Connect an External Agent with Workday MCP
- OAuth credentials.
- An external API Client of your choice, such as Bruno or Postman.
- You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
- Select your profile avatar on Workday Community.
- SelectProfile.
- On your profile page, select your organization's name, which is beneath your name and next to your job title.
- View yourSubscription Service Agreementvalue.
If the value is:- UMSA, the feature is automatically available. You can skip theEnable Innovation Services Feature and AI Data Contributions for MSA Customersstep. For more information on Machine Learning data contributions, see Concept: Workday AI for Universal Main Subscription Agreement Customers.
- MSA, you must enable this feature through Innovation Services using theEnable Innovation Services Feature and AI Data Contributions for MSA Customersstep.
Note: UMSA customers don't have Innovation Services tasks and reports in their tenants as these are for MSA customers only. UMSA customers can ignore all information regarding Innovation Services.
You can set up your tenant to connect any registered external agent with Workday’s MCP server.
This functionality is for Extend Professionals only.
- In your API Client (Bruno or Postman), call the Authorize endpoint and log in. Example:GET https://us.agent.workday.com/auth/authorize/<tenant> Params: client_id, redirect_uri, response_type=code
- Exchange for an ASU access token. Example:POST https://us.agent.workday.com/auth/oauth2/<tenant>/token Headers: Content-Type: application/x-www-form-urlencoded Body: grant_type=authorization_code&code=<code> &client_id=<id>&client_secret=<secret> Response: { "access_token": "...", "token_type": "Bearer", "refresh_token": "..." }Refresh your tokens before expiry as access tokens expire after 60 minutes. Refresh tokens after 24 hours.
- Verify your connection and confirm the MCP tools are accessible. Example:curl --request POST \ --url https://us.agent.workday.com/mcp \ --header 'Content-Type: application/json' \ --header 'Authorization: Bearer <ASU token>' \ --data '{ "jsonrpc": "2.0", "id": 1, "method": "tools/list" }'A200response with a list of your registered tools confirms everything is wired correctly.
- Connect to your agent platform.Any platform that supports MCP (Google Agentspace, Amazon Bedrock AgentCore, Microsoft Copilot Studio, and others) connects to the same endpoint using the same OAuth credentials. Refer to your platform's MCP integration documentation for the specific configuration steps.Example:When you add a Custom MCP in Cursor, in the mcp.json, add:{ "mcpServers": { "Workday MCP": { "url": "https://{agentGatewayRegionEndpoint}/{tenantName}/mcp", "headers": { "Authorization": "Bearer <your ASU token>" } } } }