BambooHR Integration

Digital Business Cards for BambooHR

Connect QRBold to BambooHR in three clicks and let your HR system decide who has a business card. New hires get a branded card built from their BambooHR profile, job title changes flow through on the next sync, and a termination in BambooHR takes the card offline — without anyone raising a ticket or touching a spreadsheet.

Start Free

Last updated

3 clicks

To connect, no API key to mint

Hourly

Roster reconciliation

Read-only

QRBold never writes to BambooHR

0 tickets

Manual offboarding steps

Can you create digital business cards from BambooHR?

Yes. QRBold connects to BambooHR over OAuth and reads your employee directory on an hourly schedule. Cards are built from BambooHR fields such as name, job title, department, work email, and mobile number, and a termination recorded in BambooHR suspends the employee's card automatically on the next sync.

Why teams choose QRBold for bamboohr

Connect with a consent screen, not a credential hunt

QRBold registers one application with BambooHR, so you never create a developer account, mint an API key, or paste a secret into a settings form. You supply your company domain — the part before .bamboohr.com — click Authorise on BambooHR's own consent screen, and the connection is live. Pasting the full URL works too; QRBold reduces it to the subdomain.

The roster reconciles every hour

A scheduled read pulls your current employee list and compares it against what QRBold holds. New hires appear, leavers are flagged, and changed titles are picked up — without anyone exporting a CSV. Between scheduled runs, BambooHR webhooks can push changes as they happen.

Termination in BambooHR ends the card

This is the failure mode the integration exists to remove: an ex-employee's card still live months after they left, still reachable from a QR code on a printed badge, still answering with your brand and their direct line on it. When BambooHR marks someone terminated, the deprovision action you chose runs on its own.

Read-only, and encrypted at rest

QRBold requests a least-privilege scope set and never writes back to BambooHR — the data flows one way. BambooHR issues a refresh token per customer, and because that token is the entire grant for as long as it lives, QRBold seals it with AES-256-GCM and refuses to store a credential at all if encryption is not configured.

Connect BambooHR in three steps

1

Enter your company domain

In QRBold, open Settings → Enterprise → BambooHR and enter your BambooHR subdomain — the "acme" in acme.bamboohr.com. You can paste the full URL from your browser's address bar instead; QRBold extracts the subdomain for you.

2

Authorise on BambooHR's consent screen

QRBold sends you to BambooHR, where you approve the requested read-only scopes as a BambooHR administrator. There is no application to register and no API key to create — QRBold's application is registered once, centrally, and every customer authorises against it.

3

Choose who gets a card, and preview the first sync

Map BambooHR fields onto card fields, pick a provisioning rule, and run the import preview. The preview shows exactly which employees would receive a card before anything is created — the first sync is always confirmed, never automatic.

BambooHR integration specification

The technical detail an evaluation actually turns on, in one place.

AuthenticationOAuth 2.0 authorisation code — one QRBold application, per-customer consent
Customer setupCompany subdomain only — no API key, no developer account, no app registration
Access levelRead-only, least-privilege scopes. QRBold never writes to BambooHR
Sync modelScheduled hourly reconciliation, plus webhook push for real-time changes
Webhook securitySignature verified with a replay window, 300 seconds by default
Credential storageRefresh token sealed with AES-256-GCM; connector refuses to store unencrypted
Typical field mapFirst name · Last name · Job title · Department · Work email · Mobile phone
Provisioning modesEveryone · By group · Selected users · Self-service · Request with approval
Deprovision actionsSuspend card · Delete card · Keep card
First runImport preview shown and confirmed before any card is created
PlanEnterprise. Re-checked on every scheduled reconciliation, not only at setup

Why the HR system is the right source of truth for a business card

Most digital business card platforms treat your employee roster as a file. You export a CSV from BambooHR, map the columns, upload it, and the data is accurate until the next person is hired, promoted, or resigns — usually within the same week. From there the roster drifts quietly, and nobody notices until someone spots a live card for a person who left in March.

BambooHR already holds the answer to every question a business card asks. It knows who works here, what their title is, which department they sit in, what their work email is, and — the part that matters most — the exact date they stopped working here. Reading that directly removes the export step, and with it the drift.

There is a security argument too, and it is usually the one that gets the project approved. A digital business card is a public URL carrying a name, a job title, a company, a direct phone number, and an email address. Left live after termination it is a working asset for social engineering, and unlike a deactivated email account, nobody gets an alert when it is used.

What the hourly sync actually does

Every scheduled run reads your current BambooHR roster and compares it to what QRBold already holds, then acts only on the differences.

  • New employees. Appear in the roster as eligible. Whether they receive a card depends on the provisioning rule you set — being in the roster is not the same as getting a card.
  • Changed attributes. A promotion, a department move, or a new mobile number updates the card behind the existing QR code. The printed code never changes.
  • Terminations. Trigger the deprovision action you configured — suspend, delete, or keep — without anyone remembering to do it.
  • Re-hires. A returning employee is matched back to their existing record rather than duplicated, so scan history is preserved.
  • Plan re-check. The Enterprise capability is verified on every run, not just at connect time, so the integration state always reflects your current plan.

Reading the roster is not the same as handing out cards

This distinction is deliberate and worth being explicit about, because it is the difference between an integration you can pilot safely and one you cannot. The BambooHR connector fills a roster and does nothing else. It never creates a card on its own.

Card creation is governed separately by the provisioning rule, and it runs the same way for every connected system. That means you can connect BambooHR to a 900-person company, look at the full roster, and still have provisioned exactly zero cards until you choose a rule and confirm the preview. A phased rollout — Sales first, then Customer Success — is a normal configuration rather than a workaround.

What QRBold can and cannot see

The connection is read-only and scoped. QRBold requests the fields needed to build a business card and to know whether someone is currently employed. It does not request compensation, performance, time-off, or benefits data, and it has no write path back into BambooHR at all — nothing QRBold does can alter an employee record.

The credential is handled accordingly. BambooHR issues a refresh token per customer, which stays valid until revoked and therefore represents the whole grant. QRBold encrypts it at rest with AES-256-GCM, never returns it from any endpoint, and never writes it to a log. If the deployment has no encryption key configured, the connector reports itself unavailable rather than storing the token in the clear.

Revoking access is done from your side and takes effect immediately: remove the authorisation in BambooHR and the next scheduled read fails closed.

BambooHR questions, answered

The questions that come up in real evaluations, answered directly.

Get started

Let BambooHR decide who has a business card

Connect in three clicks, preview exactly who gets a card, and let joiners, movers, and leavers take care of themselves.

Start Free

No credit card required