Authenticate to UKG Pro WFM API using OAuth 2.0 without appkey

domain: developer.ukg.com · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Register your application in the UKG developer portal and obtain client credentials.
  2. POST to the tenant OAuth token endpoint with your client_id and client_secret to obtain a Bearer access token.
  3. Include the token in the Authorization header of every WFM API request: Authorization: Bearer YOUR_TOKEN.
  4. Omit any appkey header or query parameter — as of 2024.R1 the appkey is no longer required and is ignored if present.
  5. Refresh the access token before it expires using the same token endpoint; do not cache indefinitely.

Known gotchas

Related routes

Authenticate to the ProdataKey (PDK) API and remotely open a door device
developer.pdk.io · 5 steps · unrated
Authenticate to UKG Pro SOAP-based web services using a Web Service Account for the Employee New Hire service
developer.ukg.com · 5 steps · unrated
Pull employee data from UKG Pro using the Personnel API
developer.ukg.com · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans