Skip to main content
Administrator Guide
Last Updated: 2026-10-09
Connect an External Agent with Workday MCP

Connect an External Agent with Workday MCP

  • OAuth credentials.
  • An external API Client of your choice, such as Bruno or Postman.
  • You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
    1. Select your profile avatar on Workday Community.
    2. Select
      Profile
      .
    3. On your profile page, select your organization's name, which is beneath your name and next to your job title.
    4. View your
      Subscription Service Agreement
      value.
    If the value is:
    • UMSA
      , the feature is automatically available. You can skip the
      Enable Innovation Services Feature and AI Data Contributions for MSA Customers
      step. For more information on Machine Learning data contributions, see Concept: Workday AI for Universal Main Subscription Agreement Customers.
    • MSA
      , you must enable this feature through Innovation Services using the
      Enable Innovation Services Feature and AI Data Contributions for MSA Customers
      step.
    Note: UMSA customers don't have Innovation Services tasks and reports in their tenants as these are for MSA customers only. UMSA customers can ignore all information regarding Innovation Services.
You can set up your tenant to connect any registered external agent with Workday’s MCP server.
This functionality is for Extend Professionals only.
  1. In your API Client (Bruno or Postman), call the Authorize endpoint and log in. Example:
    GET https://us.agent.workday.com/auth/authorize/<tenant> Params: client_id, redirect_uri, response_type=code
  2. Exchange for an ASU access token. Example:
    POST https://us.agent.workday.com/auth/oauth2/<tenant>/token Headers: Content-Type: application/x-www-form-urlencoded Body: grant_type=authorization_code&code=<code> &client_id=<id>&client_secret=<secret> Response: { "access_token": "...", "token_type": "Bearer", "refresh_token": "..." }
    Refresh your tokens before expiry as access tokens expire after 60 minutes. Refresh tokens after 24 hours.
  3. Verify your connection and confirm the MCP tools are accessible. Example:
    curl --request POST \ --url https://us.agent.workday.com/mcp \ --header 'Content-Type: application/json' \ --header 'Authorization: Bearer <ASU token>' \ --data '{ "jsonrpc": "2.0", "id": 1, "method": "tools/list" }'
    A
    200
    response with a list of your registered tools confirms everything is wired correctly.
  4. Connect to your agent platform.
    Any platform that supports MCP (Google Agentspace, Amazon Bedrock AgentCore, Microsoft Copilot Studio, and others) connects to the same endpoint using the same OAuth credentials. Refer to your platform's MCP integration documentation for the specific configuration steps.
    Example:
    When you add a Custom MCP in Cursor, in the mcp.json, add:
    { "mcpServers": { "Workday MCP": { "url": "https://{agentGatewayRegionEndpoint}/{tenantName}/mcp", "headers": { "Authorization": "Bearer <your ASU token>" } } } }