# Workday

![workday-1.png](https://assets.relyanceuat.xyz/images/docs/28748092106509/28748092103181.png)
Workday is a cloud-based software program for human resources (HR) designed to simplify workforce management. You can do everything with Workday from managing employee information, managing employee schedules, to processing payroll.

Relyance AI supports two authentication types for connecting to Workday:

### **Oauth2:**

In order to integrate Workday with Relyance AI you will need your **Tenant ID**, **Rest API Base Endpoint**, **Token Endpoint**, **Authorization Endpoint**, **Client ID**, **Client Secret**, and follow an **OAuth2** flow.

#### In Workday:

1. Login to your Workday account.
2. Find the 'Register API Client' page using the search feature.
3. Register API Client:
    1. **Select grant type**: Authorization Code Grant
    2. **Select access token type**: Bearer
    3. Select **Non-Expiring Refresh Tokens** checkbox
    4. Select the following **Scopes**:
        - Contact Information
        - Academic Foundation
        - Core Payroll
        - Customer Accounts
        - Customers
        - Procurement
        - Project Billing
        - Personal Data
        - Recruiting
        - Staffing
        - Student Core
        - System
        - Talent Pipeline
        - Workday Designer
        - Integration Build
        - Integration Process
    5. For the **Redirect URI**, use: [https://root.relyance.ai/api/oauth2](https://root.relyance.ai/api/oauth2)
    6. Click **OK** to save the API client
4. Once this is done, open up the client and copy the following values to be used in Relyance:
    - Tenant ID
    - Client ID
    - Client Secret
    - Workday REST API Endpoint
    - Token Endpoint
    - Authorization Endpoint

#### In the Relyance AI application:

1. Login to your Relyance account.
2. Navigate to the **Settings** Menu in the bottom left-hand side.
3. Select **Integrations**.
4. Click on the **Vendor** filter.
5. Find the **Workday** integration card and click it to open its connections.
6. On the **Authentication** step, pick the method under **Authentication Method**.
7. Choose **Oauth2**
8. Paste the **Tenant ID, Rest API Base Endpoint**, **Token Endpoint**, **Authorization Endpoint**, **Client ID**, **Client Secret** into their respective fields.

The REST API endpoints needs to be the BASE endpoint, all other endpoints need to be the full endpoint.

For example If the given URL is:
[https://boutique.workday.com/ccx/api/v1/boutique](https://boutique.workday.com/ccx/api/v1/boutique)

You only need to extract and use:
[https://boutique.workday.com](https://boutique.workday.com/ccx/api/v1/boutique)

1. Additional Features:
    - Select the **Enable Data Inspection** checkbox if you wish Relyance also to inspect the data. For more information on Relyance features, please refer to this help center article: [here](/docs/introduction-to-relyance-ai/integration-features/#h_01J01Z9X7W2ZN71X9XEB3JR8KZ).
2. Click **Authenticate**.
3. At this point, you should see the following result on the integrations page:
4. Congratulations, you are now connected to **Workday**.

### **Custom:**

In order to integrate Workday with Relyance AI you will need your **Tenant ID**, **Rest API Base Endpoint**, **Token Endpoint**, **Refresh Token**, **Client ID**, **Client Secret**, and follow an **OAuth2** flow.

#### In Workday:

1. Login to your Workday account.
2. Find the 'Register API Client for Integrations' page using the search feature.
3. Register API Client:
    1. **Select grant type**: Authorization Code Grant
    2. **Select access token type**: Bearer
    3. Select **Non-Expiring Refresh Tokens** checkbox
    4. Select the following **Scopes**:
        - Contact Information
        - Academic Foundation
        - Core Payroll
        - Customer Accounts
        - Customers
        - Procurement
        - Project Billing
        - Personal Data
        - Recruiting
        - Staffing
        - Student Core
        - System
        - Talent Pipeline
        - Workday Designer
        - Integration Build
        - Integration Process
    5. Use the **View API Client for Integrations** to generate a refresh token.
        - Select the newly created API client, and go to **API Client Actions > API Client > Manage Refresh Tokens for Integration**.
        - Select the Workday Account for which the refresh token must be generated, and then select **Next**.
        - Select the **Generate New Refresh Token** checkbox, and then select **OK**.
    6. For the **Redirect URI**, use: [https://root.relyance.ai/api/oauth2](https://root.relyance.ai/api/oauth2)
    7. Click **OK** to save the API client
4. Once this is done, open up the client and copy the following values to be used in Relyance:
    - Tenant ID
    - Client ID
    - Client Secret
    - Workday REST API Endpoint
    - Token Endpoint
    - Refresh Token

#### In the Relyance AI application:

1. Login to your Relyance account.
2. Navigate to the **Settings** Menu in the bottom left-hand side.
3. Select **Integrations**.
4. Click on the **Vendor** filter.
5. Find the **Workday** integration card and click it to open its connections.
6. On the **Authentication** step, pick the method under **Authentication Method**.
7. Choose **Custom**
8. Paste the **Tenant ID**, **Rest API Base Endpoint**, **Token Endpoint**, **Refresh Token**, **Client ID**, **Client Secret** into their respective fields.

![Screenshot 2025-06-11 205543.png](https://assets.relyanceuat.xyz/images/docs/28748092106509/37298505538445.png)

![Screenshot 2025-06-11 210333.png](https://assets.relyanceuat.xyz/images/docs/28748092106509/37298505540621.png)

The REST API endpoints needs to be the BASE endpoint, all other endpoints need to be the full endpoint.

For example If the given URL is:
[https://boutique.workday.com/ccx/api/v1/boutique](https://boutique.workday.com/ccx/api/v1/boutique)

You only need to extract and use:
[https://boutique.workday.com](https://boutique.workday.com/ccx/api/v1/boutique)

1. Additional Features:
    - Select the **Enable Data Inspection** checkbox if you wish Relyance also to inspect the data. For more information on Relyance features, please refer to this help center article: [here](/docs/introduction-to-relyance-ai/integration-features/#h_01J01Z9X7W2ZN71X9XEB3JR8KZ).
2. Click **Authenticate**.
3. At this point, you should see the following result on the integrations page:
4. Congratulations, you are now connected to **Workday**.

![Workday-3.png](https://assets.relyanceuat.xyz/images/docs/28748092106509/28748282547853.png)

### Verify the connection is really working

Workday is the integration where a correct-looking configuration most often returns
nothing, for two reasons that are specific to Workday.

1. **A pending security policy change.** Granting the integration system user its
   domain permissions is not live until you run **Activate Pending Security Policy
   Changes** in Workday. Until then every request is authorised against the old
   policy, so the connection authenticates and returns empty results with no error.
   This is the single most common cause of an empty Workday scan.
2. **The three endpoints are tenant- and datacenter-specific.** **Rest API
   Endpoint**, **Token Endpoint** and **Authorization Endpoint** all carry your
   tenant name and your Workday host (`wd2-impl`, `wd5`, and so on). Copying them
   from another tenant's runbook produces an authentication failure that reads like
   bad credentials.
3. **Domain security policies decide what you see.** The integration requests access
   to Workday domains — Personal Data, Staffing, Core Payroll, Contact Information,
   Recruiting and others. A domain the ISU cannot reach is omitted from the results
   rather than reported, so a missing data category usually means a missing domain
   grant.
4. **Results capped at Maximum Number of Records.** The default is 5000 per object.
   A tenant larger than that returns a truncated picture that looks like a complete
   one; raise it if your object counts exceed it.

<!-- auth-methods:begin (generated from the integration catalog; do not hand-edit) -->

## Authentication methods and fields

Pick one of these under **Authentication Method** on the connection wizard's **Authentication** step. This table is generated from the integration catalog, so it always matches what the form actually asks for.

| Method | Required | Optional |
| --- | --- | --- |
| **Oauth2** | `Tenant ID`, `Rest API Endpoint`, `Token Endpoint`, `Authorization Endpoint`, `Client ID`, `Client secret` (secret), `Maximum Number of Records` | — |
| **Custom** | `Tenant ID`, `Rest API Endpoint`, `Token Endpoint`, `Client ID`, `Client secret` (secret), `Refresh Token` (secret), `Maximum Number of Records` | — |
| **SAML 2.0 (OAuth)** | `Login Redirect URL`, `Rest API Endpoint`, `Token Endpoint`, `Authorization Endpoint`, `Client ID`, `Maximum Number of Records` | `Client secret` (secret) |
| **SAML 2.0 (IdP-initiated)** | `IdP SSO Service URL`, `Rest API Endpoint`, `Token Endpoint`, `Authorization Endpoint`, `Assertion Dictionary` (secret), `Maximum Number of Records` | — |

<!-- auth-methods:end -->

<!-- terraform-examples:begin (generated from the integration catalog; do not hand-edit) -->

## Manage this integration with Terraform

Connections for this integration can be managed as code with the [Relyance Terraform provider](https://registry.terraform.io/providers/Relyance/relyance/latest). Non-secret fields go in `auth.params`; secret fields go in `auth.secrets_wo`, which is write-only — never stored in Terraform state. Rotate secrets by bumping `auth.secrets_wo_version`.

### OAuth (browser authorization)

The **OAuth (browser authorization)** method uses a browser authorization flow, so the connection is created in the Relyance app. Manage it in Terraform afterwards by importing it (`terraform import relyance_integration_connection.example workday/<connection_id>`) or reading it with the `relyance_integration_connection` data source.

### Client ID & secret

```hcl
resource "relyance_integration_connection" "workday_1" {
  vendor = "workday"
  name   = "<your connection name>"

  auth = {
    method = "client-credentials"
    params = {
      tenant_id = "<tenant_id>"
      rest_api_endpoint = "<rest_api_endpoint>"
      token_endpoint = "<token_endpoint>"
      client_id = "<client_id>"
      maximum_number_of_records = "5000"
      data_storage_location = "us"
    }
    # Secret fields are write-only: sent to Relyance, never stored in state.
    secrets_wo = {
      client_secret = var.workday_client_secret
      refresh_token = var.workday_refresh_token
    }
    secrets_wo_version = 1
  }

  scans = { "data-inspection" = { enabled = true } }
}
```

### OAuth (browser authorization) — SAML 2.0 (OAuth)

The **OAuth (browser authorization) — SAML 2.0 (OAuth)** method uses a browser authorization flow, so the connection is created in the Relyance app. Manage it in Terraform afterwards by importing it (`terraform import relyance_integration_connection.example workday/<connection_id>`) or reading it with the `relyance_integration_connection` data source.

### Access token

```hcl
resource "relyance_integration_connection" "workday_3" {
  vendor = "workday"
  name   = "<your connection name>"

  auth = {
    method = "access-token"
    params = {
      idp_url = "<idp_url>"
      rest_api_endpoint = "<rest_api_endpoint>"
      token_endpoint = "<token_endpoint>"
      auth_endpoint = "<auth_endpoint>"
      maximum_number_of_records = "5000"
      data_storage_location = "us"
    }
    # Secret fields are write-only: sent to Relyance, never stored in state.
    secrets_wo = {
      assertion_dict = var.workday_assertion_dict
    }
    secrets_wo_version = 1
  }

  scans = { "data-inspection" = { enabled = true } }
}
```

<!-- terraform-examples:end -->
