Skip to content
Business productivity ⇄ Human resources

Agiloft to Hibob integration — real-time, two-way sync

Keep Agiloft and Hibob in sync without custom scripts. Cut weeks of integration work, eliminate silent data drift, and give your team a single, reliable source of truth.

  • SOC 2 and 6 other compliance frameworks
  • POC with real engineers in minutes

Adopted by fast-scaling companies moving mission-critical data in real time

Case study
Migrated from MuleSoft
Case study
Migrated from Celigo
Migrated from Heroku Connect
Migrated from Matillion
Case study
Migrated from Fivetran
Case study
Migrated from Celigo
Why teams connect Agiloft and Hibob

Keep the people, teams, and status that Agiloft and Hibob share aligned in real time, so a hire, role change, or departure recorded in one reaches the other within seconds.

Each tool in Agiloft keeps its own list of who can use it: users, members, or agents, along with the team they sit on and whether they are still active. Hibob is the authoritative record of the same people as employees, with their department, manager, and employment status. When those two are connected only by manual account admin or a periodic export, the work tools drift: new hires wait days for access, team and manager changes never catch up, and people who have left keep standing accounts.

Stacksync syncs Approvals, Tasks, Clause Library, Custom tables in Agiloft with Named lists, People (Employees), Employment, Work in Hibob bi-directionally and in real time. A person added, moved, or offboarded in Hibob creates or updates the matching user in Agiloft within seconds, with field-level mapping and conflict resolution in place of spreadsheets and one-off account changes. Where Agiloft captures details of its own, such as a corrected contact or a login identity, those can flow back to Hibob in whichever direction you configure.

Because the sync is field-level, each system keeps its own extras; only the shared facts, who a person is, which team they belong to, and whether their access should be on, are held in agreement.

Common use cases

  • 01 Stream Approvals and Tasks into an operational database for cycle-time, bottleneck, and SLA reporting across the contract lifecycle.
  • 02 Write contract or company records into Agiloft when a deal closes in the CRM to kick off downstream legal and procurement workflows.
  • 03 Push Salaries and Variable Pay from Bob into a payroll provider or warehouse each pay cycle, using the Payroll-permitted service user.
  • 04 Mirror Work data (department, site, manager, title) into an org-chart or reporting warehouse for headcount and structure analysis.

Common sync patterns

Offboarding: no standing access after a departure

When someone is marked as leaving in Hibob, the matching account in Agiloft is deactivated or flagged, so departures do not leave open access behind.

One employee directory

A person's name, title, contact details, or status corrected in either system updates the other, so both sides stop maintaining separate copies of the same person.

Org and team structure kept current

Department, team, and reporting-line changes from Hibob keep the groups, queues, or projects in Agiloft assigned to the right people.

What you can sync between Agiloft and Hibob

Representative objects on each side — any object or custom field can map to any target. Schemas are auto-detected; types are converted between the two systems.

Agiloft objects Hibob objects How this pairing syncs
Custom tables Agiloft is a no-code platform, so any customer-built table (NDAs, SOWs, vendor risk, renewals) exposes the same REST and SOAP CRUD and syncs like the standard CLM tables. Salaries Compensation history at /people/{id}/salaries; full CRUD but gated behind the Payroll permission on the service user. Custom tables is specific to Agiloft and Salaries to Hibob — each maps to any object or custom field on the other side.
Contracts The core table holding contract records with value, key dates, status, type, and linked parties; created and updated two-way so contract data moves between Agiloft and a database, ERP, or CRM. Time off Absence requests and who's-out data via /timeoff/employees/{id}/requests and /timeoff/whosout; submit new requests and read balances. Contracts is specific to Agiloft and Time off to Hibob — each maps to any object or custom field on the other side.
Companies Records for every organization - counterparties, vendors, customers - linked to contracts and people; read and written to keep account master data aligned with a CRM or ERP. Lifecycle Hire, termination, and leave status changes at /people/{id}/lifecycle; read-only and the source of lifecycle webhook events. Companies is specific to Agiloft and Lifecycle to Hibob — each maps to any object or custom field on the other side.
People Parent table for individuals, split into Employees (internal users) and Contacts (external company contacts); synced to map signers, approvers, and account owners to CRM or HR records. Documents Employee documents accessed under the Docs API; gated behind the Documents permission granted per service user. People is specific to Agiloft and Documents to Hibob — each maps to any object or custom field on the other side.
Attachments File records holding the executed contract PDFs and supporting documents linked to a contract; read to pull signed files out, or written to push generated documents in. Named lists Dropdown option lists such as departments and sites used to resolve field values when mapping People records during sync. Attachments is specific to Agiloft and Named lists to Hibob — each maps to any object or custom field on the other side.
Approvals Per-record approval instances generated from Approval Templates and Workflows; read to report approval status and cycle time, or written to trigger and record decisions. People (Employees) Core employee records with out-of-the-box and custom fields; read via POST /people/search, created and updated through the /people endpoints. Approvals is specific to Agiloft and People (Employees) to Hibob — each maps to any object or custom field on the other side.

How changes propagate between Agiloft and Hibob

Each direction of the sync is driven by what the source system can signal and what the destination accepts — detection, delivery, and expected latency below.

Agiloft Hibob Sub-second propagation

DetectionAgiloft notifies Stacksync of record changes through webhook events. Native webhook subscriptions (POST /ewws/webhooks) fire on record create, edit, or delete after a GET handshake verifies the callback URL.

DeliveryEach detected change is written to Hibob through its API, with automatic retries and rate-limit backoff.

Hibob Agiloft Sub-second propagation

DetectionHibob notifies Stacksync of record changes through webhook events. Webhooks fire for employee created/updated/deleted, table-entry created/updated, time off, and lifecycle events.

DeliveryEach detected change is written to Agiloft through its API, with automatic retries and rate-limit backoff.

Rate-limit considerations

  • Agiloft: Agiloft publishes no fixed per-minute REST quota; throughput is instance-specific and bounded by license seats (Assigned/Floating Power User) and concurrent API sessions. Each SOAP/EWS call runs in its own transaction, and REST logins issue a session token meant to be reused rather than re-authenticated per call.
  • Hibob: Rate limits are enforced per service user; violations return HTTP 429 with X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset response headers. The docs list POST /people/search at 50 requests per minute, and bulk /people/search is preferred over per-record reads.
What ships with Agiloft ⇄ Hibob

Connect Agiloft and Hibob for flexible, real-time data sync.

Real-time sync, workflow automation, event queues, EDI, and monitoring, for every Agiloft–Hibob connection.

Real-time

Two-way sync

Changes in Agiloft or Hibob instantly reflect in both systems. No stale data, no manual imports.

No-code + pro-code

Workflow automation

Trigger automated workflows whenever Agiloft or Hibob data changes, update records, fire webhooks, or kick off sequences without brittle API scripts.

At scale

Event queues

Handle millions of events per minute without losing a single Agiloft or Hibob record.

Observability

Monitoring

Track your Agiloft ⇄ Hibob sync health, view errors, and replay failed events in one click.

Trading partners

EDI

Transform legacy EDI complexity into simple database interactions between Agiloft and Hibob.

How the Agiloft and Hibob connectors work

Agiloft

Integration surface
REST API (/ewws/rest/{kb}) and SOAP/EWS v2 web services (EWWSv2Service WSDL), plus a native Webhooks subscription API
Authentication
OAuth 2.0 via OAuth2 Client Setup - Authorization Code with PKCE for user-delegated apps and Client Credentials for machine-to-machine; also JWT tokens or Basic Auth with a session token from POST /ewws/rest/{kb}/login
Change detection
Native webhook subscriptions (POST /ewws/webhooks) fire on record create, edit, or delete after a GET handshake verifies the callback URL; otherwise poll each table by its Date Updated / modified-time fields. Agiloft has no database change-data-capture log.
Capabilities
read · write · webhooks
Rate limits
Agiloft publishes no fixed per-minute REST quota; throughput is instance-specific and bounded by license seats (Assigned/Floating Power User) and concurrent API sessions. Each SOAP/EWS call runs in its own transaction, and REST logins issue a session token meant to be reused rather than re-authenticated per call.

Hibob

Integration surface
REST API (the Bob API)
Authentication
Service User credentials over HTTP Basic auth (Base64-encoded serviceUserId:serviceUserToken); permissions granted per data category (People, Payroll, Documents) in Bob admin
Change detection
Webhooks fire for employee created/updated/deleted, table-entry created/updated, time off, and lifecycle events; the employee.updated payload flags which fields changed and Bob recommends an API call for the full record. There is no CDC stream, and deleting a table entry fires no webhook (Bob has no table-entry deletion event).
Capabilities
read · write · webhooks
Rate limits
Rate limits are enforced per service user; violations return HTTP 429 with X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset response headers. The docs list POST /people/search at 50 requests per minute, and bulk /people/search is preferred over per-record reads.
Hibob setup guide
How it works

How to connect Agiloft to Hibob — three steps, no code

Configure and sync within minutes, no code. Whether you sync 50k or 100M+ records, Stacksync handles the queues, infra, and plumbing. Integrations are non-invasive and need zero setup on your systems.

  1. 01

    Connect your apps

    Authenticate Agiloft and Hibob with each platform's native method — OAuth, API keys, or service accounts — plus secure options like SSH tunneling, IP whitelisting, and VPC peering.

    • OAuth 2.0
    • SSH tunnel
    • VPC peering
    Agiloft connected
    Hibob connected
    OAuth 2.0
    SSH tunnel
    SSL certificate
    VPC peering
  2. 02

    Choose tables

    Pick the Agiloft and Hibob objects to sync — Stacksync auto-detects both schemas, including custom fields where the platform exposes them. Sync to existing tables, or let Stacksync create new ones with ideal data types.

    • Standard objects
    • Custom objects
    • Auto-schema
    objects · Agiloft ⇄ Hibob
    Customers 12,480
    Sales Orders 8,213
    Invoices 5,902
    Items 1,344
  3. 03

    Map fields

    Fields map automatically even when names and types differ. Stacksync handles transformation and type casting for you, zero configuration required.

    • Auto-map
    • Type casting
    • Transforms
    Agiloft Hibob
    Company company_name text
    Email email text
    Amount amount numeric
    Created created_at timestamp
FAQ

Agiloft and Hibob integration FAQ

SECURITY

Security teams trust Stacksync

As a data company, we understand the importance of keeping your data secure. Stacksync is built with security best practices to keep your data safe at every layer, and is DPF-certified for US, EU, UK and CH data transfers.

SOC 2 Type II
ISO 27001
HIPAA BAA
GDPR
CCPA
DPF US-EU-UK-CH
→ SECURITY WITH BENEFITS

SSO & SCIM

Let your users access Stacksync from your centralized user management systems. Works with Okta, Azure, Google SSO and more.

Alerts

Immediately get alerted about record syncing issues over email, Slack, PagerDuty and WhatsApp. Resolve issues from a centralized dashboard with retry and revert options.

Secure connection options

Securely connects to your systems with:

Related integrations

Every pair below is a real-time, two-way sync. Search all 407 integrations available for Agiloft and Hibob.

Popular · 6 of 407
Coworkers laughing in front of a laptop in a casual office setting

Your last integration took months.
Your next one takes a prompt.