workday-mcp-reference
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@workday-mcp-referenceshow my time off balance"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
workday-mcp-reference
A vendor-neutral, clean-room reference implementation of a Workday MCP server. It reproduces the architecture of a production Workday Model Context Protocol server — OAuth broker, opaque session tokens with silent refresh, a REST + SOAP Workday client, regex SOAP parsing, text/HTML formatters, and per-tool gating — without any company-specific data. Use it as a starting point for your own Workday MCP integration.
Stack
Python 3.11+, modern typing, absolute imports.
MCP: official
mcpSDKFastMCP, streamable-HTTP transport.HTTP:
requests(sharedSession+ retry on idempotent verbs only).Logging: stdlib
logging. Metrics: a no-opMetricsprotocol (inject your own).Tracing: optional OpenTelemetry, gated on
OTEL_EXPORTER_OTLP_ENDPOINT.Config:
os.environ+python-dotenv.
Related MCP server: PeopleSoft MCP Server
Quick start
python -m venv .venv && source .venv/bin/activate
pip install -e ".[dev]" # add ,otel,redis as needed
cp .env.example .env # fill in your tenant + OAuth client
workday-mcp-reference # serves streamable-HTTP on :8000/mcpHow auth works
An MCP client calls
/mcpwith no valid bearer → the server returns401+WWW-Authenticatepointing at/.well-known/oauth-protected-resource.The client discovers the authorization server (RFC 8414), optionally registers (RFC 7591), then opens
/authorize→ the server 302s the user to Workday.Workday redirects to
/callback?code=…; the server exchanges the code, resolves the user email, stores the Workday tokens under an opaque UUID, and returns that UUID. The client uses the UUID as its bearer thereafter.Each tool call resolves the live Workday token from the store, refreshing silently when it is within 5 minutes of expiry.
Layout
src/workday_mcp_reference/
config.py environment-driven configuration
metrics.py Metrics protocol + NoopMetrics
server.py FastMCP + Bearer gate + OAuth/health routes + main()
auth/
token_store.py opaque-id → Workday tokens, silent refresh
oauth.py authorize/callback broker + discovery metadata
workday/
client.py WorkdayClient (REST + SOAP), uniform envelope
parsers.py regex SOAP parsing (no lxml)
formatters.py text + optional HTML artifacts
tools/
__init__.py register_all + get_client/resolve_me_wid helpers
me.py exemplar tool module (workday_me)
pay.py compensation + one-time payment (REST + SOAP)
benefits.py enrollments, elections, total rewards
time.py time off: scheduled, balance, eligible types, request
org.py manager, reports, org chart, search, lookup
inbox.py inbox tasks: list, approve, deny
admin.py job profiles, pay groups, hire steps, BP status
headcount.py open positions, approvals, position detail (RaaS/WQL)The eight category tools each take an action argument and dispatch to one
implementation — mirroring how a production server keeps the MCP tool surface
small. headcount.py depends on tenant-specific RaaS reports and WQL fields, so
its report names and field mappings are driven entirely by env config (see
.env.example); the other modules use standard Workday REST/SOAP APIs.
Adding a tool module
Copy tools/me.py. Expose def register(mcp: FastMCP) -> None, define your
@mcp.tool() functions inside it, and call get_client() / resolve_me_wid(client)
— never read tokens directly. Add your module name to _TOOL_MODULES in
tools/__init__.py.
This server cannot be deployed
Maintenance
Related MCP Connectors
AI から使えるクラウドグループウェア Work Handler の MCP サーバー。組織・メンバーの参照、出退勤の共有、タイムカード、承認フロー等を本人の権限の範囲で操作できる。
MCP server unifying ERPs, CRMs, APIs and knowledge base for Claude, ChatGPT and Gemini.
isolved and ApplicantPro jobs, tenant discovery, and change detection as an MCP server.
- StytchOAuthdev.stytch.mcp
The Stytch MCP server is a reference implementation that demonstrates remote MCP server authentication and authorization using Stytch Connected Apps. It provides OAuth 2.1-compliant authorization (including PKCE), Dynamic Client Registration, and validates Stytch-issued access tokens to enable AI agents to securely interact with external services through permissioned access, supporting scopes like openid, email, profile, and manage:project_data.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceAn open-source MCP server that imports HR CSV data into an in-memory SQLite database for structured querying and metadata retrieval. It enables users to perform read-only SQL queries and structured searches on employee data through natural language.MIT
- AlicenseBqualityFmaintenanceA Model Context Protocol (MCP) server that enables AI assistants to query and understand PeopleSoft HCM databases. It provides semantic tools for HR, Payroll, Benefits, Performance, and PeopleTools metadata, allowing natural language questions to be answered with accurate SQL queries.4312MIT
- FlicenseNot gradedqualityDmaintenanceAn MCP server for interacting with an HR database, enabling querying employee data and HR operations via natural language.-
- FlicenseNot gradedqualityDmaintenanceEnables querying HR data like recent hires, employee details, departments, and PTO balances through natural language in an MCP client.-