.png)
Deel Integration Guide
Integrate Deel with enterprise HR, identity, finance, and workflow systems through REST APIs, selective webhook events, and Martini workflows.
Deel integration options at a glance
Deel provides a REST-oriented developer API for accessing supported People, Contracts, Invoices, Payments, Time off, Expenses, and Documents resources. Deel also supports webhook-style notifications for selected events, although coverage varies by resource, event, product, and account configuration. Martini can authenticate with Deel using OAuth-based access tokens, consume paginated API responses, expose an endpoint for webhook delivery, and orchestrate downstream processing. Scheduled workflows are appropriate for initial loads, reconciliation, and changes without event coverage. General-purpose bulk, GraphQL, SOAP, database, and file-transfer capabilities were not confirmed, so implementations should use documented Deel resource endpoints and validate document-specific behavior.
Common Deel integration patterns
Common Deel data objects used in integrations
Authentication and security considerations
OAuth and access tokens
Deel documents OAuth-based API authentication. Access-token expiration, refresh behavior, application permissions, and available scopes depend on the Deel account and API product.
Credential protection
Store client credentials, bearer tokens, refresh material, and webhook signing secrets in protected Martini configuration or secrets management. Do not expose sensitive values in workflow payloads or logs.
Least privilege and data minimization
Request only the Deel permissions required for the selected resources. Treat worker identity, compensation, contracts, payments, tax information, and documents as sensitive data and limit downstream exposure.
- Validate webhook authentication or signature controls before trusting event data.
- Mask sensitive values in error messages and operational logs.
- Apply retention, encryption, and access-control requirements to downloaded documents.
Operational considerations for Deel integrations
Pagination and checkpoints
Treat Deel list endpoints as paginated unless an endpoint states otherwise. Persist a cursor, timestamp, page checkpoint, or resource identifier only after successful processing, and use an overlap window for timestamp-based polling.
Rate limits and retries
Confirm the applicable Deel limits, control concurrency, and handle HTTP 429 responses with bounded backoff. Retry transient failures, but route permission and validation errors for correction.
Webhook reliability
Expect duplicate, delayed, and out-of-order notifications. Acknowledge promptly, record event-processing state, and retrieve the current Deel resource when the notification does not contain complete state.
Schema variation and testing
Fields vary by Deel product, country, worker classification, employing entity, and permissions. Test representative worker, contract, financial, time-off, expense, and document cases, including null and status-transition values.
- Use stable Deel identifiers for idempotency.
- Capture request or correlation identifiers when provided.
- Validate document download and authorization behavior separately.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration beyond point-to-point calls
Martini coordinates Deel API calls, webhook intake, scheduled polling, transformations, business rules, target writes, and exception handling in reusable workflows rather than scattering logic across scripts.
Maintainable mappings
Canonical models and explicit mappings make it easier to handle differences among HR, identity, finance, and service-management applications while accommodating Deel's product and country variation.
Reliable operations
Martini supports controlled retries, idempotent processing, asynchronous workflow paths, checkpointing, validation, and operational logging so integrations can recover from rate limits, delayed events, and transient downstream failures.
API-led reuse
Teams can expose controlled Martini APIs for on-demand synchronization or downstream consumers, while keeping Deel credentials and vendor-specific implementation details behind reusable integration assets.