Skip to content
Recruit Swipe

Docs / Using Recruit Swipe

Connect your ATS

Where to find the API credential in each supported system, and what else Recruit Swipe asks for when you connect it.

Every connection needs one credential, and some need one extra detail. This page says where each one lives. If your provider is not here, check the integrations list — it may be in development or waiting on partner access.

Your credential is encrypted the moment it arrives and is only ever decrypted inside the server function making a call on your behalf. It is never stored on your phone. See security for the detail.

Greenhouse

  • You need: a Harvest API key, plus your own Greenhouse user id.
  • Key: Configure → Dev Center → API Credential Management. You need the “manage all organization’s API credentials” permission. Grant read scopes for jobs, applications, candidates, job stages, and tags, and write scopes for move, reject, notes, and tags.
  • User id: People → your own name → the number at the end of the URL. Greenhouse attributes every write to a real user, so this is what keeps your audit trail honest.

Ashby

  • You need: an API key.
  • Key: Settings → Integrations → Developer API. Scopes: candidates read and write, jobs read, interviews read, hiring process metadata read.
  • Ashby archives rather than rejects, and we could not verify that endpoint from the public docs, so reject is not offered on Ashby connections.

Lever

  • You need: an API key.
  • Key: Settings → Integrations and API → API Credentials → Generate a new API key. Grant read on postings, opportunities, stages, and tags, and write on opportunities.
  • Lever stages are global to the account rather than per-posting, so the stage you pick applies everywhere.

Workable

  • You need: an access token and your account subdomain.
  • Key: profile icon → Settings → Integrations → Apps → API Access Tokens → Generate API token. Scopes: read jobs, read candidates, read stages, write candidates, write comments.
  • Subdomain: the first part of your Workable URL.
  • Workable tokens expire on a schedule you choose when creating them, up to two years. Pick the longest your policy allows and note the renewal date.

Recruitee

  • You need: a personal API token and your numeric company id.
  • Key: Settings → Apps and plugins → Personal API tokens → New token. The company id is shown next to the token.

BambooHR

  • You need: an API key and your company subdomain.
  • Key: user menu → API Keys → Add New Key. The key owner needs access to ATS settings.
  • Subdomain: the first part of your BambooHR URL.
  • Your account needs the hiring module enabled, or the candidate endpoints return nothing.

SmartRecruiters

  • You need: an OAuth client id and client secret.
  • Key: your administrator creates these in Credential Manager → New Credential → OAuth client. Scopes are fixed when the credential is created, so include candidate read and status write.
  • This is a server-to-server credential — there is no redirect or consent screen to click through.

Teamtailor

  • You need: an admin API key.
  • Key: Settings → Integrations → API keys, as a company admin. Create an Admin read/write key.
  • Teamtailor connections support stage changes and rejection. Notes need a Teamtailor user id to attribute to and there is no tag vocabulary endpoint, so neither is offered.
  • Accounts on the North America host are not supported yet.

JazzHR

  • You need: an API key.
  • Key: your JazzHR account settings. API access is gated to higher plan tiers.
  • JazzHR connections are read-only for now — you can source and grade, but nothing is written back.

Manatal

  • You need: an API token.
  • Key: Admin → API. API access requires Manatal’s top plan tier and may need enabling by their support team.
  • Manatal connections are read-only for now.

Connecting more than one

You can connect several sources; the number depends on your plan. Each connection carries its own swipe configuration, because the same gesture rarely means the same thing in two different systems.

Removing a connection

Delete it from the connection screen. The encrypted credential is destroyed in the same transaction, and the cached candidates and requisitions go with it. Your swipe history stays, because it is your record of what you did.