Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Diagnose and fix BambooHR API errors and exceptions. Use when encountering BambooHR errors, debugging failed requests, or troubleshooting HTTP 400/401/403/404/429/500/503 responses. Trigger with phrases like "bamboohr error", "fix bamboohr", "bamboohr not working", "debug bamboohr", "bamboohr 401", "bamboohr 429".
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 59% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 56% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 36% | 0% |
| case-17 | ✗→✓ | ▲ Improved | 111% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 63% | 0% |
Diagnostic reference for BambooHR REST API errors. BambooHR returns error details in the X-BambooHR-Error-Message response header for most 400-level and some 500-level errors.
Always check X-BambooHR-Error-Message first — it contains BambooHR's specific error detail, which is more useful than generic HTTP status text.
typescriptconst res = await fetch(`${BASE}/employees/999/`, { headers: { Authorization: AUTH, Accept: 'application/json' }, }); if (!res.ok) { const errorDetail = res.headers.get('X-BambooHR-Error-Message'); console.error(`HTTP ${res.status}: ${errorDetail || res.statusText}`); }
X-BambooHR-Error-Message: Invalid API keyCause: API key is missing, expired, revoked, or malformed in the Basic Auth header.
Solution:
bash# Verify key is set echo "Key length: ${#BAMBOOHR_API_KEY}" # Test auth directly curl -s -o /dev/null -w "%{http_code}" \ -u "${BAMBOOHR_API_KEY}:x" \ "https://api.bamboohr.com/api/gateway.php/${BAMBOOHR_COMPANY_DOMAIN}/v1/employees/directory"
Common mistakes:
:x password part in Basic Auth encodingX-BambooHR-Error-Message: You do not have access to this resourceCause: The API key's user account lacks permissions for the requested endpoint or employee.
Solution:
X-BambooHR-Error-Message: Invalid field: "jobTitl"Cause: Misspelled field name, invalid date format, or malformed JSON body.
Solution:
bash# Verify field names against BambooHR's field list curl -s -u "${BAMBOOHR_API_KEY}:x" \ "https://api.bamboohr.com/api/gateway.php/${BAMBOOHR_COMPANY_DOMAIN}/v1/employees/0/?fields=firstName,lastName" \ -H "Accept: application/json"
Common field name mistakes:
title (wrong) vs jobTitle (correct)email (wrong) vs workEmail (correct)name (wrong) vs firstName + lastName (correct)YYYY-MM-DD, not MM/DD/YYYYX-BambooHR-Error-Message: Employee not foundCause: Employee ID does not exist, wrong company domain, or malformed URL path.
Solution:
bash# Verify company domain echo "Domain: $BAMBOOHR_COMPANY_DOMAIN" # Verify the base URL structure # Correct: /api/gateway.php/{domain}/v1/employees/{id}/ # Wrong: /api/v1/employees/{id}/ # Wrong: /api/gateway.php/{domain}/employees/{id}/ (missing /v1/)
HTTP 503 with Retry-After: 30Cause: Too many requests in a short period. BambooHR does not publish exact rate limits but returns 503 with a Retry-After header.
Solution:
typescriptasync function handleRateLimit(res: Response): Promise<void> { if (res.status === 503 || res.status === 429) { const retryAfter = parseInt(res.headers.get('Retry-After') || '30', 10); console.warn(`Rate limited. Waiting ${retryAfter}s...`); await new Promise(r => setTimeout(r, retryAfter * 1000)); } }
Prevention:
/employees/changed/?since=... for incremental sync instead of full pullsCause: BambooHR internal error. Usually transient.
Solution:
bamboohr-rate-limits)Cause: Missing Accept: application/json header — BambooHR defaults to XML.
bash# Wrong — returns XML curl -u "${BAMBOOHR_API_KEY}:x" \ "${BASE}/employees/directory" # Correct — returns JSON curl -u "${BAMBOOHR_API_KEY}:x" \ -H "Accept: application/json" \ "${BASE}/employees/directory"
bash#!/bin/bash echo "=== BambooHR Diagnostic ===" echo "Company: ${BAMBOOHR_COMPANY_DOMAIN}" echo "Key set: ${BAMBOOHR_API_KEY:+YES}" echo "Key length: ${#BAMBOOHR_API_KEY}" BASE="https://api.bamboohr.com/api/gateway.php/${BAMBOOHR_COMPANY_DOMAIN}/v1" echo -n "Auth test: " STATUS=$(curl -s -o /dev/null -w "%{http_code}" -u "${BAMBOOHR_API_KEY}:x" \ -H "Accept: application/json" "${BASE}/employees/directory") echo "$STATUS" echo -n "Status page: " curl -s https://status.bamboohr.com | head -c 100 echo "" if [ "$STATUS" -eq 200 ]; then echo "Connection OK" elif [ "$STATUS" -eq 401 ]; then echo "FIX: Regenerate API key in BambooHR dashboard" elif [ "$STATUS" -eq 403 ]; then echo "FIX: Upgrade API key user's access level" elif [ "$STATUS" -eq 404 ]; then echo "FIX: Check BAMBOOHR_COMPANY_DOMAIN value" else echo "FIX: Check status page and retry" fi
X-BambooHR-Error-Message header| Status | Header | Root Cause | Fix | |--------|--------|-----------|-----| | 400 | Invalid field | Typo in field name | Check field list docs | | 401 | Invalid API key | Bad credentials | Regenerate API key | | 403 | No access | Insufficient permissions | Upgrade user access level | | 404 | Not found | Wrong ID or domain | Verify URL components | | 429/503 | Retry-After | Rate limited | Backoff and retry | | 500/502 | — | Server error | Retry; check status page |
For comprehensive debugging, see bamboohr-debug-bundle.
Other measured skills in the registry, with their headline benchmark lift.