{"activeVersionTag":"latest","latestAvailableVersionTag":"latest","collection":{"info":{"_postman_id":"2d6b84a7-e08e-45e4-aebb-e3aa9e2ecaa3","name":"ZenATS APIs Documentation","description":"Read and write your company's recruitment data in ZenATS: **Jobs**, their pipeline  \n**Stages**, the **Applications** moving through them, and your **Candidate** talent pool.\n\nEverything a set of credentials can reach is automatically scoped to its own company —  \na token can never see another company's data.\n\n## Getting started\n\n|  |  |\n| --- | --- |\n| Base URL | `https:///api/v1/ats` |\n| Token URL | `https:///oauth/token` |\n| Protocol | HTTPS only, JSON responses |\n| Auth | OAuth 2.0 Client Credentials -> short-lived Bearer JWT |\n\nThe ZenATS team provisions your `client_id`, `client_secret`, and the scopes your  \nintegration may request. Treat the secret as a password: it is shown once, cannot be  \nretrieved later, and must never ship in client-side code.\n\n## Authentication\n\nExchange your credentials for a token, requesting only the scopes you need:\n\n``` bash\ncurl -X POST https://<your-zenats-host>/oauth/token \\\n  -d grant_type=client_credentials \\\n  -d client_id=YOUR_CLIENT_ID \\\n  -d client_secret=YOUR_CLIENT_SECRET \\\n  -d \"scope=read:job read:candidate\"\n\n ```\n\nThe `access_token` is a signed RS256 JWT valid for **2 hours**. Cache it and reuse it  \nuntil it nears expiry, then request another — there is no refresh token. Send it on  \nevery call:\n\n``` bash\ncurl https://<your-zenats-host>/api/v1/ats/jobs \\\n  -H \"Authorization: Bearer YOUR_ACCESS_TOKEN\"\n\n ```\n\nSend the **token**, not the client secret. An optional locale prefix is supported:  \n`/en/api/v1/ats/...` or `/ar/api/v1/ats/...`.\n\n## Scopes\n\nAccess is governed by granular `verb:resource` scopes.\n\n| Resource | Scopes |\n| --- | --- |\n| Jobs | `read:job`, `create:job`, `update:job` |\n| Stages | `read:stage`, `create:stage`, `update:stage`, `destroy:stage` |\n| Applications | `read:job_candidate`, `create:job_candidate`, `update:job_candidate`, `destroy:job_candidate`, `move:job_candidate`, `qualify:job_candidate`, `disqualify:job_candidate` |\n| Candidates | `read:candidate`, `create:candidate`, `update:candidate`, `destroy:candidate` |\n\nThere is deliberately **no** **`destroy:job`** — deleting a job would take its stages and  \nevery application with it. Close a job with `PATCH /jobs/{id}` and `status: \"deactivated\"`.\n\n**Nested resources need the parent scope too.** Listing a job's applicants requires both  \n`read:job` and `read:job_candidate`.\n\n## Conventions\n\nList endpoints return an envelope; single resources are returned bare.\n\n``` json\n{\n  \"allowed_actions\": [],\n  \"pagination\": { \"current_page\": 1, \"per_page\": 25, \"total_entries\": 42, \"total_pages\": 2 },\n  \"data\": []\n}\n\n ```\n\n- **Pagination** — `?page=2&limit=50` (default `limit` 25, maximum 1000).\n    \n- **Filtering** — `?filter[status]=active`; date fields take a range,  \n    `?filter[created_at][from]=2026-01-01&filter[created_at][to]=2026-06-30`.\n    \n- **Expanding** — responses are lean by default; `?include=job.stages` or  \n    `?include=candidate.experiences,candidate.skills` embeds related data in the same  \n    response. Includes are eager-loaded server-side, so they avoid N+1 round-trips.\n    \n\n## Errors\n\n| Status | Meaning |\n| --- | --- |\n| `401` | Missing, malformed, or expired token |\n| `403` | Token lacks the required scope |\n| `404` | Resource does not exist, or belongs to another company |\n| `422` | Invalid request parameters |\n\n`401` returns `{ \"error\": \"Unauthorized Access\" }`. Every other error returns  \n`{ \"error\": { \"status\": ..., \"message\": ..., \"errors\": [] } }`.","schema":"https://schema.getpostman.com/json/collection/v2.0.0/collection.json","isPublicCollection":false,"owner":"34627729","team":6321075,"collectionId":"2d6b84a7-e08e-45e4-aebb-e3aa9e2ecaa3","publishedId":"2sBY4VJxLd","public":true,"publicUrl":"https://api-docs.zenats.com","privateUrl":"https://go.postman.co/documentation/34627729-2d6b84a7-e08e-45e4-aebb-e3aa9e2ecaa3","customColor":{"top-bar":"FFFFFF","right-sidebar":"303030","highlight":"00CDCA"},"documentationLayout":"classic-double-column","customisation":{"metaTags":[{"name":"description","value":""},{"name":"title","value":""}],"appearance":{"default":"light","themes":[{"name":"dark","logo":"https://content.pstmn.io/1624b936-e9de-436e-b5b6-fb2c8c13ae46/NjdlMTJkNWY4ZDI0ZTRiZjRiZTY3N2E0X1plbkhSLTEucG5n","colors":{"top-bar":"212121","right-sidebar":"303030","highlight":"00CDCA"}},{"name":"light","logo":"https://content.pstmn.io/1624b936-e9de-436e-b5b6-fb2c8c13ae46/NjdlMTJkNWY4ZDI0ZTRiZjRiZTY3N2E0X1plbkhSLTEucG5n","colors":{"top-bar":"FFFFFF","right-sidebar":"303030","highlight":"00CDCA"}}]}},"version":"8.12.7","publishDate":"2026-08-06T13:29:40.000Z","activeVersionTag":"latest","documentationTheme":"light","metaTags":{"title":"","description":""},"logos":{"logoLight":"https://content.pstmn.io/1624b936-e9de-436e-b5b6-fb2c8c13ae46/NjdlMTJkNWY4ZDI0ZTRiZjRiZTY3N2E0X1plbkhSLTEucG5n","logoDark":"https://content.pstmn.io/1624b936-e9de-436e-b5b6-fb2c8c13ae46/NjdlMTJkNWY4ZDI0ZTRiZjRiZTY3N2E0X1plbkhSLTEucG5n"}},"statusCode":200},"environments":[],"user":{"authenticated":false,"permissions":{"publish":false}},"run":{"button":{"js":"https://run.pstmn.io/button.js","css":"https://run.pstmn.io/button.css"}},"web":"https://www.getpostman.com/","team":{"logo":"https://res.cloudinary.com/postman/image/upload/t_team_logo_pubdoc/v1/team/422d68aa5b5c029b2ac4883475507fd94a7f43d5b25519d157ad9c95afceb09b","favicon":"https://zenats.com/favicon.ico"},"isEnvFetchError":false,"languages":"[{\"key\":\"csharp\",\"label\":\"C#\",\"variant\":\"HttpClient\"},{\"key\":\"csharp\",\"label\":\"C#\",\"variant\":\"RestSharp\"},{\"key\":\"curl\",\"label\":\"cURL\",\"variant\":\"cURL\"},{\"key\":\"dart\",\"label\":\"Dart\",\"variant\":\"http\"},{\"key\":\"go\",\"label\":\"Go\",\"variant\":\"Native\"},{\"key\":\"http\",\"label\":\"HTTP\",\"variant\":\"HTTP\"},{\"key\":\"java\",\"label\":\"Java\",\"variant\":\"OkHttp\"},{\"key\":\"java\",\"label\":\"Java\",\"variant\":\"Unirest\"},{\"key\":\"javascript\",\"label\":\"JavaScript\",\"variant\":\"Fetch\"},{\"key\":\"javascript\",\"label\":\"JavaScript\",\"variant\":\"jQuery\"},{\"key\":\"javascript\",\"label\":\"JavaScript\",\"variant\":\"XHR\"},{\"key\":\"c\",\"label\":\"C\",\"variant\":\"libcurl\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Axios\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Native\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Request\"},{\"key\":\"nodejs\",\"label\":\"NodeJs\",\"variant\":\"Unirest\"},{\"key\":\"objective-c\",\"label\":\"Objective-C\",\"variant\":\"NSURLSession\"},{\"key\":\"ocaml\",\"label\":\"OCaml\",\"variant\":\"Cohttp\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"cURL\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"Guzzle\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"HTTP_Request2\"},{\"key\":\"php\",\"label\":\"PHP\",\"variant\":\"pecl_http\"},{\"key\":\"powershell\",\"label\":\"PowerShell\",\"variant\":\"RestMethod\"},{\"key\":\"python\",\"label\":\"Python\",\"variant\":\"http.client\"},{\"key\":\"python\",\"label\":\"Python\",\"variant\":\"Requests\"},{\"key\":\"r\",\"label\":\"R\",\"variant\":\"httr\"},{\"key\":\"r\",\"label\":\"R\",\"variant\":\"RCurl\"},{\"key\":\"ruby\",\"label\":\"Ruby\",\"variant\":\"Net::HTTP\"},{\"key\":\"shell\",\"label\":\"Shell\",\"variant\":\"Httpie\"},{\"key\":\"shell\",\"label\":\"Shell\",\"variant\":\"wget\"},{\"key\":\"swift\",\"label\":\"Swift\",\"variant\":\"URLSession\"}]","languageSettings":[{"key":"csharp","label":"C#","variant":"HttpClient"},{"key":"csharp","label":"C#","variant":"RestSharp"},{"key":"curl","label":"cURL","variant":"cURL"},{"key":"dart","label":"Dart","variant":"http"},{"key":"go","label":"Go","variant":"Native"},{"key":"http","label":"HTTP","variant":"HTTP"},{"key":"java","label":"Java","variant":"OkHttp"},{"key":"java","label":"Java","variant":"Unirest"},{"key":"javascript","label":"JavaScript","variant":"Fetch"},{"key":"javascript","label":"JavaScript","variant":"jQuery"},{"key":"javascript","label":"JavaScript","variant":"XHR"},{"key":"c","label":"C","variant":"libcurl"},{"key":"nodejs","label":"NodeJs","variant":"Axios"},{"key":"nodejs","label":"NodeJs","variant":"Native"},{"key":"nodejs","label":"NodeJs","variant":"Request"},{"key":"nodejs","label":"NodeJs","variant":"Unirest"},{"key":"objective-c","label":"Objective-C","variant":"NSURLSession"},{"key":"ocaml","label":"OCaml","variant":"Cohttp"},{"key":"php","label":"PHP","variant":"cURL"},{"key":"php","label":"PHP","variant":"Guzzle"},{"key":"php","label":"PHP","variant":"HTTP_Request2"},{"key":"php","label":"PHP","variant":"pecl_http"},{"key":"powershell","label":"PowerShell","variant":"RestMethod"},{"key":"python","label":"Python","variant":"http.client"},{"key":"python","label":"Python","variant":"Requests"},{"key":"r","label":"R","variant":"httr"},{"key":"r","label":"R","variant":"RCurl"},{"key":"ruby","label":"Ruby","variant":"Net::HTTP"},{"key":"shell","label":"Shell","variant":"Httpie"},{"key":"shell","label":"Shell","variant":"wget"},{"key":"swift","label":"Swift","variant":"URLSession"}],"languageOptions":[{"label":"C# - HttpClient","value":"csharp - HttpClient - C#"},{"label":"C# - RestSharp","value":"csharp - RestSharp - C#"},{"label":"cURL - cURL","value":"curl - cURL - cURL"},{"label":"Dart - http","value":"dart - http - Dart"},{"label":"Go - Native","value":"go - Native - Go"},{"label":"HTTP - HTTP","value":"http - HTTP - HTTP"},{"label":"Java - OkHttp","value":"java - OkHttp - Java"},{"label":"Java - Unirest","value":"java - Unirest - Java"},{"label":"JavaScript - Fetch","value":"javascript - Fetch - JavaScript"},{"label":"JavaScript - jQuery","value":"javascript - jQuery - JavaScript"},{"label":"JavaScript - XHR","value":"javascript - XHR - JavaScript"},{"label":"C - libcurl","value":"c - libcurl - C"},{"label":"NodeJs - Axios","value":"nodejs - Axios - NodeJs"},{"label":"NodeJs - Native","value":"nodejs - Native - NodeJs"},{"label":"NodeJs - Request","value":"nodejs - Request - NodeJs"},{"label":"NodeJs - Unirest","value":"nodejs - Unirest - NodeJs"},{"label":"Objective-C - NSURLSession","value":"objective-c - NSURLSession - Objective-C"},{"label":"OCaml - Cohttp","value":"ocaml - Cohttp - OCaml"},{"label":"PHP - cURL","value":"php - cURL - PHP"},{"label":"PHP - Guzzle","value":"php - Guzzle - PHP"},{"label":"PHP - HTTP_Request2","value":"php - HTTP_Request2 - PHP"},{"label":"PHP - pecl_http","value":"php - pecl_http - PHP"},{"label":"PowerShell - RestMethod","value":"powershell - RestMethod - PowerShell"},{"label":"Python - http.client","value":"python - http.client - Python"},{"label":"Python - Requests","value":"python - Requests - Python"},{"label":"R - httr","value":"r - httr - R"},{"label":"R - RCurl","value":"r - RCurl - R"},{"label":"Ruby - Net::HTTP","value":"ruby - Net::HTTP - Ruby"},{"label":"Shell - Httpie","value":"shell - Httpie - Shell"},{"label":"Shell - wget","value":"shell - wget - Shell"},{"label":"Swift - URLSession","value":"swift - URLSession - Swift"}],"layoutOptions":[{"value":"classic-single-column","label":"Single Column"},{"value":"classic-double-column","label":"Double Column"}],"versionOptions":[],"environmentOptions":[{"value":"0","label":"No Environment"}],"canonicalUrl":"https://api-docs.zenats.com/view/metadata/2sBY4VJxLd"}