Connect your app to Workday
Connect your app to Workday so each user can see their own HR data, like worker profiles or time off, directly within your app. This is useful for building tools like employee portals or team directories that show information based on each person's Workday permissions.
Anyone building an app that needs to show personalized HR or workforce data from Workday to individual users.
Do this, in order
- 1
In Workday, register a new API Client by searching for and running the 'Register API Client' task.
This creates the necessary credentials and settings in Workday for your Lovable app to securely communicate with it.
- 2
Set 'Client Grant Type' to 'Authorization Code Grant' and 'Access Token Type' to 'Bearer'.
These settings define how your app will get permission to access Workday data on behalf of users.
- 3
Ensure 'Support Proof Key for Code Exchange (PKCE)' is disabled.
The Lovable connector uses a client secret for authentication, which is not provided if PKCE is enabled.
- 4
Set the 'Redirection URI' to 'https://connector-gateway.lovable.dev/api/v1/app-users/oauth2/callback'.
This tells Workday where to send users back after they've successfully signed in and granted permission to your app.
- 5
Check the 'Non-Expiring Refresh Tokens' box.
This prevents users from having to reconnect their Workday account frequently if they don't use your app for a while.
- 6
Under 'Scope (Functional Areas)', select only the specific data types your app needs, like 'Staffing' for worker data.
This limits your app's access to only the necessary information, improving security and adhering to the principle of least privilege.
- 7
After clicking 'OK', copy the 'Client ID' and 'Client Secret' displayed, as the secret is shown only once.
These are essential credentials for Lovable to identify and authenticate with your Workday API client.
- 8
Run the 'View API Clients' task in Workday and copy the 'Workday REST API Endpoint', 'Token Endpoint', and 'Authorization Endpoint' for your new API client.
These URLs tell Lovable where to send requests for data and authentication to your Workday tenant.
- 9
In Lovable, go to 'Connectors', select 'Workday', and click 'Add connection' then 'App user connector'.
This starts the process of setting up the Workday connection within your Lovable workspace.
- 10
Give your client a 'Display name' (e.g., 'Workday production') and paste the copied 'Workday REST API Endpoint', 'Token Endpoint', 'Authorization Endpoint', 'Client ID', and 'Client Secret' into the corresponding fields.
This configures the Lovable connector with all the details it needs to interact with your specific Workday API client.
- 11
Under 'Sharing', choose who in your Lovable workspace can use this Workday client, or keep it private to yourself.
This controls which team members can connect this Workday client to their projects.
- 12
Click 'Create client' to finalize the Workday client setup in Lovable.
This saves your configuration and makes the Workday client available for use in your projects.
Paste this into your project
Let each signed-in user connect their own Workday account and show their time off balance on the dashboard.
Words decoded
- API client
- A special account or set of credentials that allows one software system (like your Lovable app) to securely talk to another system (like Workday) and request information or perform actions.
- Workday tenant
- Your specific, private instance of Workday where your company's data is stored and managed.
- App user connector
- A type of connection where each person using your app links their own account from another service (like Workday), and your app then accesses data only with that person's specific permissions.
- Authorization Code Grant
- A secure method for an app to get permission to access a user's data from another service without ever seeing the user's password.
- Bearer token
- A security credential, like a digital key, that grants access to specific resources. Whoever holds the token can use it to access the data it's authorized for.
- Redirection URI
- A specific web address that the service (Workday) sends the user's web browser to after they've successfully signed in and approved access for your app.
- Refresh tokens
- Special tokens that an app can use to get new access tokens without requiring the user to sign in again, helping maintain a continuous connection.
- Functional areas
- Specific categories of data or actions within Workday (e.g., 'Staffing' for employee data, 'Time Off' for leave requests) that your app can be granted permission to access.
Where people get stuck
- Forgetting to copy the Client ID and Client Secret immediately after registering the API client in Workday, as the secret is shown only once.
- Using the wrong Redirection URI for an app user connector, which will prevent users from successfully connecting their Workday accounts.
- Not enabling 'Non-Expiring Refresh Tokens' in Workday, which will force users to frequently reconnect their Workday accounts to your app.
- Selecting too many or too few 'Functional Areas' in Workday, leading to either excessive permissions or your app not being able to access the data it needs.
- Trying to use the Workday connector for a shared, workspace-wide connection instead of individual user connections, as it is designed for app user connections only.
- Not having authentication set up in your Lovable app, as each user needs to be signed in before they can connect their Workday account.
The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.