.png)
Ashby Integration Guide
Connect Ashby recruiting data and selected webhook events with HR, CRM, collaboration, analytics, and operational systems through Martini workflows and APIs.
Ashby integration options at a glance
Ashby provides documented REST APIs for recruiting objects such as Candidates, Applications, Jobs, Interviews, Offers, and Job postings. Ashby also supports webhook-style notifications for selected recruiting events, although event coverage and verification requirements should be confirmed for each tenant. Martini can consume Ashby APIs, receive webhook notifications, retrieve authoritative objects, and transform Ashby JSON for downstream systems. Scheduled workflows support paginated synchronization, checkpoints, rate-limit-aware retries, and reconciliation. Ashby API keys are sent as bearer credentials and can be stored securely in Martini Secrets Management. No official Ashby GraphQL, SOAP, general-purpose bulk export, database, or common attachment API was confirmed.
Common Ashby integration patterns
Common Ashby data objects used in integrations
Authentication and security considerations
API-key authentication
Ashby API requests use API-key authentication with the key sent as a bearer credential. Martini can load the key from Secrets Management rather than embedding it in workflows or source-controlled mappings.
Credential protection
- Use separate Ashby credentials for development, testing, and production where appropriate.
- Grant only the permissions required by the integration.
- Keep API keys out of client applications, logs, payloads, and workflow definitions.
- Configure webhook verification according to the Ashby tenant and event documentation.
Recruiting data privacy
Candidate and application data may contain personally identifiable and employment-related information. Minimize transferred fields, restrict access, protect data in transit and at rest, and avoid writing resumes, personal information, or interview notes to operational logs.
Operational considerations for Ashby integrations
Pagination and checkpoints
Treat Ashby list responses as paginated where applicable. Persist cursors, page positions, or timestamps and advance checkpoints only after successful downstream processing.
Rate limits and retries
Confirm current Ashby request and rate-limit behavior for the relevant tenant and API version. Use bounded backoff for transient failures and throttling, and avoid repeating non-idempotent writes without a correlation strategy.
Idempotency and duplicates
Store Ashby event identifiers, object identifiers, event types, and processing status. Use stable Ashby IDs and deterministic downstream lookups to prevent duplicate records.
Schema changes and custom fields
Ashby schemas can vary by tenant and include custom fields. Maintain explicit mappings for required and optional data, validate before delivery, and test changes without breaking the core integration.
Reconciliation and testing
Combine webhook processing with scheduled reconciliation to identify missed events and incomplete writes. Test authentication, pagination, retries, duplicate delivery, malformed payloads, privacy controls, and tenant-specific fields before production deployment.
Why use Martini instead of scripts or point-to-point integrations?
Orchestrate more than individual API calls
Scripts and point-to-point integrations often combine authentication, pagination, transformation, business rules, and error handling in code that is difficult to govern. Martini provides reusable workflows and APIs for coordinating the complete Ashby integration lifecycle.
Separate source and target models
Martini can map Ashby Candidates, Applications, Jobs, Interviews, Offers, and Job postings into canonical or downstream schemas without tightly coupling every consumer to Ashby’s payload structure.
Support event and scheduled patterns
Webhook-triggered workflows can support timely processing for selected Ashby events, while scheduled workflows provide checkpointed synchronization and reconciliation when event coverage is incomplete.
Improve operational control
- Store credentials securely and configure environments independently.
- Apply validation, routing, retry, and duplicate-handling rules consistently.
- Preserve correlation identifiers and processing outcomes.
- Monitor failures and maintain a controlled path for reconciliation and manual review.