Skip to main content

At a glance

  • Availability: Experimental (how to enable).
  • Authentication: OAuth 2.0 (client credentials).
  • Connection: Veryfront obtains machine-to-machine tokens from the client ID and secret in the project’s environment variables.
  • Provider documentation: Authentication reference.

Credentials

Set these per environment. See Connect an integration.

Setup

  1. Generate API credentials: In Personio, go to Settings > Integrations > API credentials and click ‘Generate new credentials’. Grant the credential read access to Persons, Absences, and Attendances (and write access to Absences if you want to create absence periods). Copy the Client ID and Client Secret. If you do not have a Personio account, request a trial/demo account at https://www.personio.com.
  2. Set environment variables: Add PERSONIO_CLIENT_ID and PERSONIO_CLIENT_SECRET to your .env.
  3. Verify access: Run List Persons. Access tokens are minted automatically from https://api.personio.de/v2/auth/token via the OAuth2 client_credentials grant (form-encoded client_id and client_secret) - no user login is involved.

Provider notes

  • This connector uses the Personio v2 API. The legacy v1 token endpoint (https://api.personio.de/v1/auth) is a different flow and is not used here.
  • Access tokens are valid for 24 hours.
  • API credentials are scoped: a 403 from a tool usually means the credential is missing the corresponding permission (e.g. personio:persons:read, personio:absences:read).
Provider API reference.

Tools

Verify the connection

Call a read tool such as personio__list_persons with arguments for your account. Confirm that the result comes from the intended account or workspace before enabling write tools.