Skip to main content

About Deel

Iru reads workers, organization and legal entity structure, and time-off records from the Deel API. Authentication uses an organization API token created in the Developer Center in your Deel dashboard. Tokens are scope-bound at creation. Grant only the read scopes your controls require.

How It Works

Deel authenticates with a Bearer token against https://api.letsdeel.com/rest. There is no subdomain to configure. Deel offers organization and personal tokens. A personal token is tied to the person who created it and expires when that person leaves your company, which can stop evidence collection without warning, including during offboarding. An organization token is not tied to an individual and does not expire. Use an organization token. Official references: Authentication, How to use the Deel API.

Prerequisites

  • An Org Admin or IT Developer Admin role in Deel. Only these roles can generate API tokens.
  • Decide which scopes to grant. Deel scopes are read-specific, so you can collect roster and offboarding evidence without exposing compensation data.

Connect Deel to Iru

Complete this tab before you connect the source in Compliance.
1

Sign in to Deel

Sign in to Deel as an Org Admin or IT Developer Admin.
2

Open the Developer Center

Go to Apps & IntegrationsDeveloper Center.
3

Create an organization API token

Select Create API Token and choose Organization as the token type. Do not choose Personal. A personal token expires when its owner leaves the company.
4

Name the token

Enter a token name such as Iru Compliance, then continue.
5

Select read-only scopes

Select read-only scopes covering the evidence you need: people:read for the worker roster, organizations:read for legal entity and org structure, and time-off:read if a control depends on leave records. Grant payslips:read only if a control requires payroll data.
6

Generate and copy the token

Select Generate, then copy the token value once while Deel displays it.
Continue on the Iru Compliance tab.

Troubleshooting

Check pop-up blocker settings for the Iru site and try again.
Your Deel role is not Org Admin or IT Developer Admin. Ask someone with one of those roles to generate the token.
Confirm the token is complete and has not been revoked, and check that the value was not truncated on copy.
The token lacks the matching read scope. Deel scopes are fixed at creation. Generate a new token with the scopes you need.
A personal token was used and expired with its owner. Replace it with an organization token.

Considerations

Use an organization token

Use an organization token, not a personal token. Personal tokens expire when their owner leaves the company and can stop evidence collection during offboarding.

Sources Management

Browse and manage every Compliance source.

Getting Started With Compliance

Frameworks, actions, and Artifacts.

Iru Overview

How Endpoint, Compliance, and Identity fit together.

Artifacts Management

Upload, review, and organize evidence from sources and actions.