Tadashi Shigeoka· Mon, September 14, 2026
Before handing recruiting operations to Codex CLI or Claude Code, the first question is which applicant tracking systems (ATS) can even be driven from an API. Japan has many ATS products, but the subset where a customer can issue their own API key and talk to the system programmatically is narrow. This post walks the public information as of 2026-09-14 and sorts out the three products that are usable today, plus the ones to watch.
The evaluation is not an overall feature comparison of the products. It is strictly about whether an agent can operate the system safely and reproducibly. That translates into: a published OpenAPI specification, a standard auth model such as a Bearer token, read and write endpoints across candidates, requisitions, selections, and evaluations, documented rate limits, and the presence of a Model Context Protocol (MCP) server.
Rankings as of 2026-09-14 #
Legend: ✅ available / ⚠️ limited or conditional / ❌ not available / ❓ not confirmed
| Rank | Product | API availability | OpenAPI | Auth | Write | Official MCP |
|---|---|---|---|---|---|---|
| 1 | HERP Hire | ✅ Paid plans | ✅ Yes | ✅ API key (Bearer, scoped) | ✅ Broad | ❌ No |
| 2 | Talentio | ✅ Business plan and above | ✅ Yes | ✅ Access token (Bearer) | ✅ Broad | ❌ No |
| 3 | Wantedly Hire | ✅ Professional plan and above (paid add-on on Growth) | ❓ Not confirmed | ✅ Personal Access Token | ❌ None (read-only) | ✅ Yes |
| 4 | Saiyo Ikkatsu Kanrikun | ✅ Issued from settings | ✅ Yes | ✅ client_id + client_secret → X-KANRIKUN-TOKEN | ⚠️ Partial | ❌ No |
| 5 | HRMOS Recruiting | ⚠️ Announced, not shipped | ❓ Not confirmed | ❓ Not confirmed | ❓ Not confirmed | ❌ No |
| 6 | sonar ATS | ⚠️ HRTech integration vendors only; new intake d | ❓ Not confirmed | ❓ Not confirmed | ⚠️ Media and assessment only | ❌ No |
I could not find customer-facing public API documentation for Jobcan Recruitment, i-web by Humanage, HITO-Link Recruiting by Persol Innovation, or Cloud House Saiyo.
HERP Hire: Scoped API Keys and Broad Write Coverage #
HERP, Inc. ships HERP Hire, which went from a beta in October 2025 to general availability of its API on 2026-02-03. The public documentation renders as Redoc, and the OpenAPI specification is downloadable from the same page. The version at the time of writing is 1.10.0.
Authentication uses API keys issued from the “API Keys” menu in the top-right of the admin UI, placed in the Authorization: Bearer <API_KEY> header. At issuance you pick scopes such as all, read, write, candidacy:all, candidacy:read, and candidacy:write, with similar per-resource scopes for requisitions, users, and more. That makes it straightforward to hand an agent a read-only key and keep a separate write key for approved mutations.
The endpoint surface spans the application lifecycle. Create an application (POST /v1/candidacies), list applications ( GET /v1/candidacies), update the selection step ( PATCH /v1/candidacies/{id}/step), terminate selection ( PATCH /v1/candidacies/{id}/termination), upload files ( POST /v1/candidacies/{id}/files, up to 50 MB total) and fetch them ( GET /v1/candidacies/{id}/files/{fileId}), post timeline comments ( POST /v1/candidacies/{id}/timeline-comments, with Markdown and user mentions), create interview contacts, and read or write evaluations. An agent fetching a resume via the file API, parsing it locally, and posting a Markdown summary and recommended judgment back to the candidate’s timeline fits within one API surface.
The rate limit is 100 requests per minute per tenant. Response headers x-remaining-request and x-reset-at carry the remaining count and reset time (ISO 8601). Backoff on rate-limit detection is easy to write, and a script that batches reads against a per-minute cap pairs well with cache + delta fetching.
HERP’s own help docs show a use case where a resume is fetched through the API, text is extracted and sent to a generative model, and the output is written back to the HERP Hire timeline. Showing the full loop, including writing the model’s output back into the ATS, in official help is what sets it apart from Wantedly Hire, whose official MCP server is read-only.
The weak spots are Webhooks (not confirmed in public specs) and the absence of an official CLI or SDK. Change detection leans on polling. Pinning the OpenAPI spec in the repo and generating a thin client with OpenAPI Generator covers the SDK gap in practice.
Talentio: 5,000 Requests per Hour and a Mature REST API #
Talentio is now operated by jinjer Co., Ltd., which acquired its developer, Talentio Inc., in March 2026 and absorbed it in a merger effective 2026-10-01. It has run a developer portal for years and keeps the public API documentation up to v1.1.2. The OpenAPI specification is downloadable from the same page.
Authentication is an access token issued from “Basic settings → API settings,” placed in Authorization: Bearer <ACCESS_TOKEN>. The token is shown only once at issuance, so the practical path is dropping it into a secret manager immediately. The documentation describes no auth method other than this access token.
The rate limit is 5,000 requests per hour. X-Remaining carries the remaining count and X-Reset holds the reset-in seconds. Pagination is 100 per page with the total count in X-Total. Because the whole hourly budget can be spent in a short window, bursty workloads fare better here than under HERP Hire’s per-minute cap. Sustained throughput is a different story: 5,000 req/hour is below HERP Hire’s 6,000 req/hour, so long-running full-tenant syncs to BigQuery or Snowflake don’t come out ahead.
Endpoints cover candidates (GET, POST, PATCH /candidates), tag updates, selection creation and judgment ( POST /candidates/{candidateId}/stages/{stageId}/judge), evaluation updates ( PUT .../evaluations/{evaluationId}), attachments (up to 100 MB total), comments, and requisition creation (GET, POST /requisitions). One quirk worth noting when designing agent commands: you cannot change a candidate’s status directly via PATCH; instead you add a selection and call the judgment API.
As a worked example, the GMO Pepabo case study describes combining the Talentio API with Slack to automate screening reminders, pre-interview notifications, and per-role channel routing. In a CLI for Codex or Claude Code, the same polling-for-updates and Slack channel posting can be implemented as subcommands without changing the structure.
The weak spots are a less granular token scoping story than HERP Hire’s, and Webhooks that are not confirmed in public specs. In an in-house CLI I would split read and write subcommands and layer Claude Code per-command permission rules on top as the defensive design.
Wantedly Hire: The Only Official MCP Among the Japanese ATS Products I Checked #
Wantedly, Inc. ships Wantedly Hire, and on 2026-08-31 launched an official MCP server. As of 2026-09-14 it is the only Japanese ATS I could find that publishes an official MCP server.
Setup is: issue a Personal Access Token from personal settings, then register the server URL and token in any MCP-capable client such as Claude, Cursor, or VS Code. There is no added fee on the Professional plan or above; it is a paid add-on on the Growth plan.
Eight tools are provided, all read-only:
list_candidatesget_candidatelist_job_positionsget_job_positionlist_selectionsget_selectionlist_candidate_activitiesget_interview_kit
The official page states that the server is read-only for now and describes status updates, notes, and other write operations as future additions. As of 2026-09-14, writing back to the ATS is not possible through the MCP server. Visible data is scoped to the user’s permissions. I could not find separate public REST API documentation for Wantedly Hire, so this isn’t the right choice for custom code integrations. The fit is conversational analytics in Claude Code: summarize the pipeline, draft a report, answer “how many candidates are at second-round interviews across these roles.”
For completeness: the Wantedly Open API is for embed-style widgets on the recruiting social side and does not access ATS data.
Saiyo Ikkatsu Kanrikun: Proprietary Token Flow and RPC-ish Endpoints #
HR Cloud Co., Ltd. ships Saiyo Ikkatsu Kanrikun with Redoc documentation for both the mid-career version and the new-graduate version, and OpenAPI specifications are downloadable from each.
Auth starts from a client_id and client_secret issued in “Various settings → External public API settings.” You exchange these at POST /auth/v1.0/token/get for an access token and attach it on later requests as the X-KANRIKUN-TOKEN header. The access token is valid for one hour. Both token issuance and API calls are limited to 1,000 per hour per company; the docs label these as planned values that may change after verification.
Compared with the single-Bearer-key simplicity of HERP Hire and Talentio, this adds a refresh/cache step and a two-stage secret lifecycle (client_secret plus access token). It is a reasonable machine-to-machine shape, but keeping the raw client_secret out of the Codex or Claude Code process is a good idea. A wrapper CLI that holds the long-lived secret and only hands the one-hour token to the agent process is a defensive fit.
Endpoints are RPC-ish (for example POST /mid-career/v1.0/candidate/get), and candidate fetches enumerate wanted fields in a request array. Selection statuses are numeric codes. Letting the agent read raw API docs and infer those codes every time wastes context and inference. An in-house CLI that abstracts them (atsctl kanrikun candidates list --status selecting --fields name,selection-status,selection-log) is a better interface to expose.
Pricing starts at roughly 20,000 to 30,000 JPY per month (the plan page says from 20,000 JPY, while the official site’s site name says 30,000 JPY), with the detailed price list provided as a download. Coverage of both new-graduate and mid-career hiring is the strength.
HRMOS Recruiting: API Announced on 2026-08-31, Spec Not Published #
BizReach, Inc. ships HRMOS Recruiting. On 2026-08-31 the vendor announced an API. The planned surface is a “selection and applicant information reference API” plus a “selection evaluation registration API,” restricted to tenants on the selection-flow management feature. Timing and details were deferred to a later announcement, and as of 2026-09-14 the base URL, auth method, OpenAPI availability, and rate limits are not confirmable from public sources.
The sister product’s HRMOS CORE API has an OpenAPI spec, Bearer auth, Webhooks (custom notifications), and a 600-request-per-minute rate limit per token. HRMOS Recruiting’s API may land in the same shape, but that is speculation as of this date. The practical move for existing HRMOS Recruiting customers is to watch for the GA announcement and re-evaluate then.
sonar ATS: HRTech Integration Vendors Only, New Intake d #
Thinkings Inc. (part of the BizReach group) ships sonar ATS, and the sonar ATS Developers portal exposes an API for job-board and web-assessment vendors. Documented use cases are applicant registration, assessment result storage, applicant file registration, and public requisition retrieval. This is not an API that customer companies call for their own internal automation. The portal also states that as of 2026-09-14 it is not accepting new partners for API development.
Unless the organization already holds a vendor contract, operating sonar ATS from Codex or Claude Code directly is off the table. Evaluating the product’s features and evaluating its API-automation fit are separate questions here.
Put a Thin CLI Between the Agent and the API #
Rather than letting Codex or Claude Code type raw API calls, a single in-house CLI constrained to domain commands fits every ATS covered here that has a usable API. The Codex use-case guide Create a CLI Codex can use describes giving Codex a composable command for an API. In Claude Code, permission rules allow or deny individual Bash commands, and sandboxing restricts filesystem and network access.
flowchart LR
A["Codex / Claude Code"] -->|"Scoped commands"| B["In-house atsctl"]
S["Secret Manager / OS Keychain"] -->|"Fetched at run time"| B
B -->|"HTTPS / read"| C["ATS API"]
C -->|"Normalized JSON"| B
B -->|"Minimum necessary info"| A
A -->|"Draft write"| G["Human approval / policy gate"]
G -->|"Approved writes only"| B
B -->|"HTTPS / write"| C
The commands the agent sees are shaped around business concepts, not endpoints:
With that layer in place, the differences in auth models (HERP Hire’s scoped keys, Talentio’s access token, Kanrikun’s client_secret and one-hour token) stay out of the agent’s working context. API keys stop needing to live in prompts, CLAUDE.md, AGENTS.md, or the repo’s .env.
Writes go through a human approval policy gate, and irreversible operations such as rejection, candidate deletion, and selection termination stay off the agent’s allowlist. Recruiting data is sensitive personal information; the “fetch everything the ATS has and let the agent see it” shape is a bad default. Mask down to the fields actually needed before each agent step.
For the three products that publish OpenAPI, pinning the schema in the repo and generating types plus contract tests catches API drift at build time.
Since none of the surveyed vendors publicly specifies Webhooks, change detection leans on delta polling. HERP Hire’s 100 req/min, Talentio’s 5,000 req/hour, and Kanrikun’s 1,000 req/hour give a budget to work against: combine updated-at filters with pagination and avoid full-tenant rescans.
Picking by Use Case #
| Scenario | First choice | Second | Why |
|---|---|---|---|
| Broad read-write agent control from Codex or Claude Code | HERP Hire | Talentio | Scoped keys and write APIs for selection and evaluation |
| BI, analytics, batch export | Talentio | HERP Hire | Burst-friendly 5,000 req/hour budget and a mature REST surface |
| Resume → generative AI → write result back to ATS | HERP Hire | Talentio | Vendor-published use case in official help |
| Agent workflow including interviews and evaluations | HERP Hire | Talentio | Contact creation covers scheduling and evaluation requests |
| Large-scale new-graduate + mid-career operations, price-sensitive | Saiyo Ikkatsu Kanrikun | Talentio | APIs for both tracks and pricing from 20,000 to 30,000 JPY per month |
| Conversational Q&A over the pipeline from Claude | Wantedly Hire | HERP Hire | Shortest path via the official read-only MCP |
| Integrating from an HRTech service into the ATS | sonar ATS | HERP Hire | Partner-vendor API; note the current on new intake |
| Already on HRMOS Recruiting and able to wait for its API | Watch HRMOS Recruiting | HERP Hire | HRMOS Recruiting API is still at the announcement stage |
For a new build today that needs Codex or Claude Code to actually drive the ATS, pick HERP Hire as the first candidate, keep Talentio in the quote as the comparison, and consider Saiyo Ikkatsu Kanrikun as the third option on price and dual new-graduate / mid-career coverage. If the use case is read-only analytics or reporting, the Wantedly Hire official MCP is the shortest route. sonar ATS enters the conversation only if an existing integration-vendor contract is in play, and HRMOS Recruiting enters it after the API’s GA announcement lands.
That’s all from comparing Japanese ATS public APIs through the Codex and Claude Code lens, and concluding that as of 2026-09-14 the usable choices are HERP Hire, Talentio, and the read-only Wantedly Hire, from the Gemba.