At a glance
- Availability: Experimental (how to enable).
- Authentication: OAuth 2.0.
- Connection: A user authorizes the connection in the provider’s consent screen.
- Provider documentation: Authentication reference.
Credentials
Set these per environment. See Connect an integration. These variables are required only when you supply your own OAuth app. If a managed app is available, you can connect without setting them. Provider permissions and consent still apply.Setup
- Create a developer application: Sign up at https://dev.gusto.com and create an application. New apps start in the demo environment (api.gusto-demo.com) where you can create a free test company.
- Set the redirect URI: Add your deployment’s /api/auth/gusto/callback URL to the application’s redirect URIs.
- Set environment variables: Copy the application’s client_id and secret into GUSTO_CLIENT_ID and GUSTO_CLIENT_SECRET in your .env.
- Connect and verify: Complete the OAuth consent flow with a company admin account, then run Get Token Info to discover the company UUID and confirm access.
Provider notes
- Scopes/permissions are configured on the application in the Developer Portal, not passed in the authorize URL
- Access tokens expire after 2 hours; refresh tokens are single-use and rotate on every refresh
- Production access (api.gusto.com) requires Gusto’s app approval; until then use the demo environment
- Tools pin X-Gusto-API-Version: 2024-04-01; raise the default to adopt newer versions
Tools
Verify the connection
Call a read tool such asgusto__get_token_info with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.