ADP API facts that shape an MCP server
| Fact | Detail | Source |
|---|---|---|
| Official MCP server | None. As of September 2026 ADP hasn’t published an MCP server, and a search of the official MCP Registry for "adp" returns only unrelated servers, such as Google Ads and Apple Ads tools. | Official MCP Registry: search for adp |
| ADP’s own AI | ADP’s AI is ADP Assist. In a September 8, 2026 release, ADP describes ADP Assist agents built with Amazon Bedrock AgentCore for employees, managers and HR and payroll practitioners that "think, plan, and take action under human oversight". The release doesn’t mention MCP. | ADP newsroom: ADP partners with AWS (September 8, 2026) |
| ADP Assist in Microsoft 365 Copilot | Companies that use ADP Assist in their ADP payroll system can add ADP’s Marketplace app to bring it into Microsoft Teams and Microsoft 365 Copilot for HR information, time-off requests, benefits support and payroll questions. ADP lists it for Workforce Now (current and next generation), RUN, Vantage HCM, TotalSource, Enterprise HR and Lyric HCM. | ADP Marketplace: ADP Assist for Microsoft Teams |
| API access for clients | ADP API Central is an add-on subscription, priced per employee per month and bought through ADP Marketplace, for Workforce Now, Workforce Now Next Generation, Vantage HCM, Enterprise HR (V6) and Lyric. RUN Powered by ADP isn’t on that list, and ADP notes that available APIs vary by platform. | ADP Developer Resources: client integration overview |
| Authentication | Every API request needs a mutual TLS connection using the X.509 certificate registered for your application, plus an OAuth 2.0 bearer token. Tokens expire after 60 minutes by default, can’t be used by another application, and may be tied to the environment that requested them, for example an IP address. | ADP Developer Resources: Access Tokens |
| Rate limits | ADP asks each API Central project to stay under 120 calls in a 60-second period with no more than 10 concurrent requests, and Marketplace partner apps under 300 calls and 50 concurrent requests. Beyond that, ADP throttles requests and returns HTTP 429. | ADP Developer Resources: Access Tokens |
| App types and consent | ADP Marketplace defines two application types. A data connector uses the client_credentials grant and acts as a pre-assigned system user in the practitioner role, with consent given once by the purchasing organization. An end-user application uses authorization_code, acts with the signed-in person’s own ADP authorizations, and collects consent again every 90 days. | ADP Developer Resources: Application Types |
| Revoking access | When a company buys a Marketplace app that connects system to system, ADP emails the purchaser to allow or deny the app’s request for company data. An allowed app can be blocked later in ADP Consent Manager at adpapps.adp.com/consent-manager. | ADP Developer Resources: Using Consent Manager |
| Events | ADP puts data-change events, such as a new hire, on a first-in, first-out queue that you poll, or since October 2025 pushes them to your webhook. Webhooks need a publicly accessible US endpoint and carry an HMAC-SHA256 signature, and failed deliveries are retried and kept for five days. | ADP Developer Resources: event notification guide |
| Payroll input API | Workforce Now’s Pay Data Input API lets a data connector application send data into a specific pay data batch for a payroll cycle, covering items such as earnings, deductions, reimbursements, allocations and shifts. | ADP API Explorer: Pay Data Input for Workforce Now |
| Sensitive APIs | ADP’s Workforce Now API catalog also includes Pay Statements (gross and net pay, deductions and year-to-date totals), Worker Pay Distributions for direct deposit, US Tax Profiles for state tax withholding, and APIs that add or change a worker’s government ID. | ADP API Explorer: ADP Workforce Now APIs |
| Sensitive actions in hosted catalogs | StackOne’s ADP Workforce Now server has 53 actions, including changing a worker’s base pay and direct-deposit settings, modifying pay data for a payroll cycle, reading organizational pay statements and terminating a work assignment. | StackOne: ADP Workforce Now MCP server |
Every way to connect ADP to AI
| Option | Type | Fits when | Limits |
|---|---|---|---|
| StackOne ADP Workforce Now MCP | Hosted | A quick pilot with 53 actions across workers, time off, pay data, departments, jobs and recruiting. Each user authenticates their own ADP account while StackOne handles token exchange and refresh, and session tokens can be scoped to exact actions, with a prompt-injection guard. | The catalog includes base-pay and direct-deposit changes, pay statements and terminations, so restrict actions before connecting an assistant. Workforce Now Next Generation is a separate StackOne connector, and data passes through StackOne. |
| Knit ADP MCP servers | Hosted | Separate ADP Workforce Now HRIS and ADP RUN HRIS servers, so it also covers small businesses on RUN. Knit manages credentials and refresh and says it is a stateless passthrough that doesn’t store ADP data. | Actions include Terminate Employee, Update Employee Compensation, deduction changes and Get Payroll Statement, so turn off what you don’t need. Pricing is by integrated accounts or API call volume, with a 30-day free trial. |
| Unified.to ADP Workforce Now | Hosted | Real-time, pass-through reads and writes through a unified API and MCP server, covering employees, time off, groups, locations, deductions and payslips. Unified.to says it never stores end-customer data. | Its ADP models include bank accounts and payslips, and a raw passthrough can call other ADP endpoints, so lock both down. Usage-based pricing, with a 30-day free trial. |
| Apideck ADP Workforce Now MCP | Hosted | A narrow scope that is easy to review: employees and time-off requests only, each with list, get, create, update and delete, through Apideck’s MCP server and its Vault connection. | Writes include deleting employees and time-off requests, so disable them. Apideck’s ADP setup asks you for your own ADP client ID, secret, certificate and private key, from API Central or an ADP partnership. |
| Aquera Agentic AI Bridge | Hosted | An MCP gateway for ADP Workforce Now and Lyric that ChatGPT, Claude, Gemini, Microsoft 365 Copilot and Perplexity use as standard MCP clients. Each request is authenticated through your identity provider, authorized against the person’s own ADP entitlements and logged with who asked, what ran and what changed. | It performs governed writes as well as reads (updating an address, requesting time off or running ADP workflows), so decide which workflows to allow. Aquera doesn’t list pricing on its ADP page, and requests pass through its bridge. |
| Custom ADP MCP server | Custom | Payroll-safe tools built for your questions (headcount, time off, payroll totals) on your own API Central project, with field allowlists, per-person scoping from your identity provider, approvals for any pay data write and hosting in your own cloud. | Needs an API Central subscription or a Marketplace partnership, an ADP-signed certificate, and upkeep of token handling, throttling and API changes. RUN isn’t on API Central’s supported list. |
Tools a ADP MCP server should expose
Start with read-only tools and add write actions once the team trusts the answers. Every write action below runs with a confirmation or approval step.
| Tool | Access | Risk | Purpose | Guard |
|---|---|---|---|---|
get_headcount | Read | Low | Active headcount by company, department or location. | Counts only, never names; any group smaller than a set minimum is hidden. |
find_worker | Read | Medium | Look up a worker’s name, job title, department, manager, work location and status. | Allowlisted fields only; never returns government IDs, birth date, home address, direct-deposit or tax data. |
get_time_off_balances | Read | Medium | Time-off balances and approved upcoming leave for a worker or a team. | Limited to the caller’s own record, their direct reports or their HR population; leave reasons are never returned. |
list_upcoming_new_hires | Read | Low | People starting in the next 30 days, with position and start date. | Names, positions and start dates only; no onboarding documents, tax forms or identity data. |
get_payroll_totals | Read | Medium | Totals for a completed payroll (gross, deductions and net) by company or department, read from Payroll Outputs. | Aggregates only, never per-worker pay statements; payroll or finance role required. |
get_base_pay | Read | High | Show one worker’s current base rate to an authorized HR or payroll user. | HR or payroll role required; current rate only, no history or pay statements; every call is logged. |
submit_time_off_request | Write | Medium | Create a time-off request for the signed-in employee. | Employees file only for themselves and confirm the dates first; the manager still approves in ADP. |
stage_pay_data_input | Write | High | Add approved hours, bonuses or reimbursements to the pay data batch for the current payroll cycle. | Shows totals per worker and earnings code, then needs approval by a payroll admin; one idempotency key per batch; blocked after the payroll cutoff; no deduction or tax changes. |
Connect it to Claude, ChatGPT or Copilot Studio
Claude
Add a hosted ADP server or your own as a custom connector using its remote URL; for OAuth, enter the client ID and secret under Advanced settings. On Team and Enterprise plans an Owner adds custom connectors and each person then connects individually. Calls come from Anthropic’s cloud, so a server on a private network must allowlist Anthropic’s IP ranges. Keep pay data tools off when using Research, which can call connector tools without asking each time.
ChatGPT
Turn on developer mode and add the server as a ChatGPT plugin (Pro, Plus, Business, Enterprise and Education on the web; on Enterprise and Education an admin grants developer-mode access and enables plugins by role). Developer mode accepts OAuth or no authentication rather than a static token, and it asks for confirmation on tools without a readOnlyHint, so mark lookups read-only. ADP’s client secret, certificate and private key stay on the MCP server; use Secure MCP Tunnel if the server must stay private.
Microsoft Copilot Studio
Add the server with the MCP onboarding wizard on the agent’s Tools page, over Streamable HTTP (Copilot Studio doesn’t support SSE) with OAuth 2.0, so each person signs in with your company identity and the server maps them to the ADP records they may see. Generative orchestration must be on, and Power Platform data policies govern the connection. For employee self-service, ADP’s own ADP Assist app already brings ADP into Microsoft Teams and Microsoft 365 Copilot for companies that use ADP Assist.
Claude implementation · Copilot implementation · ChatGPT implementation
Permissions, identity and audit
- An API Central project issues a client ID and secret and uses a certificate that ADP signs from your certificate signing request. Keep all three on the MCP server in a secrets manager, never in the AI client, since ADP advises keeping these credentials under strict control.
- A data connector reaches ADP as one system user in the practitioner role, so ADP can’t tell which person asked. The MCP server must map each signed-in person (from Entra ID or another identity provider) to what they may see: HR their population, managers their direct reports, employees their own record.
- Choose only the APIs your tools need when you set up the project; calls outside the token’s scope fail with 403 insufficient_scope. Leave Worker Pay Distributions, US Tax Profiles and the government ID APIs out entirely.
- For a server distributed through ADP Marketplace, the customer approves access after purchase and can block it in ADP Consent Manager at any time, so the server should fail closed on a 401 or 403 rather than retry with other credentials.
- Log every call with the user, the tool and the ADP associate IDs touched, not the data returned, and review the log with HR and payroll.
- Keep SSNs and other government IDs, bank and direct-deposit details, tax withholding and full pay statements out of every tool response; workflows that need them stay in ADP.
Hosting and network
- Hosted options run the MCP server in the vendor’s cloud and may hold your ADP credentials there (Apideck’s setup, for one, takes your client secret, certificate and private key); check each vendor’s data processing terms and where logs are kept.
- A custom server runs in your AWS or Azure account and calls api.adp.com over mutual TLS, with the certificate, private key and client secret in a secrets manager. ADP may tie tokens to the environment that requested them, so send traffic through fixed egress IP addresses.
- Claude and ChatGPT reach the MCP server from their own clouds, so publish it behind authentication and an allowlist, or keep it private with ChatGPT’s Secure MCP Tunnel.
- Stay under ADP’s limits (for an API Central project, under 120 calls a minute and 10 at once): reuse each token for its 60-minute life, as ADP asks, and cache reference data such as departments and validation tables.
- Use ADP events to keep caches fresh: ADP recommends treating a notification as a trigger and reading the current record. Webhooks need a public US endpoint that checks ADP’s HMAC signature, while polling the queue works from a private network.
Cost and timeline
- ADP API Central is priced per employee per month and, according to ADP, can be bought online and activated within minutes. Hosted servers add their own pricing: Knit charges by integrated accounts or API call volume and Unified.to by usage, both with a 30-day free trial.
- A focused read-only ADP MCP server with payroll-safe tools typically takes two to four weeks including security and evaluation, once API Central is active. Software vendors should allow more time on ADP’s side, since Marketplace partners go through an application review, security and legal reviews and a sandbox agreement.
- Write tools (pay data input, time off) and multi-system work (ADP plus an ERP, a time system or an applicant tracking system) take longer and are scoped after a short discovery.
ADP MCP questions
Does ADP have an MCP server?
No. As of September 2026 ADP hasn’t published an MCP server, and the official MCP Registry has no ADP entry. The address mcp.apps.adp.com is unrelated: it redirects to an ADP Marketplace site described as ADP Multi-Country Payroll. ADP’s own AI is ADP Assist, which works in ADP’s products and, through an ADP Marketplace app, in Microsoft Teams and Microsoft 365 Copilot.
Is there a free ADP MCP server?
Not a maintained one that we found on September 27, 2026. CData’s MIT-licensed adp-mcp-server-by-cdata on GitHub is a local, read-only server, last updated in October 2025, that needs CData’s licensed JDBC driver for ADP, and most other "ADP MCP" projects share the acronym but have nothing to do with ADP payroll. Hosted servers offer trials (Knit and Unified.to list 30 days), and every route still needs API access from ADP, through the paid API Central add-on or a Marketplace partner’s app.
Can an MCP server run payroll in ADP?
It can prepare payroll inputs, but we keep the payroll run and its approval in ADP. Workforce Now’s Pay Data Input API adds earnings, deductions or reimbursements to a pay data batch for a payroll cycle, RUN’s version records one-time payroll changes for a worker, and Payroll Outputs reads the results of a run. Any pay data tool we build shows totals first, needs approval by a payroll admin, uses one idempotency key per batch and stops at the payroll cutoff.
Does it work with Claude, ChatGPT or Copilot?
Yes. A hosted or custom ADP server connects to Claude as a custom connector, to ChatGPT in developer mode and to Copilot Studio over Streamable HTTP, and the ADP credentials stay on the server. ADP’s own ADP Assist also appears in Microsoft Teams and Microsoft 365 Copilot for companies that use it, but ADP ships it as a Teams app, not as an MCP server.
What do I need from ADP for API access?
For Workforce Now, Workforce Now Next Generation, Vantage HCM, Enterprise HR or Lyric, a subscription to ADP API Central, which ADP prices per employee per month. In API Central you generate a mutual TLS certificate and create a project that gives you client credentials; software vendors instead join the ADP Marketplace partner program and sign a sandbox agreement. RUN isn’t on API Central’s list, so ask ADP how to reach RUN data, and expect some hosted platforms to need your credentials too: Apideck asks for your client ID, secret, certificate and private key.
How is payroll data protected?
By design, not by prompt. Tools return allowlisted fields only, never SSNs or other government IDs, direct-deposit or bank details, tax withholding or full pay statements, and the APIs behind those fields stay out of the project’s scope. The server maps each person to the records they may see, aggregates hide small groups, and logs record who asked for what without storing the answers.
Hosted or custom?
Hosted servers are the quickest route to a pilot, and Aquera’s bridge runs each request under the person’s own ADP permissions. Several hosted catalogs also include direct-deposit changes, terminations or pay statements, so limit actions and fields before anyone connects an assistant. A custom server fits when HR needs payroll-safe tools, hosting in your own cloud and approvals tied to your payroll roles. AIONDATA is an independent provider, not an ADP partner, so we will say when a hosted option is enough.