Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Install and configure BambooHR API authentication with HTTP Basic Auth. Use when setting up a new BambooHR integration, configuring API keys, or initializing BambooHR REST API access in your project. Trigger with phrases like "install bamboohr", "setup bamboohr", "bamboohr auth", "configure bamboohr API key", "bamboohr credentials".
.claude/skills/jeremylongshore-bamboohr-install-auth/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 19% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 54% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 48% | 0% |
| case-18 | ✗→✓ | ▲ Improved | 43% | 0% |
| case-22 | ✗→✓ | ▲ Improved | 63% | 0% |
Configure the narrowest BambooHR identity that fits the integration. OAuth 2.0 is BambooHR's recommended path for partner integrations. An API key is suitable for an internal tool or prototype when its owning user's permissions and key lifecycle are acceptable.
https://{company-subdomain}.bamboohr.com.https://{company-subdomain}.bamboohr.com/authorize.php.POST https://{company-subdomain}.bamboohr.com/token.php?request=token.x as password.
IDs, retry controls, and redacted logging. As of 2026-09-11 the documented bamboohr-sdk distribution is not discoverable on public PyPI; verify the registry before installing or use an approved commit pin.
For OAuth, register an HTTPS redirect URI, generate a high-entropy state, bind it to the initiating session, and reject callbacks whose state does not match. Exchange the code server-side. Store access token, refresh token, expiry, tenant, subject, and granted scope in an encrypted, tenant-scoped record.
For API keys, create a dedicated BambooHR user with only required field and workflow permissions. Store the key in the deployment secret manager. Never put it in .env.example, logs, shell history, test fixtures, or a client bundle.
tenant, and record the authentication decision.
full arbitrary host from untrusted input.
token persistence, rotation, and reauthorization after terminal refresh failure. The SDK does not persist refreshed tokens for the application.
rotation and revocation procedure before use.
and request ID, but discard the response body from evidence.
field cases before production approval.
Use Read, Glob, and Grep to inspect existing configuration and secret references. Use Write or Edit only for approved application configuration; write placeholders, never credentials. This skill does not authorize browser consent, credential creation, package installation, or remote secret mutation.
Require explicit approval before registering an OAuth app, changing redirect URIs, creating or rotating an API key, writing a deployment secret, or testing against a production tenant.
Return the chosen auth mode, tenant, requested permissions, callback and token- storage design, test evidence without bodies, key/token owner, rotation plan, and every action still awaiting approval.
401: refresh once when configured; otherwise treat the credential as invalid.403: inspect the BambooHR user's field permissions; do not broaden blindly.require reauthorization.
tenant-isolated token persistence.
privilege identity and rotation owner exist.
Read official evidence before implementation.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 11,406 | 7,717 | -32% | 1 | 1 | 0% | 2,537 | 3,015 | +19% | 0 | 0 | — |
case-02 | fail→pass | 12,404 | 11,427 | -8% | 1 | 1 | 0% | 2,624 | 4,051 | +54% | 0 | 0 | — |
case-03 | fail→pass | 10,287 | 7,448 | -28% | 1 | 1 | 0% | 1,984 | 2,936 | +48% | 0 | 0 | — |
case-04 | pass→pass | 13,187 | 13,289 | +1% | 1 | 1 | 0% | 2,771 | 4,130 | +49% | 0 | 0 | — |
case-05 | pass→pass | 15,685 | 18,367 | +17% | 1 | 1 | 0% | 3,020 | 5,417 | +79% | 0 | 0 | — |
case-06 | pass→pass | 12,318 | 15,164 | +23% | 1 | 1 | 0% | 2,284 | 4,382 | +92% | 0 | 0 | — |
case-07 | pass→pass | 7,239 | 5,019 | -31% | 1 | 1 | 0% | 1,456 | 2,417 | +66% | 0 | 0 | — |
case-08 | pass→pass | 4,547 | 1,816 | -60% | 1 | 1 | 0% | 823 | 1,697 | +106% | 0 | 0 | — |
case-09 | pass→pass | 10,510 | 6,066 | -42% | 1 | 1 | 0% | 1,906 | 2,656 | +39% | 0 | 0 | — |
case-10 | fail→fail | 9,026 | 8,905 | -1% | 1 | 1 | 0% | 1,696 | 2,993 | +76% | 0 | 0 | — |
case-11 | pass→pass | 3,358 | 3,487 | +4% | 1 | 1 | 0% | 545 | 1,975 | +262% | 0 | 0 | — |
case-12 | pass→pass | 9,204 | 7,115 | -23% | 1 | 1 | 0% | 1,482 | 2,579 | +74% | 0 | 0 | — |
case-13 | pass→pass | 10,309 | 7,058 | -32% | 1 | 1 | 0% | 1,756 | 2,604 | +48% | 0 | 0 | — |
case-14 | pass→pass | 4,578 | 3,598 | -21% | 1 | 1 | 0% | 772 | 1,947 | +152% | 0 | 0 | — |
case-15 | pass→pass | 15,624 | 18,079 | +16% | 1 | 1 | 0% | 2,717 | 4,713 | +73% | 0 | 0 | — |
case-16 | pass→pass | 11,452 | 8,190 | -28% | 1 | 1 | 0% | 2,011 | 2,899 | +44% | 0 | 0 | — |
case-17 | pass→pass | 5,377 | 4,454 | -17% | 1 | 1 | 0% | 1,054 | 2,365 | +124% | 0 | 0 | — |
case-18 | fail→pass | 6,565 | 2,686 | -59% | 1 | 1 | 0% | 1,302 | 1,868 | +43% | 0 | 0 | — |
case-19 | pass→pass | 8,203 | 4,741 | -42% | 1 | 1 | 0% | 1,617 | 2,263 | +40% | 0 | 0 | — |
case-20 | pass→pass | 15,663 | 10,260 | -34% | 1 | 1 | 0% | 2,360 | 3,068 | +30% | 0 | 0 | — |
case-21 | pass→pass | 3,796 | 1,827 | -52% | 1 | 1 | 0% | 700 | 1,726 | +147% | 0 | 0 | — |
case-22 | fail→pass | 7,721 | 4,581 | -41% | 1 | 1 | 0% | 1,413 | 2,302 | +63% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +23 percentage points is the difference between those two pass rates over the 22 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.