Nmbrs Companies API

Company (employer) records within a Nmbrs environment.

OpenAPI Specification

nmbrs-companies-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: Nmbrs Public REST API (HR & Payroll) Absences Companies API
  description: 'Modeled OpenAPI for the Visma Nmbrs public REST API - the current, forward-looking interface to Nmbrs HR and payroll software (Netherlands and Sweden). The REST API is served from https://api.nmbrsapp.com and is authenticated with the OAuth 2.0 Authorization Code flow (identityservice.nmbrs.com) plus a per-product subscription key sent on every request. It exposes HRIS and payroll resources - companies, employees, employments, personal and salary info, wage components, payruns, and absences - scoped by granular OAuth scopes such as employee.info, employee.employment, and employee.payment.

    HONESTY NOTE: The Nmbrs REST API reference is published as an interactive Stoplight project rather than a downloadable OpenAPI file, and the live endpoints are gated behind OAuth + a subscription key (GET https://api.nmbrsapp.com/api/companies returns 401 unauthenticated). The paths, parameters, and schemas below are MODELED from the published resource groups and the confirmed base URL / auth model; they are a faithful representation for discovery, not a byte-for-byte copy of the vendor spec. Nmbrs also operates a separate, older SOAP API (api.nmbrs.nl/soap/v3, EmployeeService / CompanyService / DebtorService) that is deprecated and scheduled to be retired on 1 March 2027 - it is described in the repository README and review, not in this REST document.'
  version: 1.0-modeled
  contact:
    name: Nmbrs Developer Portal
    url: https://developer.nmbrs.com
servers:
- url: https://api.nmbrsapp.com
  description: Nmbrs Public REST API
security:
- oauth2: []
  subscriptionKey: []
tags:
- name: Companies
  description: Company (employer) records within a Nmbrs environment.
paths:
  /api/companies:
    get:
      operationId: listCompanies
      tags:
      - Companies
      summary: List companies
      description: Lists the companies (employers) accessible to the authenticated subscription.
      responses:
        '200':
          description: A list of companies.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/Company'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    Company:
      type: object
      properties:
        id:
          type: string
        name:
          type: string
        number:
          type: integer
        phase:
          type: string
  responses:
    Unauthorized:
      description: Missing or invalid OAuth token or subscription key.
      content:
        application/json:
          schema:
            type: object
            properties:
              statusCode:
                type: integer
                example: 401
              message:
                type: string
                example: Access denied due to invalid subscription key or bearer token.
  securitySchemes:
    oauth2:
      type: oauth2
      description: OAuth 2.0 Authorization Code flow via identityservice.nmbrs.com.
      flows:
        authorizationCode:
          authorizationUrl: https://identityservice.nmbrs.com/connect/authorize
          tokenUrl: https://identityservice.nmbrs.com/connect/token
          scopes:
            employee.info: Read/write employee personal information
            employee.info.read: Read employee personal information
            employee.employment: Read/write employment data
            employee.employment.read: Read employment data
            employee.payment: Read/write salary and payment data
    subscriptionKey:
      type: apiKey
      in: header
      name: X-Subscription-Key
      description: Per-product subscription key generated in the Nmbrs developer portal, required on every request in addition to the OAuth bearer token.