Skip to main content

Does the HiBob MCP server connect AI agents to key features in Bob?

  • May 21, 2026
  • 17 replies
  • 479 views

Harshil Boparai
Bobber

YES! The HiBob MCP server connects AI agents to key features in Bob, including people data, time off, and tasks.

With this integration, agents like Claude, Cursor, and Copilot can:

  • Read and update employee data
  • Access time-off records
  • Retrieve and manage tasks

You can also use the MCP server to build your own agents or integrate AI capabilities into your internal tools.

Supported agents
MCP is currently supported by:

More agents may be supported in the future.

MCP lets you take HR actions outside the UI, inside your chatbots, helpdesks, or internal apps. Instead of clicking through the platform, users can ask questions or issue commands in natural language and get real-time results wherever they already work.

Are you using any of the above, and in what capacity? We’d love to know! 

17 replies

Harshil Boparai
Bobber

A common question we get is: Is MCP secure for handling employee data?

Yes. MCP is built with enterprise-grade security in mind. All data access follows HiBob’s strict role-based permissions and is encrypted in transit. It respects your existing data privacy policies and ensures that only authorized tools and users can access or update employee information.


Olga Frolova

Hi everyone, and thanks for raising this important topic, ​@Harshil Boparai !

We started testing the Bob MCP server shortly after the beta release, but ran into a major limitation that makes it difficult for us to use in production.

As we understand it, the MCP server currently operates through a single service user, which means all MCP users effectively inherit the same permissions. Because of this, we can’t provide managers access only to their direct reports, assign separate permissions for Finance or Legal teams, or otherwise differentiate access levels between users.

At the moment, this leaves us with two options: either everyone using the native HiBob MCP server ends up sharing the same permission scope, or we would need to issue and manage separate tokens for each individual user with their corresponding permission sets. In a large organization, that becomes a significant amount of manual work and ongoing token management overhead.

For us, this is especially challenging because our employees naturally have restricted visibility across the organization and should only access the data relevant to their role. To work around this, we’re currently building our own MCP server using n8n, where we implement role-based access controls using employee references in order to grant access to specific datasets on a per-user basis.

Is there any plan to address this limitation in the native HiBob MCP server? Ideally, we’d love to see permission handling aligned with the existing HiBob permission model, so that each MCP user would inherit the exact same access rights they already have within HiBob itself.


Harshil Boparai
Bobber

hi ​@Olga Frolova thank you for sharing such a detailed explanation of your setup and the limitation you’ve encountered. This is really helpful feedback, especially as you’re already testing practical ways to bring MCP into production securely.

I’ve checked with our Product team, and this is an area we’re actively addressing. We’re planning to introduce OAuth per-user authentication support for the HiBob MCP server, which is intended to better support user-level access and reduce the need to manage separate tokens manually for each individual user.

I don’t have a confirmed release date to share just yet, but the direction is very much aligned with what you described. Great to hear about your n8n workaround in the meantime, I’m sure you might find this interesting ​@tom :) and might have some great tips to share! 


I will sync Bob with Claude Co-Work soon and would like to sync with some people who already have some experience. You also can contact me via https://www.linkedin.com/in/katja-lorenz-3a0589123/ and we can share our experiences here afterwards for all


Has anyone connected it with Google Gem/ AI? 


  • June 3, 2026

Hi ​@Harshil Boparai are there any plans to support a hosted MCP server with OAuth and tools scoped to users? We’d really like for all staff to be able to use a BOB MCP server for requesting leave, managing their teams etc.


Harshil Boparai
Bobber

Hi ​@LisaS  Great question! This is exactly the kind of use case we’re excited about.

Yes, a hosted HiBob MCP server with OAuth is already in beta as of this week.

In terms of access, MCP currently works with the user’s existing Bob permissions. So while we don’t currently scope individual MCP tools separately, users should only be able to take actions and access data according to the permissions they already have in Bob.

That should help support scenarios like employees requesting leave or managers managing their teams through an AI agent, while still aligning with the permission model already configured in Bob.

It’s still in beta, so please do keep the feedback coming, especially around the workflows you’d want all staff or managers to use through MCP. ✨


Olga Frolova

Hi ​@Harshil Boparai , 

If there is any chance to join the HiBob MCP server with OAuth beta - please count us in! It will save tons of working hours for us if it could replace our self-made Bob MCP in n8n. 

I will also contact our CSM to check if we can be a part of this beta. 


  • June 4, 2026

Thanks ​@Harshil Boparai that’s great news!!! Is there a beta testing group that we could be added to?  If not we look forward to the updates and i’ll add any feedback re: workflows etc we’re looking to use it for.


Harshil Boparai
Bobber

@Olga Frolova & ​@LisaS  thank you both, appreciate the interest! 🌻

I checked with the team, and while we’re not able to add more customers to the beta right this moment, we do expect to be able to open this up to more customers soon.

In the meantime, I’d definitely recommend reaching out to your CSM as well so they can note your interest and keep you aligned as soon as there’s availability. I’ll also make sure to reach out once the beta is open to more customers. :) 


Hi ​@Harshil Boparai , 

Does the MCP server connect to My 1:1’s in Bob? If I was to set up a Service User with permission group ‘Employee - view own data’ to allow everyone to access their own data regarding 1:1s.

Or, does this “Employee-level access (with OAuth) is not supported at the moment.” as per info on https://apidocs.hibob.com/docs/hibob-mcp-server, mean that it is not possible set up connection to employee’s own 1:1s in Bob? 

 


Hi ​@Harshil Boparai , 

Does the MCP server connect to My 1:1’s in Bob? If I was to set up a Service User with permission group ‘Employee - view own data’ to allow everyone to access their own data regarding 1:1s.

Or, does this “Employee-level access (with OAuth) is not supported at the moment.” as per info on https://apidocs.hibob.com/docs/hibob-mcp-server, mean that it is not possible set up connection to employee’s own 1:1s in Bob? 

 

Have the same question but related to setting and updating goals in Hibob.


Harshil Boparai
Bobber

Hi ​@Piret Davies & ​@Linda Buytendorp 

The service-user approach won't work for this use case. A service user is a single shared identity, so everyone would access data based on that service user's permissions, not their own.

Your interpretation is correct: employee-level access via OAuth is required for employees to access data according to their own permissions. OAuth support is currently in beta.

Also, the hosted MCP server doesn't currently expose 1:1 data. The available tool catalog is limited to People, Time Off, and Tasks, so 1:1s aren't accessible through MCP regardless of the permission model. Hope that helps! 


Olga Frolova

Hi ​@Harshil Boparai ,

Could you please share a few more details about the MCP server? Is it a remote MCP server hosted by HiBob, or is it something that customers need to deploy within their own infrastructure?

We're currently discussing MCP-related architectural decisions internally, so it would be very helpful to better understand how the HiBob OAuth MCP server is designed and operates.


RespectMyHRthority

Hi ​@LisaS  Great question! This is exactly the kind of use case we’re excited about.

Yes, a hosted HiBob MCP server with OAuth is already in beta as of this week.

In terms of access, MCP currently works with the user’s existing Bob permissions. So while we don’t currently scope individual MCP tools separately, users should only be able to take actions and access data according to the permissions they already have in Bob.

That should help support scenarios like employees requesting leave or managers managing their teams through an AI agent, while still aligning with the permission model already configured in Bob.

It’s still in beta, so please do keep the feedback coming, especially around the workflows you’d want all staff or managers to use through MCP. ✨

Happened to stumble into this thread and be delighted by this news; really looking forward to this development!


Michael Walsh

We too are interested in the MCP server with OAuth. From what I understand Gemini can in theory connect but it isn’t mentioned. Has anyone in the group tested it with Gemini?


Harshil Boparai
Bobber

Hi ​@Olga Frolova 

It's a remote MCP server hosted by us; there's nothing for you to deploy in your own infrastructure. you just point your MCP client (Claude, etc.) at our hosted endpoint and connect. :) 

Two ways to authenticate:

  1. OAuth (per-user) - in a slow gradual beta rollout - the user logs in, we resolve them to their Bob employee, and tools are scoped to that user's own permissions. this is the flow rolling out now.
  2. Service user (company-level token) - for shared/automation use, scoped at the company level rather than per individual.

So for your architecture decision: no self-hosting and no infra on your side, it's our hosted server + your MCP client over OAuth. docs: https://apidocs.hibob.com/docs/hibob-mcp-server