Workday Advanced Compensation · Authentication Profile

Workday Advanced Compensation Authentication

Authentication

Workday Advanced Compensation secures its APIs with oauth2 across 4 declared security schemes, as derived from its OpenAPI definitions. OAuth 2.0 is offered via the implicit, authorizationCode, and clientCredentials flow(s).

CompensationHuman ResourcesPayrollHCMEnterprise SoftwareTotal RewardsBonusMeritStock CompensationSOAPSoftware-as-a-Service
Methods: oauth2 Schemes: 4 OAuth flows: implicit, authorizationCode, clientCredentials API key in:

Security Schemes

OAuth2 oauth2
· flows: implicit
OAuth2 Authorization Code oauth2
· flows: authorizationCode
OAuth2 Client Credentials (Integration System User) oauth2
· flows: clientCredentials
WS-Security UsernameToken http
scheme: ws-security

Source

Authentication Profile

Raw ↑
generated: '2026-09-17'
method: searched
source: openapi/_original/workday-advanced-compensation-compensation-v3-openapi.json
docs: https://developer.workday.com/doc/axp1537909839739.md
summary:
  types:
  - oauth2
  oauth2_flows:
  - implicit
  - authorizationCode
  - clientCredentials
  api_key_in: []
  note: >-
    OAuth 2.0 only. Workday's published compensation OpenAPI declares a single OAuth2 scheme with
    the implicit flow against a templated tenant authorization host; the developer documentation
    documents Authorization Code (user-context apps) and Client Credentials with an Integration
    System User (server-to-server) as the supported grants. The SOAP Workday Web Services surface
    additionally accepts WS-Security UsernameToken with an ISU account.
schemes:
- name: OAuth2
  type: oauth2
  flows:
  - flow: implicit
    authorizationUrl: https://<tenantAuthorizationHostname>
    scopes: 0
  description: >-
    Declared verbatim in Workday's published compensation v1/v2/v3 OpenAPI documents. The
    authorization host is tenant-specific and is left templated by Workday.
  sources:
  - openapi/_original/workday-advanced-compensation-compensation-v3-openapi.json
  - openapi/_original/workday-advanced-compensation-compensation-v2-openapi.json
  - openapi/_original/workday-advanced-compensation-compensation-v1-openapi.json
- name: OAuth2 Authorization Code
  type: oauth2
  flows:
  - flow: authorizationCode
  description: Documented grant for apps acting in a signed-in Workday user's context.
  sources:
  - https://developer.workday.com/doc/jzx1537909761291.md
- name: OAuth2 Client Credentials (Integration System User)
  type: oauth2
  flows:
  - flow: clientCredentials
  description: >-
    Documented grant for server-to-server integrations. The API Client is registered in the
    tenant and bound to an Integration System User whose security groups carry the domains the
    operations name (e.g. "Set Up: Merit and Bonus").
  sources:
  - https://developer.workday.com/doc/axp1537909839739.md
- name: WS-Security UsernameToken
  type: http
  scheme: ws-security
  description: >-
    Workday Web Services (SOAP) authentication for the Compensation and Compensation_Review
    WSDLs, using an Integration System User account scoped to the tenant.
  sources:
  - wsdl/workday-advanced-compensation-compensation.wsdl
gateways:
  note: >-
    Workday Extend / Workday Cloud Platform API gateway and authorization base URLs are
    region-specific and published by Workday.
  source: https://developer.workday.com/doc/dlh1653340161856.md
  regions:
  - region: United States
    api_gateway: https://api.workday.com
    authorization_base_url: https://auth.api.workday.com
  - region: Germany
    api_gateway: https://api.eu.wcp.workday.com
    authorization_base_url: https://api.eu.wcp.workday.com/auth
  - region: Singapore
    api_gateway: https://api.sg.wcp.workday.com
    authorization_base_url: https://api.sg.wcp.workday.com/auth
  - region: United Kingdom
    api_gateway: https://api.uk.wcp.workday.com
    authorization_base_url: https://api.uk.wcp.workday.com/auth

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/workday-advanced-compensation-authentication"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.