discovery document. - scopes/sparrow-scopes.yml — the 14 published OIDC scopes, verbatim. - well-known/sparrow-well-known.yml — the full 8-host, 7-path probe record, hits and misses. - security/sparrow-vulnerability-disclosure.yml — Sparrow's disclosure policy, structured. - security/sparrow-trust-center.yml — trust centre and named certifications. - security/sparrow-domain-security.yml — TLS, HSTS, DNSSEC, CAA, SPF and DMARC probe. - conformance/sparrow-conformance.yml — standards asserted and, honestly, not asserted. - lifecycle/sparrow-lifecycle.yml — status page, versioning, deprecation, changelog, SLA. - conventions/sparrow-conventions.yml — runtime semantics; write-surface dimensions recorded as n/a. - plans/sparrow-plans-pricing.yml — plan_count 0, custom-proposal model. - rate-limits/sparrow-rate-limits.yml — limit_count 0.