Loading.....
No licensed middleware · No broker in the path

The connection, under the hood.

Mercans reads Bob through its documented API, transforms the data on Mercans-owned infrastructure, and runs payroll on its own engine. No licensed middleware. No broker sitting between your tenant and your payroll.

Bob REST API · JSON
Mercans-owned infrastructure
No third-party iPaaS in the data path
01
System architecture

Your tenant on one side. Everything else, Mercans-owned.

HiBob tenant
People · time off
Bob REST API
JSON payloads
PULL · REST/JSON ON-DEMAND · ANY CYCLE RESULTS BACK
MERCANS-OWNED INFRASTRUCTURE
Connector
HRBlizz parser
Mapping · transform
Validation
Payroll engine
HR Blizz™ · G2N™
Gross-to-net
160+ countries

Your Bob tenant is the only system outside the Mercans boundary. The connector and the payroll engine both run on Mercans-owned infrastructure — the connector code is written and maintained by Mercans engineers, with no third-party iPaaS in the data path.

02
The connection model

Four building blocks. All documented, all standard.

01
Service-user auth

Mercans connects through a dedicated Bob service user with permissions scoped to exactly the payroll fields it needs — least privilege, over an mTLS-secured, IP-whitelisted channel.

02
REST · JSON

The connector is a configurable REST parser that reads Bob's JSON endpoints — defined per legal entity, with its own auth and certificate.

03
On-demand pull

Mercans pulls a complete, current data set from Bob whenever a cycle runs — on your schedule or on request — so every run reflects the latest hires, leavers and changes.

04
Mercans-owned engine

Transformation and payroll both run on Mercans infrastructure (HR Blizz™ · G2N™). No licensed broker, no opaque scheduling layer.

03
Separation of concerns

Three planes. One audited channel.

The integration keeps data movement, orchestration, and security logically separate — all meeting at a single, monitored channel between Bob and Mercans.

Data planeMaster data, compensation, banking, time off, evaluated hours
Control planeScheduling, orchestration, monitoring, error detection, reprocessing
Security planeService-user permissions, encryption, data residency
One
audited channel
Least privilege, not all-accessBob's permissions are category-based: you grant the Mercans service user view access only to the fields payroll requires. Anything outside that scope is never returned — the connector simply can't see it.
04
Built to stay reliable

Engineered for high-volume, repeatable runs.

Bulk-first reads

Employees are listed then fetched in batches — the pattern Bob recommends for large directories — instead of slow one-by-one calls.

Rate-limit aware

The connector respects Bob's rate limits with retry-after handling and exponential backoff, so big pay groups never trip the API.

Idempotent & auditable

Every fetch lands as a hash-stamped interface file with its own status and timestamps — fully traceable, safe to reprocess.

Transport & security
REST · mTLS · HTTPS SFTP / H2H file channels IP whitelisting SSH-key auth PGP encryption Basic authentication
What each pull captures
Master data Compensation Variable payments Bank details Time off Timesheet hours One-time payments Joiners, leavers & changes

Want the architecture reviewed by your IT team?

We'll walk through auth, permissions, residency and the data path in detail.

Book a session
Up next · 03
Interfaces & Data

Exactly what connects — the full data inventory and the lifecycle every run goes through.

Our sales team is ready to assist you.


You can also reach us toll free at: