Read-only Workday for Claude — fetch tasks, pay, benefits via your signed-in session
SaferSkills independently audited workday-mcp (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Read-only MCP server for Workday. Fetches your Workday tasks and data cards — pay, benefits, compensation — and returns them as structured JSON. Every request routes through your own signed-in *.myworkday.com tab via the fetchproxy browser extension, reusing your existing SSO-authenticated session.
⚠️ Workday gives employees no personal API. This server reads the same internal *.htmld endpoints the Workday web app calls, dispatched through your own signed-in browser tab. It is read-only and touches only your own data. Check your employer's acceptable-use policy. Use at your own discretion.>
🤖 This project was developed and is maintained by AI (Claude Code).
The official Workday REST/SOAP API requires a tenant administrator to register an OAuth API client + Integration System User — an employee can't self-provision it. Tenants also sit behind corporate SSO (Ping/Okta/Entra) with MFA, so there's no server-side login. The only surface an employee can reach for their own data is their live browser session, which is what this server relays.
See SKILL.md for full setup. In brief:
{
"mcpServers": {
"workday": {
"command": "npx",
"args": ["-y", "workday-mcp"],
"env": { "WORKDAY_TENANT": "your-tenant-slug" }
}
}
}Then install the fetchproxy extension and sign into Workday in your browser.
| Tool | What it does |
|---|---|
workday_get_apps | List your Workday apps with launchable task ids — the discovery entry point |
workday_get_task | Read a Workday task/data card by task id or path → title, fields, references, related tasks, export links |
workday_healthcheck | Verify the bridge + session end-to-end with an actionable hint |
npm install
npm test # vitest
npm run build # tsc --noEmit + esbuild bundle → dist/bundle.jsThe widget-tree parser (src/parse.ts) is the durable core; see docs/WORKDAY-API.md for the captured endpoint shapes and schema. License: MIT.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.