workday-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| WORKDAY_TENANT | Yes | Your Workday tenant slug |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| workday_healthcheckA | Round-trips a small public wd5.myworkday.com URL (/acme-corp/get-global-prefs.htmld?feature=doNotShowMobileAd) through ContextMint Bridge (your signed-in browser tab) and returns diagnostics: the bridge's role (host/peer/null), port, version, the extension link (linked / pair pending / not attached / never answered), the elapsed round-trip time, and a plain-English hint distinguishing 'bridge never came up' from 'extension not connected' from 'this browser can't serve a capability' from 'real wd5.myworkday.com-side problem'. Read-only, no auth required. Call this when a real tool fails and you want to know which hop broke. |
| workday_get_appsA | List the Workday apps available on your home screen, each with a launchable task id. Use this to discover what you can read, then pass an app's |
| workday_open_appA | Open one of your Workday apps by name — "My Team Management", "Talent and Performance", "Time", "Absence", "Benefits and Pay", "Org Chart", "Total Rewards" — and read it, following the app down to the child cards that hold its real content. Most Workday app hubs return a near-empty shell on their own; this follows the links for you. Matched case-insensitively against your own app menu, so it works without knowing any task ids. Read-only. |
| workday_get_taskA | Fetch a Workday page (task or data card) by its path and return a structured, read-only view: title, current user, each section as label/value fields, navigable references (instance id + drill-in uri), and the page's related tasks + export links. The path is a Workday |
| workday_get_org_chartA | Read the reporting chain around you: each person with their business title, location, report count, and a |
| workday_get_workerA | Read a worker's Workday profile and return the CATALOG of everything readable about them: sections (Job, Compensation, Benefits, Contact, Personal, Performance, Career, Feedback) each listing named, fetchable tasks. Pass a |
| workday_get_worker_taskA | Open a single named item from a worker's profile — "Compensation", "Job Details", "Performance Reviews", "Management Chain", "Benefits", "Goals", "Pay Change History", and so on. Matched case-insensitively against that worker's own task catalog; if it does not match, the error lists exactly what is available. Read-only. |
| workday_get_my_profileA | Read your own worker profile — the same catalog |
| workday_fetchA | GET any Workday data endpoint and return the RAW JSON with secrets redacted — the escape hatch for pages the typed tools do not model yet. Prefer |
| workday_graphqlA | Run a read-only GraphQL query against Workday's PEX surface ( |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 10 tools
Most tools target clearly distinct resources: apps, my-profile, worker, org-chart, worker-task. There is some overlap among workday_get_task, workday_fetch, and workday_graphql (all retrieve Workday pages/endpoints), but the descriptions establish a clear hierarchy (structured view vs raw JSON escape hatch vs GraphQL-only surfaces), which prevents most misselection.
All tools share the workday_ prefix and mostly follow a verb_noun pattern (get_apps, get_worker, open_app, get_org_chart). Minor deviations exist: workday_healthcheck is noun-only, and workday_fetch/workday_graphql omit a noun, but the set reads consistently overall.
Ten tools is well-scoped for a read-only Workday browser bridge, with no apparent redundancy and each tool earning its place (discovery, profile reads, page fetch, and two explicit escape hatches).
For an explicitly read-only server, the surface covers discovery (apps, org chart), profile/catalog reads, named task access, and raw JSON plus GraphQL escape hatches for unmodeled pages. The only gap is the deliberate absence of any write/mutation operations, which is by design rather than an oversight.