Skip to main content

About Workable

Iru calls https://YOUR_SUBDOMAIN.workable.com/spi/v3 with Authorization: Bearer. Access tokens are scoped and carry a mandatory expiration (between 30 days and 2 years). Use read scopes only, e.g. r_jobs, r_candidates - and omit write scopes for least privilege.

How It Works

Authorization: Bearer YOUR_ACCESS_TOKEN
DetailValue
CategoryATS / recruiting
AuthenticationBearer (scoped access token)
Official references: Access tokens, API, REST reference.

Prerequisites

  • Admin role - only Admins create tokens.
  • Subdomain from https://YOUR_SUBDOMAIN.workable.com.

Connect Workable to Iru

Complete this tab before you connect the source in Compliance.
1

Sign in to Workable

Open https://YOUR_SUBDOMAIN.workable.com and sign in with an Admin (only Admins can create access tokens).
2

Open your profile menu

Select Profile (or your avatar) in the Workable header.
3

Open Settings

Choose Settings from the menu.
4

Open Integrations

Select Integrations (or Developer / API, depending on your Workable edition) until you see Access Tokens.
5

Generate a new token

Open Access Tokens, then Generate new token. Enter a name such as Iru Compliance.
6

Set expiry and read scopes

Set expiry per your rotation policy. Enable only read scopes your controls need (for example r_jobs, r_candidates).
7

Generate and copy the token

Generate the token and copy the value once when Workable displays it. Store it securely until you paste it into Iru as the Bearer token.
Continue on the Iru Compliance tab.

Troubleshooting

Check pop-up blocker settings for the Iru site and try again.
Token expired; rotate.
Add missing read scopes - new token required.

Sources Management

Browse and manage every Compliance source.

Getting Started With Compliance

Frameworks, actions, and Artifacts.

Iru Overview

How Endpoint, Compliance, and Identity fit together.

Artifacts Management

Upload, review, and organize evidence from sources and actions.