.png)
UKG Integration Guide
Integrate UKG Pro, UKG Pro Workforce Management, and UKG Ready with enterprise systems through REST APIs, selected web services, events, and file-based workflows.
UKG integration options at a glance
UKG integrations vary by product, tenant, region, licensed module, and API program. REST APIs are the preferred starting point for current integrations, while selected UKG products and legacy capabilities may expose SOAP or other web services. Event or callback mechanisms may be available for selected events, but coverage is not universal. Batch, scheduled, and file-based exchanges are also used for employee, payroll, time, and organizational data. OAuth 2.0 is the primary authentication pattern for current developer APIs, with other credentials possible for legacy services. Martini can authenticate securely, orchestrate workflows, transform JSON, XML, and files, and expose normalized APIs to downstream systems.
Common UKG integration patterns
Common UKG data objects used in integrations
Authentication and security considerations
Product-specific authentication
UKG authentication depends on the product, tenant, API family, region, and enabled modules. OAuth 2.0 with client credentials and bearer access tokens is the primary current pattern for supported developer APIs. Selected legacy or product-specific services may require other credentials.
Secrets and access control
- Store UKG client secrets, tokens, API keys, and tenant endpoints in Martini secrets and environment-specific configuration.
- Use only the scopes, roles, and UKG permissions required for the integration.
- Secure Martini endpoints that receive UKG callbacks using the documented authentication and authorization method.
- Do not place access tokens, payroll details, tax data, or unnecessary employee information in logs.
Sensitive workforce data
Employee, compensation, benefits, tax, and time data can contain personally identifiable or regulated information. Use encrypted transport, least-privilege access, limited retention, and masked operational logging.
Operational considerations for UKG integrations
Rate limits and pagination
Respect UKG-specific quotas and throttling behavior. Process collection responses page by page, control concurrency, and retry transient failures such as HTTP 429 responses with backoff.
Incremental synchronization
Prefer supported modified timestamps, effective dates, incremental extracts, or event notifications. Maintain a Martini checkpoint and use scheduled reconciliation when events are partial or unavailable.
Idempotency and effective dates
Use stable UKG identifiers and source-to-target mappings to prevent duplicate Employees, Jobs, Organizations, and Timecards. Treat future-dated changes, terminations, payroll periods, reopened time, and retroactive corrections explicitly.
Files and schema changes
For file exchanges, track file identity, generation time, record counts, control totals, rejected rows, and processing status. Validate explicit mappings because UKG resource names and schemas vary across products and API versions.
Testing and monitoring
Test in the appropriate UKG environment with representative employee, time, and payroll scenarios. Monitor correlation IDs, workflow outcomes, retries, rejected records, and changes to enumerations or response structures.
Why use Martini instead of scripts or point-to-point integrations?
Orchestration beyond point-to-point calls
UKG integrations often combine tenant-specific APIs, callbacks, scheduled reconciliation, and files. Martini provides a maintainable workflow layer that coordinates these mechanisms and separates acquisition, transformation, business rules, and delivery.
Reusable transformation and API assets
Martini can map UKG JSON, XML, and structured files into canonical models, expose controlled APIs for downstream consumers, and reuse authentication, validation, and error-handling logic across UKG products and target systems.
Operational control
- Handle pagination, checkpoints, throttling, retries, and duplicate prevention consistently.
- Route rejected records and partial failures for reconciliation instead of losing them in scripts.
- Keep secrets and tenant-specific configuration separate from workflow logic.
- Support REST, selected SOAP services, webhooks, scheduled workflows, and file-based processing in one integration design.